2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-28547MEDIUM6.5Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the firewallEn parameter of formSetFirewallCfg function.
CVE-2024-28537CRITICAL9.8Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the page parameter of fromNatStaticSetting function.
CVE-2024-27774MEDIUM6.5 Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-259: Use of Hard-coded Password may allow disclosing ...
CVE-2024-27773HIGH8.8 Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-348: Use of Less Trusted Source may allow RCE
CVE-2024-27772HIGH8.8 Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-78: 'OS Command Injection' may allow RCE
CVE-2024-27771HIGH8.8 Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE
CVE-2024-27770HIGH8.8 Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-23: Relative Path Traversal
CVE-2024-27769HIGH8.8 Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-200: Exposure of Sensitive Information to an Unautho...
CVE-2024-27768CRITICAL9.8 Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE
CVE-2024-27767CRITICAL9.8 CWE-287: Improper Authentication may allow Authentication Bypass
CVE-2024-2496MEDIUM5.5A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occu...
CVE-2024-2002HIGH7.5A double-free vulnerability was found in libdwarf. In a multiply-corrupted DWARF object, libdwarf may try to dealloc(fre...
CVE-2024-28550MEDIUM4.3Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the filePath parameter of formExpandDlnaFile function.
CVE-2024-20767HIGH7.4ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could resu...
CVE-2024-26641MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: make sure to pull inner header in __ip6...
CVE-2024-26640MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tcp: add sanity checks to rx zerocopy TCP rx zeroc...
CVE-2024-26639Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-26638MEDIUM4.4In the Linux kernel, the following vulnerability has been resolved: nbd: always initialize struct msghdr completely sy...
CVE-2024-26637MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: rely on mac80211 debugfs handling for...
CVE-2024-26636MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: llc: make llc_ui_sendmsg() more robust against bond...
CVE-2024-26635MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: llc: Drop support for ETH_P_TR_802_2. syzbot repor...
CVE-2024-26634MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: fix removing a namespace with conflicting altn...
CVE-2024-26633MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: fix NEXTHDR_FRAGMENT handling in ip6_tn...
CVE-2024-26632MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: block: Fix iterating over an empty bio with bio_for...
CVE-2024-26631MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: fix data-race in ipv6_mc_down / mld_if...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now