2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-14021 | HIGH | 7.8 | 0.3% | Jan 12, 2026 | LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe deserialization vulnerability i... |
| CVE-2024-30547 | HIGH | 7.1 | 0.2% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Shazdeh Hea... |
| CVE-2024-53735 | HIGH | 7.1 | 0.1% | Jan 5, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in corourke iPhone We... |
| CVE-2024-30516 | HIGH | 7.5 | 0.2% | Jan 5, 2026 | Improper Validation of Specified Quantity in Input vulnerability in SaasProject Booking Package allows Accessing Functio... |
| CVE-2024-30461 | HIGH | 7.1 | 0.1% | Jan 5, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tumult Inc ... |
| CVE-2024-58337 | HIGH | 8.7 | 0.2% | Dec 30, 2025 | Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to... |
| CVE-2024-58336 | HIGH | 8.7 | 0.3% | Dec 30, 2025 | Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video s... |
| CVE-2024-58315 | HIGH | 8.5 | 0.2% | Dec 30, 2025 | Tosibox Key Service 3.3.0 contains an unquoted service path vulnerability that allows local non-privileged users to pote... |
| CVE-2024-25183 | HIGH | 7.5 | 0.6% | Dec 29, 2025 | givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php. |
| CVE-2024-30855 | HIGH | 8.8 | 0.2% | Dec 29, 2025 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/makehtml_list_act... |
| CVE-2024-9684 | HIGH | 7.5 | 0.3% | Dec 23, 2025 | FreyrSCADA/IEC-60870-5-104 server v21.06.008 allows remote attackers to cause a denial of service by sending specific me... |
| CVE-2024-24844 | HIGH | 7.5 | 0.2% | Dec 23, 2025 | Missing Authorization vulnerability in IdeaBox Creations PowerPack Pro for Elementor allows Exploiting Incorrectly Confi... |
| CVE-2024-46062 | HIGH | 7.8 | 0.2% | Dec 17, 2025 | Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside t... |
| CVE-2024-46060 | HIGH | 7.8 | 0.2% | Dec 17, 2025 | Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside th... |
| CVE-2024-29371 | HIGH | 7.5 | 0.2% | Dec 17, 2025 | In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encry... |
| CVE-2024-44599 | HIGH | 8.3 | 0.4% | Dec 15, 2025 | FNT Command 13.4.0 is vulnerable to Directory Traversal. |
| CVE-2024-44598 | HIGH | 8.8 | 0.4% | Dec 15, 2025 | FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module. |
| CVE-2024-58316 | HIGH | 8.7 | 0.5% | Dec 12, 2025 | Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows... |
| CVE-2024-58314 | HIGH | 8.8 | 1.4% | Dec 12, 2025 | Atcom 100M IP Phones firmware version 2.7.x.x contains an authenticated command injection vulnerability in the web confi... |
| CVE-2024-58305 | HIGH | 8.8 | 0.4% | Dec 12, 2025 | WonderCMS 4.3.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious JavaScript throu... |
| CVE-2024-58313 | HIGH | 7.2 | 0.5% | Dec 11, 2025 | xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative pr... |
| CVE-2024-58312 | HIGH | 7.5 | 1.0% | Dec 11, 2025 | xbtitFM 4.1.18 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system ... |
| CVE-2024-58310 | HIGH | 8.7 | 0.8% | Dec 11, 2025 | APC Network Management Card 4 contains a path traversal vulnerability that allows unauthenticated attackers to access se... |
| CVE-2024-58307 | HIGH | 8.8 | 0.4% | Dec 11, 2025 | CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authent... |
| CVE-2024-58306 | HIGH | 8.7 | 0.4% | Dec 11, 2025 | minaliC 2.0.0 contains a denial of service vulnerability that allows remote attackers to crash the web server by sending... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now