2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-14040HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Increase weight to u16 In CLOS netwo...
CVE-2024-58355CRITICAL9.3Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking...
CVE-2024-58354CRITICAL9.9cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Acti...
CVE-2024-58353CRITICAL9.3Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly ac...
CVE-2024-58330HIGH7.5A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to ret...
CVE-2024-58023HIGH8.4Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive inform...
CVE-2024-5300MEDIUM5.6An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configura...
CVE-2024-51316HIGH7.5The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /g...
CVE-2024-51315CRITICAL9.8The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/Se...
CVE-2024-51314CRITICAL9.8The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/se...
CVE-2024-51312CRITICAL9.8The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/Se...
CVE-2024-51313CRITICAL9.8The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/Se...
CVE-2024-51311CRITICAL9.8The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/Se...
CVE-2024-58370MEDIUM6.5SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements includin...
CVE-2024-58369HIGH7.1SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or names...
CVE-2024-58368HIGH8.7SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing s...
CVE-2024-58367MEDIUM6.5SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations,...
CVE-2024-58366HIGH8.8SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when script...
CVE-2024-58365HIGH7.1SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls ...
CVE-2024-58364HIGH7.1SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing quer...
CVE-2024-58363MEDIUM6.3SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clau...
CVE-2024-58362HIGH8.8SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operati...
CVE-2024-58361HIGH7.1SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code ...
CVE-2024-58359HIGH7.1SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY r...
CVE-2024-58358MEDIUM6.9SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owne...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now