2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53104 | HIGH | 7.8 | 3.3% | Dec 2, 2024 | In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS... |
| CVE-2024-53103 | HIGH | 7.8 | 0.2% | Dec 2, 2024 | In the Linux kernel, the following vulnerability has been resolved: hv_sock: Initializing vsk->trans to NULL to prevent... |
| CVE-2024-20138 | HIGH | 7.5 | 0.3% | Dec 2, 2024 | In wlan driver, there is a possible out of bound read due to improper input validation. This could lead to remote inform... |
| CVE-2024-20137 | HIGH | 7.5 | 1.2% | Dec 2, 2024 | In wlan driver, there is a possible client disconnection due to improper handling of exceptional conditions. This could ... |
| CVE-2024-20129 | HIGH | 7.5 | 0.3% | Dec 2, 2024 | In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of ... |
| CVE-2024-20128 | HIGH | 7.5 | 0.3% | Dec 2, 2024 | In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of ... |
| CVE-2024-20127 | HIGH | 7.5 | 0.3% | Dec 2, 2024 | In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of ... |
| CVE-2024-53605 | HIGH | 7.5 | 0.4% | Dec 2, 2024 | Incorrect access control in the component content://com.handcent.messaging.provider.MessageProvider/ of Handcent NextSMS... |
| CVE-2024-53750 | HIGH | 7.1 | 0.1% | Dec 1, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Maeve Lander PayPal Responder allows Stored XSS.This issue affects Pa... |
| CVE-2024-53742 | HIGH | 7.1 | 0.2% | Dec 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prism I.T. Systems... |
| CVE-2024-45520 | HIGH | 7.5 | 0.5% | Dec 1, 2024 | WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1 allows a remote Denial of Service because of memory corruption dur... |
| CVE-2024-53778 | HIGH | 7.1 | 0.2% | Nov 30, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Essential Marketer Essential Breadcrumbs essential-breadcrumbs allows... |
| CVE-2024-53783 | HIGH | 7.6 | 0.5% | Nov 30, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Anzar Ahmed Ni Woo... |
| CVE-2024-11998 | HIGH | 7.5 | 0.4% | Nov 30, 2024 | A vulnerability was found in code-projects Farmacia 1.0. It has been declared as critical. This vulnerability affects un... |
| CVE-2024-43703 | HIGH | 8.1 | 0.4% | Nov 30, 2024 | Software installed and run as a non-privileged user may conduct improper GPU system calls to achieve unauthorised reads ... |
| CVE-2024-43702 | HIGH | 8.1 | 0.3% | Nov 30, 2024 | Software installed and run as a non-privileged user may conduct improper GPU system calls to allow unprivileged access t... |
| CVE-2024-53623 | HIGH | 7.5 | 0.4% | Nov 29, 2024 | Incorrect access control in the component l_0_0.xml of TP-Link ARCHER-C7 v5 allows attackers to access sensitive informa... |
| CVE-2024-36612 | HIGH | 7.5 | 0.6% | Nov 29, 2024 | Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers. |
| CVE-2024-35371 | HIGH | 7.5 | 0.5% | Nov 29, 2024 | Ant-Media-Serverv2.8.2 is affected by Improper Output Neutralization for Logs. The vulnerability stems from insufficient... |
| CVE-2024-53980 | HIGH | 7.5 | 0.7% | Nov 29, 2024 | RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ... |
| CVE-2024-53979 | HIGH | 8.2 | 0.1% | Nov 29, 2024 | ibm.ibm_zhmc is an Ansible collection for the IBM Z HMC. The Ansible collection "ibm.ibm_zhmc" writes password-like prop... |
| CVE-2024-53865 | HIGH | 8.2 | 0.1% | Nov 29, 2024 | zhmcclient is a pure Python client library for the IBM Z HMC Web Services API. In affected versions the Python package "... |
| CVE-2024-53861 | HIGH | 7.5 | 0.8% | Nov 29, 2024 | pyjwt is a JSON Web Token implementation in Python. An incorrect string comparison is run for `iss` checking, resulting ... |
| CVE-2024-53848 | HIGH | 7.1 | 0.1% | Nov 29, 2024 | check-jsonschema is a CLI and set of pre-commit hooks for jsonschema validation. The default cache strategy uses the bas... |
| CVE-2024-36611 | HIGH | 7.5 | 0.8% | Nov 29, 2024 | In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to ad... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now