2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1899MEDIUM5.3An issue in the anchors subparser of Showdownjs versions <= 2.1.0 could allow a remote attacker to cause denial of servi...
CVE-2024-27084Rejected reason: This CVE is a duplicate of CVE-2024-1631.
CVE-2024-26455HIGH7.5fluent-bit 2.2.2 contains a Use-After-Free vulnerability in /fluent-bit/plugins/custom_calyptia/calyptia.c.
CVE-2024-25770MEDIUM4.3libming 0.4.8 contains a memory leak vulnerability in /libming/src/actioncompiler/listaction.c.
CVE-2024-25768HIGH7.5OpenDMARC 1.4.2 contains a null pointer dereference vulnerability in /OpenDMARC/libopendmarc/opendmarc_policy.c.
CVE-2024-27088MEDIUM5.5es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into ...
CVE-2024-27087MEDIUM5.4Kirby is a content management system. The new link field introduced in Kirby 4 allows several different link types that ...
CVE-2024-27081HIGH8.8ESPHome is a system to control your ESP8266/ESP32. A security misconfiguration in the edit configuration file API in the...
CVE-2024-25767MEDIUM6.5nanomq 0.21.2 contains a Use-After-Free vulnerability in /nanomq/nng/src/core/socket.c.
CVE-2024-24402CRITICAL9.8An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/n...
CVE-2024-24401CRITICAL9.8SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payl...
CVE-2024-27456CRITICAL9.1rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions for the .rb files.
CVE-2024-27455CRITICAL9.1In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token wh...
CVE-2024-27454HIGH7.5orjson.loads in orjson before 3.9.15 does not limit recursion for deeply nested JSON documents.
CVE-2024-27447CRITICAL9.8pretix before 2024.1.1 mishandles file validation.
CVE-2024-27444CRITICAL9.8langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-...
CVE-2024-27359HIGH7.5Certain WithSecure products allow a Denial of Service because the engine scanner can go into an infinite loop when proce...
CVE-2024-27350MEDIUM5.9Amazon Fire OS 7 before 7.6.6.9 and 8 before 8.1.0.3 allows Fire TV applications to establish local ADB (Android Debug B...
CVE-2024-26606MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: binder: signal epoll threads of self-work In (e)po...
CVE-2024-26605MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix deadlock when enabling ASPM A last m...
CVE-2024-26604MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Revert "kobject: Remove redundant checks for whethe...
CVE-2024-26603MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Stop relying on userspace for info to faul...
CVE-2024-26602MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sched/membarrier: reduce the ability to hammer on s...
CVE-2024-26601MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ext4: regenerate buddy after block freeing failed i...
CVE-2024-26600MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: phy: ti: phy-omap-usb2: Fix NULL pointer dereferenc...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now