2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-49870MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: cachefiles: fix dentry leak in cachefiles_open_file...
CVE-2024-49869HIGH7.8In the Linux kernel, the following vulnerability has been resolved: btrfs: send: fix buffer overflow detection when cop...
CVE-2024-49868MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: fix a NULL pointer dereference when failed t...
CVE-2024-49867MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: wait for fixup workers before stopping clean...
CVE-2024-49866MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: tracing/timerlat: Fix a race during cpuhp processin...
CVE-2024-49865HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/xe/vm: move xa_alloc to prevent UAF Evil user ...
CVE-2024-49864MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix a race between socket set up and I/O thr...
CVE-2024-49863MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: vhost/scsi: null-ptr-dereference in vhost_scsi_get_...
CVE-2024-49368CRITICAL9.8Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logr...
CVE-2024-49367HIGH7.5Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, the log path of nginxui is co...
CVE-2024-49366HIGH7.5Nginx UI is a web user interface for the Nginx web server. Nginx UI v2.0.0-beta.35 and earlier gets the value from the j...
CVE-2024-40746MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component < 5.1.1 allows remote attackers to execut...
CVE-2024-48930HIGH8.7secp256k1-node is a Node.js binding for an Optimized C library for EC operations on curve secp256k1. In `elliptic`-based...
CVE-2024-8305MEDIUM6.5prepareUnique index may cause secondaries to crash due to incorrect enforcement of index constraints on secondaries, whe...
CVE-2024-6519HIGH8.2A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to ...
CVE-2024-45309HIGH7.5OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthentica...
CVE-2024-49862HIGH7.1In the Linux kernel, the following vulnerability has been resolved: powercap: intel_rapl: Fix off by one in get_rpi() ...
CVE-2024-49861HIGH7.1In the Linux kernel, the following vulnerability has been resolved: bpf: Fix helper writes to read-only maps Lonial fo...
CVE-2024-49860HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ACPI: sysfs: validate return type of _STR method O...
CVE-2024-49859MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to check atomic_file in f2fs ioctl interf...
CVE-2024-49858MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: efistub/tpm: Use ACPI reclaim memory for event log ...
CVE-2024-49857MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: set the cipher for secured NDP ...
CVE-2024-49856MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: x86/sgx: Fix deadlock in SGX NUMA node search When...
CVE-2024-49855HIGH7In the Linux kernel, the following vulnerability has been resolved: nbd: fix race between timeout and normal completion...
CVE-2024-49854HIGH7.8In the Linux kernel, the following vulnerability has been resolved: block, bfq: fix uaf for accessing waker_bfqq after ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now