2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-53136MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: mm: revert "mm: shmem: fix data-race in shmem_getat...
CVE-2024-53135MEDIUM6.5In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Bury Intel PT virtualization (guest/host ...
CVE-2024-53134MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx93-blk-ctrl: correct remove path The ...
CVE-2024-53133HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Handle dml allocation failure to a...
CVE-2024-53132MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Fix "Missing outer runtime PM protection...
CVE-2024-53131MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix null-ptr-deref in block_touch_buffer tr...
CVE-2024-53130MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix null-ptr-deref in block_dirty_buffer tr...
CVE-2024-53129MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: vop: Fix a dereferenced before check ...
CVE-2024-53128MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sched/task_stack: fix object_is_on_stack() for KASA...
CVE-2024-53127MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Revert "mmc: dw_mmc: Fix IDMAC operation with pages...
CVE-2024-53126HIGH7.8In the Linux kernel, the following vulnerability has been resolved: vdpa: solidrun: Fix UB bug with devres In psnet_op...
CVE-2024-40745MEDIUM5.4Reflected Cross site scripting vulnerability in Convert Forms component for Joomla in versions before 4.4.8.
CVE-2024-40744CRITICAL9.8Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8.
CVE-2024-12056LOW2.3The Client secret is not checked when using the OAuth Password grant type. By exploiting this vulnerability, an attacke...
CVE-2024-7488MEDIUM5.3Integer Overflow or Wraparound, Improper Validation of Specified Quantity in Input vulnerability in RestApp Inc. Online ...
CVE-2024-53125MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: sync_linked_regs() must preserve subreg_def R...
CVE-2024-51465HIGH8.8IBM App Connect Enterprise Certified Container 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, and 12.3 could allow a remote authent...
CVE-2024-12138HIGH8.8A vulnerability classified as critical was found in horilla up to 1.2.1. This vulnerability affects the function request...
CVE-2024-11935MEDIUM6.4The Email Address Obfuscation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ paramete...
CVE-2024-8962MEDIUM5.4The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG F...
CVE-2024-8894HIGH8.1Out-of-bounds Write vulnerability was discovered in Open Design Alliance Drawings SDK before 2025.10. Reading crafted DW...
CVE-2024-54158MEDIUM5.3In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding
CVE-2024-54157MEDIUM6.5In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector
CVE-2024-54156MEDIUM6.5In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack
CVE-2024-54155MEDIUM5.3In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import wit...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now