2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53136 | MEDIUM | 4.7 | 0.2% | Dec 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: mm: revert "mm: shmem: fix data-race in shmem_getat... |
| CVE-2024-53135 | MEDIUM | 6.5 | 0.2% | Dec 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Bury Intel PT virtualization (guest/host ... |
| CVE-2024-53134 | MEDIUM | 5.5 | 0.2% | Dec 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx93-blk-ctrl: correct remove path The ... |
| CVE-2024-53133 | HIGH | 7.8 | 0.2% | Dec 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Handle dml allocation failure to a... |
| CVE-2024-53132 | MEDIUM | 5.5 | 0.2% | Dec 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Fix "Missing outer runtime PM protection... |
| CVE-2024-53131 | MEDIUM | 5.5 | 0.2% | Dec 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix null-ptr-deref in block_touch_buffer tr... |
| CVE-2024-53130 | MEDIUM | 5.5 | 0.2% | Dec 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix null-ptr-deref in block_dirty_buffer tr... |
| CVE-2024-53129 | MEDIUM | 5.5 | 0.2% | Dec 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: vop: Fix a dereferenced before check ... |
| CVE-2024-53128 | MEDIUM | 5.5 | 0.2% | Dec 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: sched/task_stack: fix object_is_on_stack() for KASA... |
| CVE-2024-53127 | MEDIUM | 5.5 | 0.2% | Dec 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: Revert "mmc: dw_mmc: Fix IDMAC operation with pages... |
| CVE-2024-53126 | HIGH | 7.8 | 0.2% | Dec 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: vdpa: solidrun: Fix UB bug with devres In psnet_op... |
| CVE-2024-40745 | MEDIUM | 5.4 | 0.2% | Dec 4, 2024 | Reflected Cross site scripting vulnerability in Convert Forms component for Joomla in versions before 4.4.8. |
| CVE-2024-40744 | CRITICAL | 9.8 | 0.5% | Dec 4, 2024 | Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8. |
| CVE-2024-12056 | LOW | 2.3 | 0.3% | Dec 4, 2024 | The Client secret is not checked when using the OAuth Password grant type. By exploiting this vulnerability, an attacke... |
| CVE-2024-7488 | MEDIUM | 5.3 | 0.3% | Dec 4, 2024 | Integer Overflow or Wraparound, Improper Validation of Specified Quantity in Input vulnerability in RestApp Inc. Online ... |
| CVE-2024-53125 | MEDIUM | 5.5 | 0.2% | Dec 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: bpf: sync_linked_regs() must preserve subreg_def R... |
| CVE-2024-51465 | HIGH | 8.8 | 0.7% | Dec 4, 2024 | IBM App Connect Enterprise Certified Container 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, and 12.3 could allow a remote authent... |
| CVE-2024-12138 | HIGH | 8.8 | 0.7% | Dec 4, 2024 | A vulnerability classified as critical was found in horilla up to 1.2.1. This vulnerability affects the function request... |
| CVE-2024-11935 | MEDIUM | 6.4 | 0.3% | Dec 4, 2024 | The Email Address Obfuscation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ paramete... |
| CVE-2024-8962 | MEDIUM | 5.4 | 0.3% | Dec 4, 2024 | The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG F... |
| CVE-2024-8894 | HIGH | 8.1 | 0.2% | Dec 4, 2024 | Out-of-bounds Write vulnerability was discovered in Open Design Alliance Drawings SDK before 2025.10. Reading crafted DW... |
| CVE-2024-54158 | MEDIUM | 5.3 | 0.3% | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding |
| CVE-2024-54157 | MEDIUM | 6.5 | 0.6% | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector |
| CVE-2024-54156 | MEDIUM | 6.5 | 0.3% | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack |
| CVE-2024-54155 | MEDIUM | 5.3 | 0.4% | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import wit... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now