2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42649 | MEDIUM | 6.5 | 0.3% | Jul 14, 2025 | NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a ... |
| CVE-2024-42648 | MEDIUM | 6.5 | 0.3% | Jul 14, 2025 | NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via ... |
| CVE-2024-42646 | HIGH | 7.5 | 0.4% | Jul 14, 2025 | A segmentation fault in NanoMQ v0.21.10 allows attackers to cause a Denial of Service (DoS) via crafted messages. |
| CVE-2024-51770 | HIGH | 7.5 | 0.4% | Jul 14, 2025 | An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17. |
| CVE-2024-51769 | HIGH | 7.5 | 0.4% | Jul 14, 2025 | An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17. |
| CVE-2024-51768 | HIGH | 8 | 0.4% | Jul 14, 2025 | An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17. |
| CVE-2024-51767 | HIGH | 7.3 | 1.1% | Jul 14, 2025 | An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17. |
| CVE-2024-26293 | HIGH | 8.7 | 0.4% | Jul 14, 2025 | The Avid Nexis Agent uses a vulnerable gSOAP version. An undocumented vulnerability impacting gSOAP v2.8 makes the appli... |
| CVE-2024-26292 | HIGH | 7.1 | 0.4% | Jul 14, 2025 | An authenticated Arbitrary File Deletion vulnerability enables an attacker to delete critical files. This issue affects ... |
| CVE-2024-26291 | HIGH | 8.7 | 1.1% | Jul 14, 2025 | An Unauthenticated Arbitrary File Read vulnerability affects the Agent when installed on a system. The parameter filenam... |
| CVE-2024-58258 | HIGH | 7.2 | 13.2% | Jul 13, 2025 | SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can... |
| CVE-2024-41169 | HIGH | 7.5 | 0.6% | Jul 12, 2025 | The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, in... |
| CVE-2024-38648 | MEDIUM | 5.7 | 0.6% | Jul 12, 2025 | A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensit... |
| CVE-2024-47065 | MEDIUM | 6.5 | 0.2% | Jul 11, 2025 | Meshtastic is an open source mesh networking solution. Prior to 2.5.1, traceroute responses from the remote node are not... |
| CVE-2024-47252 | HIGH | 7.5 | 0.7% | Jul 10, 2025 | Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/... |
| CVE-2024-43394 | HIGH | 7.5 | 1.1% | Jul 10, 2025 | Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a maliciou... |
| CVE-2024-43204 | HIGH | 7.5 | 0.8% | Jul 10, 2025 | SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled ... |
| CVE-2024-42516 | HIGH | 7.5 | 0.7% | Jul 10, 2025 | HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type respons... |
| CVE-2024-39752 | CRITICAL | 9.8 | 0.3% | Jul 10, 2025 | IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by not validating the type... |
| CVE-2024-38327 | CRITICAL | 9.8 | 0.3% | Jul 10, 2025 | IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 is vulnerable to information exposure and further attacks due to an exp... |
| CVE-2024-37524 | MEDIUM | 5.3 | 0.3% | Jul 10, 2025 | IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain sensitive information when a de... |
| CVE-2024-36697 | MEDIUM | 6.1 | 0.2% | Jul 10, 2025 | A cross-site scripting (XSS) vulnerability in the Admin Login page of Allworx System Software v9.1.9.12 allows attackers... |
| CVE-2024-7650 | MEDIUM | 6.3 | 0.3% | Jul 10, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Directory Services allows Remote Co... |
| CVE-2024-10391 | — | — | — | Jul 9, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-56468 | MEDIUM | 6.5 | 0.3% | Jul 8, 2025 | IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 could allow a remote user to cause a denial of service ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now