2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-27798 | HIGH | 7.8 | 0.2% | May 14, 2024 | An authorization issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.7.5, macOS... |
| CVE-2024-27796 | HIGH | 7.8 | 0.3% | May 14, 2024 | The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 1... |
| CVE-2024-27793 | HIGH | 7.8 | 0.7% | May 14, 2024 | The issue was addressed with improved checks. This issue is fixed in iTunes 12.13.2 for Windows. Parsing a file may lead... |
| CVE-2024-27790 | HIGH | 7.5 | 0.5% | May 14, 2024 | Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases ho... |
| CVE-2024-27789 | MEDIUM | 5.5 | 0.6% | May 14, 2024 | A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS Monterey 12... |
| CVE-2024-27460 | MEDIUM | 6.7 | 1.7% | May 14, 2024 | A privilege escalation exists in the updater for Plantronics Hub 3.25.1 and below. |
| CVE-2024-27401 | HIGH | 7.1 | 0.3% | May 14, 2024 | In the Linux kernel, the following vulnerability has been resolved: firewire: nosy: ensure user_length is taken into ac... |
| CVE-2024-27400 | MEDIUM | 5.5 | 0.2% | May 14, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: once more fix the call oder in amdgpu_t... |
| CVE-2024-27399 | MEDIUM | 5.5 | 0.3% | May 14, 2024 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_... |
| CVE-2024-27398 | HIGH | 7.8 | 0.8% | May 14, 2024 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free bugs caused by sco_so... |
| CVE-2024-27397 | HIGH | 7 | 0.3% | May 14, 2024 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: use timestamp to check for se... |
| CVE-2024-27396 | HIGH | 7.8 | 0.2% | May 14, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: gtp: Fix Use-After-Free in gtp_dellink Since ... |
| CVE-2024-27395 | HIGH | 7.8 | 0.2% | May 14, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: Fix Use-After-Free in ovs_ct_exit... |
| CVE-2024-27394 | HIGH | 7.8 | 0.3% | May 14, 2024 | In the Linux kernel, the following vulnerability has been resolved: tcp: Fix Use-After-Free in tcp_ao_connect_init Sin... |
| CVE-2024-27393 | HIGH | 7.5 | 0.3% | May 14, 2024 | In the Linux kernel, the following vulnerability has been resolved: xen-netfront: Add missing skb_mark_for_recycle Not... |
| CVE-2024-27282 | MEDIUM | 6.6 | 0.6% | May 14, 2024 | An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it ... |
| CVE-2024-27281 | MEDIUM | 4.5 | 1.6% | May 14, 2024 | An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_option... |
| CVE-2024-27280 | CRITICAL | 9.8 | 2.4% | May 14, 2024 | A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3... |
| CVE-2024-27269 | MEDIUM | 6.8 | 0.4% | May 14, 2024 | IBM QRadar SIEM 7.5 could allow a privileged user to configure user management that would disclose unintended sensitive ... |
| CVE-2024-27082 | MEDIUM | 5.4 | 0.9% | May 14, 2024 | Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 are vulnerabl... |
| CVE-2024-26517 | CRITICAL | 9.1 | 0.8% | May 14, 2024 | SQL Injection vulnerability in School Task Manager v.1.0 allows a remote attacker to obtain sensitive information via a ... |
| CVE-2024-26306 | MEDIUM | 5.9 | 1.1% | May 14, 2024 | iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channe... |
| CVE-2024-25662 | MEDIUM | 6.1 | 0.4% | May 14, 2024 | Oxygen XML Web Author v26.0.0 and older and Oxygen Content Fusion v6.1 and older are vulnerable to Cross-Site Scripting ... |
| CVE-2024-25641 | HIGH | 7.2 | 86.3% | May 14, 2024 | Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file writ... |
| CVE-2024-25581 | HIGH | 7.5 | 1.1% | May 14, 2024 | When incoming DNS over HTTPS support is enabled using the nghttp2 provider, and queries are routed to a tcp-only or DNS ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now