2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53095 | CRITICAL | 9.8 | 0.2% | Nov 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free of network namespac... |
| CVE-2024-53094 | MEDIUM | 5.5 | 0.2% | Nov 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Add sendpage_ok() check to disable MSG_SP... |
| CVE-2024-53093 | MEDIUM | 5.5 | 0.2% | Nov 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: nvme-multipath: defer partition scanning We need t... |
| CVE-2024-53092 | MEDIUM | 5.5 | 0.2% | Nov 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: virtio_pci: Fix admin vq cleanup by using correct i... |
| CVE-2024-53091 | MEDIUM | 5.5 | 0.2% | Nov 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: bpf: Add sk_is_inet and IS_ICSK check in tls_sw_has... |
| CVE-2024-53090 | MEDIUM | 5.5 | 0.2% | Nov 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: afs: Fix lock recursion afs_wake_up_async_call() c... |
| CVE-2024-53089 | MEDIUM | 5.5 | 0.2% | Nov 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Mark hrtimer to expire in hard inte... |
| CVE-2024-51337 | LOW | 3.5 | 0.6% | Nov 21, 2024 | Cross Site Scripting vulnerability in Gibbon before v.27.0.01 and fixed in v.28.0.00 allows a remote attacker to obtain ... |
| CVE-2024-53432 | HIGH | 7.5 | 0.7% | Nov 21, 2024 | While parsing certain malformed PLY files, PCL version 1.14.1 crashes due to an uncaught std::out_of_range exception in ... |
| CVE-2024-53335 | HIGH | 7.8 | 0.3% | Nov 21, 2024 | TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in downloadFlile.cgi. |
| CVE-2024-53334 | HIGH | 8.8 | 0.7% | Nov 21, 2024 | TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in infostat.cgi. |
| CVE-2024-53333 | MEDIUM | 6.3 | 17.5% | Nov 21, 2024 | TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. Th... |
| CVE-2024-52309 | MEDIUM | 5.1 | 0.6% | Nov 21, 2024 | SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azur... |
| CVE-2024-52307 | MEDIUM | 5.6 | 0.5% | Nov 21, 2024 | authentik is an open-source identity provider. Due to the usage of a non-constant time comparison for the /-/metrics/ en... |
| CVE-2024-52289 | CRITICAL | 9.8 | 1.1% | Nov 21, 2024 | authentik is an open-source identity provider. Redirect URIs in the OAuth2 provider in authentik are checked by RegEx co... |
| CVE-2024-52287 | HIGH | 7.2 | 0.6% | Nov 21, 2024 | authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was pos... |
| CVE-2024-48288 | HIGH | 8 | 10.3% | Nov 21, 2024 | TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification... |
| CVE-2024-48286 | HIGH | 8 | 12.4% | Nov 21, 2024 | Linksys E3000 1.0.06.002_US is vulnerable to command injection via the diag_ping_start function. |
| CVE-2024-52803 | CRITICAL | 9.8 | 2.3% | Nov 21, 2024 | LLama Factory enables fine-tuning of large language models. A critical remote OS command injection vulnerability has bee... |
| CVE-2024-52799 | HIGH | 8.2 | 0.2% | Nov 21, 2024 | Argo Workflows Chart is used to set up argo and its needed dependencies through one command. Prior to 0.44.0, the workfl... |
| CVE-2024-49529 | MEDIUM | 5.5 | 0.3% | Nov 21, 2024 | InDesign Desktop versions 19.0, 20.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to ... |
| CVE-2024-45517 | MEDIUM | 5.4 | 0.5% | Nov 21, 2024 | An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability in the /h... |
| CVE-2024-45513 | MEDIUM | 4.8 | 0.4% | Nov 21, 2024 | An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A stored Cross-Site Scripting (XSS) vulnerability ex... |
| CVE-2024-45194 | MEDIUM | 4.8 | 0.5% | Nov 21, 2024 | In Zimbra Collaboration (ZCS) 9.0 and 10.0, a vulnerability in the Webmail Modern UI allows execution of stored Cross-Si... |
| CVE-2024-8526 | MEDIUM | 5.9 | 0.6% | Nov 21, 2024 | A vulnerability in Automated Logic WebCTRL 7.0 could allow an attacker to send a maliciously crafted URL, which when vis... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now