2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21539 | HIGH | 7.7 | 0.5% | Nov 19, 2024 | Versions of the package @eslint/plugin-kit before 0.2.3 are vulnerable to Regular Expression Denial of Service (ReDoS) d... |
| CVE-2024-50301 | HIGH | 7.1 | 0.3% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: security/keys: fix slab-out-of-bounds in key_task_p... |
| CVE-2024-50293 | HIGH | 7.8 | 0.2% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: net/smc: do not leave a dangling sk pointer in __sm... |
| CVE-2024-50286 | HIGH | 7 | 0.3% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-use-after-free in ksmbd_smb2_sessio... |
| CVE-2024-50283 | HIGH | 7.8 | 0.2% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-use-after-free in smb3_preauth_hash... |
| CVE-2024-50282 | HIGH | 7.8 | 0.3% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: add missing size check in amdgpu_debugf... |
| CVE-2024-50280 | HIGH | 7.8 | 0.2% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: dm cache: fix flushing uninitialized delayed_work o... |
| CVE-2024-50279 | HIGH | 7.1 | 0.3% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: dm cache: fix out-of-bounds access to the dirty bit... |
| CVE-2024-50278 | HIGH | 7.1 | 0.3% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: dm cache: fix potential out-of-bounds access on the... |
| CVE-2024-50276 | HIGH | 7.8 | 0.3% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: vertexcom: mse102x: Fix possible double free o... |
| CVE-2024-50275 | HIGH | 7 | 0.2% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: arm64/sve: Discard stale CPU state when handling SV... |
| CVE-2024-50274 | HIGH | 7.8 | 0.2% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: idpf: avoid vport access in idpf_get_link_ksettings... |
| CVE-2024-50269 | HIGH | 7.8 | 0.3% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: usb: musb: sunxi: Fix accessing an released usb phy... |
| CVE-2024-50268 | HIGH | 7.1 | 0.3% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: fix potential out of bounds in ucsi_ccg... |
| CVE-2024-50267 | HIGH | 7.8 | 0.3% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_edgeport: fix use after free in deb... |
| CVE-2024-50264 | HIGH | 7.8 | 0.4% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: Initialization of the dangling pointe... |
| CVE-2024-52587 | HIGH | 8.8 | 2.7% | Nov 18, 2024 | StepSecurity's Harden-Runner provides network egress filtering and runtime security for GitHub-hosted and self-hosted ru... |
| CVE-2024-52418 | HIGH | 7.1 | 0.3% | Nov 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CactusThemes Gamep... |
| CVE-2024-52417 | HIGH | 7.1 | 0.3% | Nov 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes ReConst... |
| CVE-2024-21287 | HIGH | 7.5 | 1.5% | Nov 18, 2024 | Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Pro... |
| CVE-2024-52583 | HIGH | 8.2 | 0.2% | Nov 18, 2024 | The WesHacks GitHub repository provides the official Hackathon competition website source code for the Muweilah Wesgreen... |
| CVE-2024-52304 | HIGH | 7.5 | 0.6% | Nov 18, 2024 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.10.11, the Python par... |
| CVE-2024-50804 | HIGH | 7.8 | 0.6% | Nov 18, 2024 | Insecure Permissions vulnerability in Micro-star International MSI Center Pro 2.1.37.0 allows a local attacker to execut... |
| CVE-2024-52303 | HIGH | 8.7 | 0.6% | Nov 18, 2024 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions starting with 3.10.6 and pri... |
| CVE-2024-51743 | HIGH | 8.8 | 0.7% | Nov 18, 2024 | MarkUs is a web application for the submission and grading of student assignments. In versions prior to 2.4.8, an arbitr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now