2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50617 | HIGH | 7.5 | 0.2% | Feb 11, 2026 | Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to... |
| CVE-2024-50620 | HIGH | 8.8 | 0.3% | Feb 11, 2026 | Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document manage compon... |
| CVE-2024-26480 | HIGH | 7.5 | 0.6% | Feb 11, 2026 | An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the admin p... |
| CVE-2024-26477 | HIGH | 7.5 | 0.5% | Feb 11, 2026 | An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the api par... |
| CVE-2024-36324 | HIGH | 8.8 | 0.2% | Feb 11, 2026 | Improper input validation in AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentia... |
| CVE-2024-36320 | HIGH | 7 | 0.1% | Feb 11, 2026 | Integer Overflow within atihdwt6.sys can allow a local attacker to cause out of bound read/write potentially leading to ... |
| CVE-2024-56808 | HIGH | 7.8 | 0.6% | Feb 11, 2026 | A command injection vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network... |
| CVE-2024-36355 | HIGH | 7 | 0.2% | Feb 10, 2026 | Improper input validation in the SMM handler could allow an attacker with Ring0 access to write to SMRAM and modify exec... |
| CVE-2024-5386 | HIGH | 8.8 | 0.5% | Feb 2, 2026 | In lunary-ai/lunary version 1.2.2, an account hijacking vulnerability exists due to a password reset token leak. A user ... |
| CVE-2024-54263 | HIGH | 7.5 | 0.3% | Feb 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-4027 | HIGH | 7.5 | 0.6% | Jan 30, 2026 | A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an... |
| CVE-2024-11976 | HIGH | 7.3 | 0.4% | Jan 23, 2026 | The The BuddyPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includ... |
| CVE-2024-44238 | HIGH | 7.8 | 0.1% | Jan 16, 2026 | The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1... |
| CVE-2024-48077 | HIGH | 7.5 | 0.3% | Jan 15, 2026 | NanoMQ v0.22.7 is vulnerable to Denial of Service (DoS) due to improper resource throttling. A crafted sequence of reque... |
| CVE-2024-58340 | HIGH | 7.5 | 0.4% | Jan 12, 2026 | LangChain versions up to and including 0.3.1 contain a regular expression denial-of-service (ReDoS) vulnerability in the... |
| CVE-2024-58339 | HIGH | 7.5 | 0.6% | Jan 12, 2026 | LlamaIndex (run-llama/llama_index) versions up to and including 0.12.2 contain an uncontrolled resource consumption vuln... |
| CVE-2024-14021 | HIGH | 7.8 | 0.3% | Jan 12, 2026 | LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe deserialization vulnerability i... |
| CVE-2024-30547 | HIGH | 7.1 | 0.2% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Shazdeh Hea... |
| CVE-2024-53735 | HIGH | 7.1 | 0.1% | Jan 5, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in corourke iPhone We... |
| CVE-2024-30516 | HIGH | 7.5 | 0.2% | Jan 5, 2026 | Improper Validation of Specified Quantity in Input vulnerability in SaasProject Booking Package allows Accessing Functio... |
| CVE-2024-30461 | HIGH | 7.1 | 0.1% | Jan 5, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tumult Inc ... |
| CVE-2024-58337 | HIGH | 8.7 | 0.2% | Dec 30, 2025 | Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to... |
| CVE-2024-58336 | HIGH | 8.7 | 0.3% | Dec 30, 2025 | Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video s... |
| CVE-2024-58315 | HIGH | 7.8 | 0.2% | Dec 30, 2025 | Tosibox Key Service 3.3.0 contains an unquoted service path vulnerability that allows local non-privileged users to pote... |
| CVE-2024-25183 | HIGH | 7.5 | 0.6% | Dec 29, 2025 | givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now