2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39478 | MEDIUM | 5.5 | 0.2% | Jul 5, 2024 | In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA te... |
| CVE-2024-39477 | MEDIUM | 5.5 | 0.2% | Jul 5, 2024 | In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: do not call vma_add_reservation upon EN... |
| CVE-2024-39476 | MEDIUM | 5.5 | 0.2% | Jul 5, 2024 | In the Linux kernel, the following vulnerability has been resolved: md/raid5: fix deadlock that raid5d() wait for itsel... |
| CVE-2024-39475 | MEDIUM | 5.5 | 0.2% | Jul 5, 2024 | In the Linux kernel, the following vulnerability has been resolved: fbdev: savage: Handle err return when savagefb_chec... |
| CVE-2024-39474 | MEDIUM | 5.5 | 0.2% | Jul 5, 2024 | In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: fix vmalloc which may return null if ca... |
| CVE-2024-39473 | MEDIUM | 5.5 | 0.2% | Jul 5, 2024 | In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Fix input format query of... |
| CVE-2024-39472 | MEDIUM | 5.5 | 0.2% | Jul 5, 2024 | In the Linux kernel, the following vulnerability has been resolved: xfs: fix log recovery buffer allocation for the leg... |
| CVE-2024-34481 | MEDIUM | 6.1 | 0.6% | Jul 5, 2024 | drupal-wiki.com Drupal Wiki before 8.31.1 allows XSS via comments, captions, and image titles of a Wiki page. |
| CVE-2024-32498 | MEDIUM | 6.5 | 0.8% | Jul 5, 2024 | An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file... |
| CVE-2024-39936 | MEDIUM | 5.9 | 0.5% | Jul 4, 2024 | An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x th... |
| CVE-2024-6511 | MEDIUM | 6.1 | 0.3% | Jul 4, 2024 | A vulnerability classified as problematic was found in y_project RuoYi up to 4.7.9. Affected by this vulnerability is th... |
| CVE-2024-37474 | MEDIUM | 5.4 | 0.3% | Jul 4, 2024 | Cross Site Scripting (XSS) vulnerability in Automattic Newspack Ads allows Stored XSS.This issue affects Newspack Ads: f... |
| CVE-2024-37472 | MEDIUM | 6.1 | 0.3% | Jul 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WofficeIO Woffice ... |
| CVE-2024-37471 | MEDIUM | 6.1 | 0.3% | Jul 4, 2024 | Cross Site Scripting (XSS) vulnerability in WofficeIO Woffice Core allows Reflected XSS.This issue affects Woffice Core:... |
| CVE-2024-37476 | MEDIUM | 5.4 | 0.3% | Jul 4, 2024 | Cross Site Scripting (XSS) vulnerability in Automattic Newspack Campaigns allows Stored XSS.This issue affects Newspack ... |
| CVE-2024-39929 | MEDIUM | 5.4 | 41.2% | Jul 4, 2024 | Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filenam... |
| CVE-2024-22277 | MEDIUM | 5.4 | 0.3% | Jul 4, 2024 | VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to ... |
| CVE-2024-39211 | MEDIUM | 5.3 | 1.1% | Jul 4, 2024 | Kaiten 57.128.8 allows remote attackers to enumerate user accounts via a crafted POST request, because a login response ... |
| CVE-2024-6434 | MEDIUM | 4.3 | 0.6% | Jul 4, 2024 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in a... |
| CVE-2024-39884 | MEDIUM | 6.2 | 0.9% | Jul 4, 2024 | A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of... |
| CVE-2024-1574 | MEDIUM | 6.7 | 0.2% | Jul 4, 2024 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in the licensing featur... |
| CVE-2024-1573 | MEDIUM | 5.9 | 0.6% | Jul 4, 2024 | Missing Authentication for Critical Function vulnerability in the mobile monitoring feature of Mitsubishi Electric GENES... |
| CVE-2024-5641 | MEDIUM | 5.4 | 0.3% | Jul 4, 2024 | The One Click Order Re-Order plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca... |
| CVE-2024-3639 | MEDIUM | 5.4 | 0.3% | Jul 4, 2024 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pos... |
| CVE-2024-3638 | MEDIUM | 5.4 | 0.3% | Jul 4, 2024 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Marq... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now