2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-26943 | MEDIUM | 5.5 | 0.2% | May 1, 2024 | In the Linux kernel, the following vulnerability has been resolved: nouveau/dmem: handle kcalloc() allocation failure ... |
| CVE-2024-26942 | MEDIUM | 5.5 | 0.1% | May 1, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: phy: qcom: at803x: fix kernel panic with at803... |
| CVE-2024-26941 | MEDIUM | 5.5 | 0.2% | May 1, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/dp: Fix divide-by-zero regression on DP MST unp... |
| CVE-2024-26940 | MEDIUM | 5.5 | 0.2% | May 1, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Create debugfs ttm_resource_manager ent... |
| CVE-2024-26938 | MEDIUM | 5.5 | 0.2% | May 1, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/i915/bios: Tolerate devdata==NULL in intel_bios... |
| CVE-2024-26937 | MEDIUM | 5.5 | 0.3% | May 1, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: Reset queue_priority_hint on parking ... |
| CVE-2024-26935 | MEDIUM | 5.5 | 0.2% | May 1, 2024 | In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix unremoved procfs host directory reg... |
| CVE-2024-26931 | MEDIUM | 5.5 | 0.3% | May 1, 2024 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix command flush on cable pull Sys... |
| CVE-2024-28979 | MEDIUM | 4.8 | 0.3% | May 1, 2024 | Dell OpenManage Enterprise, versions 4.1.0 and older, contains an Improper Neutralization of Input During Web Page Gener... |
| CVE-2024-28978 | MEDIUM | 6.5 | 0.4% | May 1, 2024 | Dell OpenManage Enterprise, versions 3.10 and 4.0, contains an Improper Access Control vulnerability. A high privileged ... |
| CVE-2024-33767 | MEDIUM | 5 | 0.3% | May 1, 2024 | lunasvg v2.3.9 was discovered to contain a segmentation violation via the component composition_solid_source. |
| CVE-2024-33766 | MEDIUM | 5.3 | 0.6% | May 1, 2024 | lunasvg v2.3.9 was discovered to contain an FPE (Floating Point Exception) at blend_transformed_tiled_argb.isra.0. |
| CVE-2024-33764 | MEDIUM | 5.5 | 0.3% | May 1, 2024 | lunasvg v2.3.9 was discovered to contain a stack-overflow at lunasvg/source/element.h. |
| CVE-2024-4369 | MEDIUM | 6.8 | 0.7% | May 1, 2024 | An information disclosure flaw was found in OpenShift's internal image registry operator. The AZURE_CLIENT_SECRET can be... |
| CVE-2024-34149 | MEDIUM | 6.3 | 0.4% | Apr 30, 2024 | In Bitcoin Core through 27.0 and Bitcoin Knots before 25.1.knots20231115, tapscript lacks a policy size limit check, a d... |
| CVE-2024-4348 | MEDIUM | 4.3 | 1.8% | Apr 30, 2024 | A vulnerability, which was classified as problematic, was found in osCommerce 4. Affected is an unknown function of the ... |
| CVE-2024-3746 | MEDIUM | 6.8 | 0.2% | Apr 30, 2024 | The entire parent directory - C:\ScadaPro and its sub-directories and files are configured by default to allow user, in... |
| CVE-2024-33436 | MEDIUM | 5.3 | 0.6% | Apr 30, 2024 | An issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information due to missing support... |
| CVE-2024-33371 | MEDIUM | 6.1 | 0.5% | Apr 30, 2024 | Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to execute arbitrary code via the typei... |
| CVE-2024-22546 | MEDIUM | 6.4 | 1.5% | Apr 30, 2024 | TRENDnet TEW-815DAP 1.0.2.0 is vulnerable to Command Injection via the do_setNTP function. An authenticated attacker wit... |
| CVE-2024-33832 | MEDIUM | 6.3 | 0.7% | Apr 30, 2024 | OneNav v0.9.35-20240318 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /index.php?c=ap... |
| CVE-2024-33103 | MEDIUM | 6.1 | 0.5% | Apr 30, 2024 | An arbitrary file upload vulnerability in the Media Manager component of DokuWiki 2024-02-06a allows attackers to execut... |
| CVE-2024-33102 | MEDIUM | 5.4 | 0.4% | Apr 30, 2024 | A stored cross-site scripting (XSS) vulnerability in the component /pubs/counter.php of ThinkSAAS v3.7.0 allows attacker... |
| CVE-2024-33101 | MEDIUM | 6.1 | 0.4% | Apr 30, 2024 | A stored cross-site scripting (XSS) vulnerability in the component /action/anti.php of ThinkSAAS v3.7.0 allows attackers... |
| CVE-2024-2877 | MEDIUM | 5.5 | 0.2% | Apr 30, 2024 | Vault Enterprise, when configured with performance standby nodes and a configured audit device, will inadvertently log r... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now