2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-58096MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: add srng->lock for ath11k_hal_srng_* ...
CVE-2024-58095MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: jfs: add check read-only before txBeginAnon() call ...
CVE-2024-58094MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: jfs: add check read-only before truncation in jfs_t...
CVE-2024-58093HIGH7.8In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix link state exit during switch upstrea...
CVE-2024-58248LOW3.5nopCommerce through 4.90.1 does not offer locking for order placement. Thus there is a race condition with duplicate red...
CVE-2024-46915Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-58092MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nfsd: fix legacy client tracking initialization Ge...
CVE-2024-52281HIGH8.9A: Improper Neutralization of Input During Web Page Generation vulnerability in SUSE rancher allows a malicious actor to...
CVE-2024-22036CRITICAL9.1A vulnerability has been identified within Rancher where a cluster or node driver can be used to escape the chroot jail...
CVE-2024-10680MEDIUM4.8The Form Maker by 10Web WordPress plugin before 1.15.32 does not sanitise and escape some of its settings, which could ...
CVE-2024-13452MEDIUM6.1The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an...
CVE-2024-49200MEDIUM6.4An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential D...
CVE-2024-44843MEDIUM5.9An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbit...
CVE-2024-42193HIGH8.1HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate valid...
CVE-2024-50960HIGH7.2A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351...
CVE-2024-42200MEDIUM5.4HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validat...
CVE-2024-42189MEDIUM6.5HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an ...
CVE-2024-36842HIGH7.3An issue in Oncord+ Android Infotainment Systems OS Android 12, Model Hardware TS17,Hardware part Number F57L_V3.2_20220...
CVE-2024-13177MEDIUM5.2Netskope Client on Mac OS is impacted by a vulnerability in which the postinstall script does not properly validate the ...
CVE-2024-11084MEDIUM6.3Helix ALM prior to 2025.1 returns distinct error responses during authentication, allowing an attacker to determine whet...
CVE-2024-45712MEDIUM5.4SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be...
CVE-2024-13610MEDIUM4.8The Simple Social Media Share Buttons WordPress plugin before 6.0.0 does not sanitise and escape some of its settings, ...
CVE-2024-13207MEDIUM4.8The Widget for Social Page Feeds WordPress plugin before 6.4.2 does not sanitise and escape some of its settings, which ...
CVE-2024-49825MEDIUM4.3IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.20 and 23.0.0 through ...
CVE-2024-49709MEDIUM4.4Internet Starter, one of SoftCOM iKSORIS system modules, allows for setting an arbitrary session cookie value. An attack...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now