2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-53095CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free of network namespac...
CVE-2024-53094MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Add sendpage_ok() check to disable MSG_SP...
CVE-2024-53093MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nvme-multipath: defer partition scanning We need t...
CVE-2024-53092MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: virtio_pci: Fix admin vq cleanup by using correct i...
CVE-2024-53091MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: Add sk_is_inet and IS_ICSK check in tls_sw_has...
CVE-2024-53090MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: afs: Fix lock recursion afs_wake_up_async_call() c...
CVE-2024-53089MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Mark hrtimer to expire in hard inte...
CVE-2024-51337LOW3.5Cross Site Scripting vulnerability in Gibbon before v.27.0.01 and fixed in v.28.0.00 allows a remote attacker to obtain ...
CVE-2024-53432HIGH7.5While parsing certain malformed PLY files, PCL version 1.14.1 crashes due to an uncaught std::out_of_range exception in ...
CVE-2024-53335HIGH7.8TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in downloadFlile.cgi.
CVE-2024-53334HIGH8.8TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in infostat.cgi.
CVE-2024-53333MEDIUM6.3TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. Th...
CVE-2024-52309MEDIUM5.1SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azur...
CVE-2024-52307MEDIUM5.6authentik is an open-source identity provider. Due to the usage of a non-constant time comparison for the /-/metrics/ en...
CVE-2024-52289CRITICAL9.8authentik is an open-source identity provider. Redirect URIs in the OAuth2 provider in authentik are checked by RegEx co...
CVE-2024-52287HIGH7.2authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was pos...
CVE-2024-48288HIGH8TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification...
CVE-2024-48286HIGH8Linksys E3000 1.0.06.002_US is vulnerable to command injection via the diag_ping_start function.
CVE-2024-52803CRITICAL9.8LLama Factory enables fine-tuning of large language models. A critical remote OS command injection vulnerability has bee...
CVE-2024-52799HIGH8.2Argo Workflows Chart is used to set up argo and its needed dependencies through one command. Prior to 0.44.0, the workfl...
CVE-2024-49529MEDIUM5.5InDesign Desktop versions 19.0, 20.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to ...
CVE-2024-45517MEDIUM5.4An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability in the /h...
CVE-2024-45513MEDIUM4.8An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A stored Cross-Site Scripting (XSS) vulnerability ex...
CVE-2024-45194MEDIUM4.8In Zimbra Collaboration (ZCS) 9.0 and 10.0, a vulnerability in the Webmail Modern UI allows execution of stored Cross-Si...
CVE-2024-8526MEDIUM5.9A vulnerability in Automated Logic WebCTRL 7.0 could allow an attacker to send a maliciously crafted URL, which when vis...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now