2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50555 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elemento... |
| CVE-2024-50452 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH Nexter Bl... |
| CVE-2024-43228 | MEDIUM | 5.3 | 0.2% | Feb 20, 2026 | Missing Authorization vulnerability in SecuPress SecuPress Free secupress.This issue affects SecuPress Free: from n/a th... |
| CVE-2024-34438 | MEDIUM | 5.3 | 0.3% | Feb 20, 2026 | Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a... |
| CVE-2024-31118 | MEDIUM | 6.5 | 0.2% | Feb 17, 2026 | Missing Authorization vulnerability in Smartypants SP Project & Document Manager allows Exploiting Incorrectly Configure... |
| CVE-2024-21961 | MEDIUM | 6 | 0.3% | Feb 13, 2026 | Improper restriction of operations within the bounds of a memory buffer in PCIe® Link could allow an attacker with acces... |
| CVE-2024-36319 | MEDIUM | 6.3 | 0.1% | Feb 12, 2026 | Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously cr... |
| CVE-2024-50618 | MEDIUM | 4.3 | 0.2% | Feb 11, 2026 | A Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 all... |
| CVE-2024-26479 | MEDIUM | 5.3 | 0.5% | Feb 11, 2026 | An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the Command... |
| CVE-2024-26478 | MEDIUM | 5.3 | 0.4% | Feb 11, 2026 | An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the /api/us... |
| CVE-2024-36316 | MEDIUM | 5.5 | 0.2% | Feb 11, 2026 | The integer overflow vulnerability within AMD Graphics driver could allow an attacker to bypass size checks potentially ... |
| CVE-2024-56807 | MEDIUM | 5.5 | 0.1% | Feb 11, 2026 | An out-of-bounds read vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local netwo... |
| CVE-2024-36311 | MEDIUM | 4.6 | 0.1% | Feb 10, 2026 | A Time-of-check time-of-use (TOCTOU) race condition in the SMM communications buffer could allow a privileged attacker t... |
| CVE-2024-36310 | MEDIUM | 4.6 | 0.2% | Feb 10, 2026 | Improper input validation in the SMM communications buffer could allow a privileged attacker to perform an out of bounds... |
| CVE-2024-21953 | MEDIUM | 5.9 | 0.2% | Feb 10, 2026 | Improper input validation in IOMMU could allow a malicious hypervisor to reconfigure IOMMU registers resulting in loss o... |
| CVE-2024-54192 | MEDIUM | 5.5 | 0.1% | Feb 10, 2026 | An issue inTcpreplay v4.5.1 allows a local attacker to cause a denial of service via a crafted file to the tcpedit_dlt_g... |
| CVE-2024-52334 | MEDIUM | 6.3 | 0.3% | Feb 10, 2026 | A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07). The affected application does not ... |
| CVE-2024-51451 | MEDIUM | 6.5 | 0.2% | Feb 4, 2026 | IBM Concert 1.0.0 through 2.1.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HO... |
| CVE-2024-43181 | MEDIUM | 6.3 | 0.2% | Feb 4, 2026 | IBM Concert 1.0.0 through 2.1.0 does not invalidate session after logout which could allow an authenticated user to impe... |
| CVE-2024-40685 | MEDIUM | 4.3 | 0.1% | Feb 4, 2026 | IBM Operations Analytics – Log Analysis versions 1.3.5.0 through 1.3.8.3 and IBM SmartCloud Analytics – Log Analysis are... |
| CVE-2024-39724 | MEDIUM | 5.3 | 0.3% | Feb 4, 2026 | IBM Db2 Big SQL on Cloud Pak for Data versions 7.6 (on CP4D 4.8), 7.7 (on CP4D 5.0), and 7.8 (on CP4D 5.1) do not proper... |
| CVE-2024-4147 | MEDIUM | 6.5 | 0.4% | Feb 2, 2026 | In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to delete p... |
| CVE-2024-9432 | MEDIUM | 6.9 | 0.1% | Jan 30, 2026 | Cleartext Storage of Sensitive Information vulnerability in OpenText™ Vertica allows Retrieve Embedded Sensitive Data. ... |
| CVE-2024-54855 | MEDIUM | 6.4 | 0.3% | Jan 13, 2026 | fabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain static keys for the SSH service, allowing attac... |
| CVE-2024-14020 | MEDIUM | 5 | 0.3% | Jan 7, 2026 | A weakness has been identified in carboneio carbone up to fbcd349077ad0e8748be73eab2a82ea92b6f8a7e. This impacts an unkn... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now