2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-51775MEDIUM5.3Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server...
CVE-2024-52279MEDIUM5.3Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not ac...
CVE-2024-41177MEDIUM6.1Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: befo...
CVE-2024-13978LOW2.5A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as problematic. Affected by this vulnerability is...
CVE-2024-34327MEDIUM6.5Sielox AnyWare v2.1.2 was discovered to contain a SQL injection vulnerability via the email address field of the passwor...
CVE-2024-34328MEDIUM6.3An open redirect in Sielox AnyWare v2.1.2 allows attackers to execute a man-in-the-middle attack via a crafted URL.
CVE-2024-11478——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-48916HIGH8.1Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an ...
CVE-2024-45955HIGH7.3Rocket Software Rocket Zena 4.4.1.26 is vulnerable to SQL Injection via the filter parameter.
CVE-2024-45515MEDIUM6.1An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability exists in...
CVE-2024-43018MEDIUM6.4Piwigo 13.8.0 and below is vulnerable to SQL Injection in the parameters max_level and min_register. These parameters ar...
CVE-2024-52894MEDIUM4.9IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 1...
CVE-2024-51473HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 1...
CVE-2024-49828HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 1...
CVE-2024-42655HIGH8.8An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system ...
CVE-2024-42651HIGH7.5NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vuln...
CVE-2024-42645HIGH7.5An issue in FlashMQ v1.14.0 allows attackers to cause an assertion failure via sending a crafted retain message, leading...
CVE-2024-42644HIGH7.5FlashMQ v1.14.0 was discovered to contain an assertion failure in the function PublishCopyFactory::getNewPublish, which ...
CVE-2024-49343MEDIUM5.4IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could inject malicious HT...
CVE-2024-49342HIGH7.5IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacke...
CVE-2024-58266CRITICAL9.8The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may fa...
CVE-2024-58265MEDIUM4.3The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby deny...
CVE-2024-58264HIGH7.5The serde-json-wasm crate before 1.0.1 for Rust allows stack consumption via deeply nested JSON data.
CVE-2024-58263MEDIUM5.3The cosmwasm-std crate before 2.0.2 for Rust allows integer overflows that cause incorrect contract calculations.
CVE-2024-58262MEDIUM5.1The curve25519-dalek crate before 4.1.3 for Rust has a constant-time operation on elliptic curve scalars that is removed...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now