2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-55074CRITICAL9The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a cra...
CVE-2024-55408MEDIUM5.3An improper access control vulnerability in the AsusSAIO.sys driver may lead to the misuse of software functionality uti...
CVE-2024-55407HIGH7.8An issue in the DeviceloControl function of ITE Tech. Inc ITE IO Access v1.0.0.0 allows attackers to perform arbitrary p...
CVE-2024-46209MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attacke...
CVE-2024-35498MEDIUM6.1A cross-site scripting (XSS) vulnerability in Grav v1.7.45 allows attackers to execute arbitrary web scripts or HTML via...
CVE-2024-56828CRITICAL9.8File Upload vulnerability in ChestnutCMS through 1.5.0. Based on the code analysis, it was determined that the /api/memb...
CVE-2024-55629HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2024-55628HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2024-55627HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2024-55626MEDIUM5.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2024-55529CRITICAL9.8Z-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \zb_users\theme\shell\template.
CVE-2024-54880CRITICAL9.1SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user t...
CVE-2024-54879CRITICAL9.1SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user t...
CVE-2024-46622CRITICAL9.8An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software 7.0.x before 7.0.38, 7....
CVE-2024-46073MEDIUM6.1A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is...
CVE-2024-56769MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: dvb-frontends: dib3000mb: fix uninit-value i...
CVE-2024-56768MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: Fix bpf_get_smp_processor_id() on !CONFIG_SMP ...
CVE-2024-56767MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: dmaengine: at_xdmac: avoid null_prt_deref in at_xdm...
CVE-2024-56766HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: fix double free in atmel_pmecc_create...
CVE-2024-56765HIGH7.8In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries/vas: Add close() callback in vas_vm...
CVE-2024-56764HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ublk: detach gendisk from ublk device if add_disk()...
CVE-2024-56763MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tracing: Prevent bad count for tracing_cpumask_writ...
CVE-2024-56762——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-56761MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: x86/fred: Clear WFE in missing-ENDBRANCH #CPs An i...
CVE-2024-56760MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: PCI/MSI: Handle lack of irqdomain gracefully Alexa...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now