2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42239 | MEDIUM | 5.5 | 0.2% | Aug 7, 2024 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fail bpf_timer_cancel when callback is being c... |
| CVE-2024-42238 | MEDIUM | 5.5 | 0.2% | Aug 7, 2024 | In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Return error if block header over... |
| CVE-2024-42237 | MEDIUM | 5.5 | 0.2% | Aug 7, 2024 | In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Validate payload length before pr... |
| CVE-2024-42236 | MEDIUM | 5.5 | 0.2% | Aug 7, 2024 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: configfs: Prevent OOB read/write in us... |
| CVE-2024-42235 | MEDIUM | 5.5 | 0.2% | Aug 7, 2024 | In the Linux kernel, the following vulnerability has been resolved: s390/mm: Add NULL pointer check to crst_table_free(... |
| CVE-2024-42234 | MEDIUM | 5.5 | 0.2% | Aug 7, 2024 | In the Linux kernel, the following vulnerability has been resolved: mm: fix crashes from deferred split racing folio mi... |
| CVE-2024-42232 | MEDIUM | 5.5 | 0.2% | Aug 7, 2024 | In the Linux kernel, the following vulnerability has been resolved: libceph: fix race between delayed_work() and ceph_m... |
| CVE-2024-41432 | MEDIUM | 5.3 | 0.4% | Aug 7, 2024 | An IP Spoofing vulnerability has been discovered in Likeshop up to 2.5.7.20210811. This issue allows an attacker to repl... |
| CVE-2024-41252 | MEDIUM | 6.5 | 0.4% | Aug 7, 2024 | An Incorrect Access Control vulnerability was found in /smsa/admin_student_register_approval.php and /smsa/admin_student... |
| CVE-2024-41251 | MEDIUM | 6.5 | 0.4% | Aug 7, 2024 | An Incorrect Access Control vulnerability was found in /smsa/admin_teacher_register_approval.php and /smsa/admin_teacher... |
| CVE-2024-41249 | MEDIUM | 5.3 | 0.6% | Aug 7, 2024 | An Incorrect Access Control vulnerability was found in /smsa/view_subject.php in Kashipara Responsive School Management ... |
| CVE-2024-41248 | MEDIUM | 5.3 | 0.5% | Aug 7, 2024 | An Incorrect Access Control vulnerability was found in /smsa/add_subject.php and /smsa/add_subject_submit.php in Kashipa... |
| CVE-2024-41247 | MEDIUM | 5.3 | 0.4% | Aug 7, 2024 | An Incorrect Access Control vulnerability was found in /smsa/add_class.php and /smsa/add_class_submit.php in Kashipara R... |
| CVE-2024-41246 | MEDIUM | 5.3 | 0.5% | Aug 7, 2024 | An Incorrect Access Control vulnerability was found in /smsa/admin_dashboard.php in Kashipara Responsive School Manageme... |
| CVE-2024-43045 | MEDIUM | 6.3 | 4.3% | Aug 7, 2024 | Jenkins 2.470 and earlier, LTS 2.452.3 and earlier does not perform a permission check in an HTTP endpoint, allowing att... |
| CVE-2024-7355 | MEDIUM | 5.4 | 0.3% | Aug 7, 2024 | The Organization chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_input’ and 'node... |
| CVE-2024-7353 | MEDIUM | 5.4 | 0.3% | Aug 7, 2024 | The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's accept_str... |
| CVE-2024-7267 | MEDIUM | 6.5 | 0.6% | Aug 7, 2024 | Exposure of Sensitive Information vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy E... |
| CVE-2024-7266 | MEDIUM | 4.3 | 0.3% | Aug 7, 2024 | Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP al... |
| CVE-2024-42222 | MEDIUM | 4.3 | 1.0% | Aug 7, 2024 | In Apache CloudStack 4.19.1.0, a regression in the network listing API allows unauthorised list access of network detail... |
| CVE-2024-6494 | MEDIUM | 6.1 | 0.3% | Aug 7, 2024 | The WordPress File Upload WordPress plugin before 4.24.8 does not properly sanitize and escape certain parameters, which... |
| CVE-2024-3973 | MEDIUM | 4.8 | 0.3% | Aug 7, 2024 | The House Manager WordPress plugin through 1.0.8.4 does not sanitise and escape a parameter before outputting it back i... |
| CVE-2024-37403 | MEDIUM | 5.5 | 0.5% | Aug 7, 2024 | Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to pr... |
| CVE-2024-34788 | MEDIUM | 6.5 | 0.9% | Aug 7, 2024 | An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to ac... |
| CVE-2024-34636 | MEDIUM | 5.5 | 0.1% | Aug 7, 2024 | Use of implicit intent for sensitive communication in Samsung Email prior to version 6.1.94.2 allows local attackers to ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now