2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-27798HIGH7.8An authorization issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.7.5, macOS...
CVE-2024-27796HIGH7.8The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 1...
CVE-2024-27793HIGH7.8The issue was addressed with improved checks. This issue is fixed in iTunes 12.13.2 for Windows. Parsing a file may lead...
CVE-2024-27790HIGH7.5Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases ho...
CVE-2024-27789MEDIUM5.5A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS Monterey 12...
CVE-2024-27460MEDIUM6.7A privilege escalation exists in the updater for Plantronics Hub 3.25.1 and below.
CVE-2024-27401HIGH7.1In the Linux kernel, the following vulnerability has been resolved: firewire: nosy: ensure user_length is taken into ac...
CVE-2024-27400MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: once more fix the call oder in amdgpu_t...
CVE-2024-27399MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_...
CVE-2024-27398HIGH7.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free bugs caused by sco_so...
CVE-2024-27397HIGH7In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: use timestamp to check for se...
CVE-2024-27396HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: gtp: Fix Use-After-Free in gtp_dellink Since ...
CVE-2024-27395HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: Fix Use-After-Free in ovs_ct_exit...
CVE-2024-27394HIGH7.8In the Linux kernel, the following vulnerability has been resolved: tcp: Fix Use-After-Free in tcp_ao_connect_init Sin...
CVE-2024-27393HIGH7.5In the Linux kernel, the following vulnerability has been resolved: xen-netfront: Add missing skb_mark_for_recycle Not...
CVE-2024-27282MEDIUM6.6An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it ...
CVE-2024-27281MEDIUM4.5An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_option...
CVE-2024-27280CRITICAL9.8A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3...
CVE-2024-27269MEDIUM6.8IBM QRadar SIEM 7.5 could allow a privileged user to configure user management that would disclose unintended sensitive ...
CVE-2024-27082MEDIUM5.4Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 are vulnerabl...
CVE-2024-26517CRITICAL9.1SQL Injection vulnerability in School Task Manager v.1.0 allows a remote attacker to obtain sensitive information via a ...
CVE-2024-26306MEDIUM5.9iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channe...
CVE-2024-25662MEDIUM6.1Oxygen XML Web Author v26.0.0 and older and Oxygen Content Fusion v6.1 and older are vulnerable to Cross-Site Scripting ...
CVE-2024-25641HIGH7.2Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file writ...
CVE-2024-25581HIGH7.5When incoming DNS over HTTPS support is enabled using the nghttp2 provider, and queries are routed to a tcp-only or DNS ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now