2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-55074 | CRITICAL | 9 | 0.6% | Jan 6, 2025 | The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a cra... |
| CVE-2024-55408 | MEDIUM | 5.3 | 0.2% | Jan 6, 2025 | An improper access control vulnerability in the AsusSAIO.sys driver may lead to the misuse of software functionality uti... |
| CVE-2024-55407 | HIGH | 7.8 | 0.2% | Jan 6, 2025 | An issue in the DeviceloControl function of ITE Tech. Inc ITE IO Access v1.0.0.0 allows attackers to perform arbitrary p... |
| CVE-2024-46209 | MEDIUM | 5.4 | 0.4% | Jan 6, 2025 | A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attacke... |
| CVE-2024-35498 | MEDIUM | 6.1 | 0.4% | Jan 6, 2025 | A cross-site scripting (XSS) vulnerability in Grav v1.7.45 allows attackers to execute arbitrary web scripts or HTML via... |
| CVE-2024-56828 | CRITICAL | 9.8 | 0.9% | Jan 6, 2025 | File Upload vulnerability in ChestnutCMS through 1.5.0. Based on the code analysis, it was determined that the /api/memb... |
| CVE-2024-55629 | HIGH | 7.5 | 0.5% | Jan 6, 2025 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-55628 | HIGH | 7.5 | 0.7% | Jan 6, 2025 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-55627 | HIGH | 7.5 | 1.0% | Jan 6, 2025 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-55626 | MEDIUM | 5.5 | 0.2% | Jan 6, 2025 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-55529 | CRITICAL | 9.8 | 0.6% | Jan 6, 2025 | Z-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \zb_users\theme\shell\template. |
| CVE-2024-54880 | CRITICAL | 9.1 | 0.9% | Jan 6, 2025 | SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user t... |
| CVE-2024-54879 | CRITICAL | 9.1 | 0.9% | Jan 6, 2025 | SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user t... |
| CVE-2024-46622 | CRITICAL | 9.8 | 0.6% | Jan 6, 2025 | An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software 7.0.x before 7.0.38, 7.... |
| CVE-2024-46073 | MEDIUM | 6.1 | 0.4% | Jan 6, 2025 | A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is... |
| CVE-2024-56769 | MEDIUM | 5.5 | 0.2% | Jan 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: media: dvb-frontends: dib3000mb: fix uninit-value i... |
| CVE-2024-56768 | MEDIUM | 5.5 | 0.2% | Jan 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix bpf_get_smp_processor_id() on !CONFIG_SMP ... |
| CVE-2024-56767 | MEDIUM | 5.5 | 0.2% | Jan 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: at_xdmac: avoid null_prt_deref in at_xdm... |
| CVE-2024-56766 | HIGH | 7.8 | 0.2% | Jan 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: fix double free in atmel_pmecc_create... |
| CVE-2024-56765 | HIGH | 7.8 | 0.2% | Jan 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries/vas: Add close() callback in vas_vm... |
| CVE-2024-56764 | HIGH | 7.8 | 0.2% | Jan 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: ublk: detach gendisk from ublk device if add_disk()... |
| CVE-2024-56763 | MEDIUM | 5.5 | 0.2% | Jan 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: tracing: Prevent bad count for tracing_cpumask_writ... |
| CVE-2024-56762 | — | — | — | Jan 6, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-56761 | MEDIUM | 5.5 | 0.2% | Jan 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: x86/fred: Clear WFE in missing-ENDBRANCH #CPs An i... |
| CVE-2024-56760 | MEDIUM | 5.5 | 0.2% | Jan 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: PCI/MSI: Handle lack of irqdomain gracefully Alexa... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now