2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45014 | MEDIUM | 5.5 | 0.2% | Sep 11, 2024 | In the Linux kernel, the following vulnerability has been resolved: s390/boot: Avoid possible physmem_info segment corr... |
| CVE-2024-45013 | MEDIUM | 5.5 | 0.2% | Sep 11, 2024 | In the Linux kernel, the following vulnerability has been resolved: nvme: move stopping keep-alive into nvme_uninit_ctr... |
| CVE-2024-45012 | MEDIUM | 5.5 | 0.2% | Sep 11, 2024 | In the Linux kernel, the following vulnerability has been resolved: nouveau/firmware: use dma non-coherent allocator C... |
| CVE-2024-45011 | MEDIUM | 5.5 | 0.2% | Sep 11, 2024 | In the Linux kernel, the following vulnerability has been resolved: char: xillybus: Check USB endpoints when probing de... |
| CVE-2024-45010 | MEDIUM | 5.5 | 0.2% | Sep 11, 2024 | In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: only mark 'subflow' endp as available A... |
| CVE-2024-45009 | MEDIUM | 5.5 | 0.2% | Sep 11, 2024 | In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: only decrement add_addr_accepted for MPJ... |
| CVE-2024-44851 | MEDIUM | 5.4 | 0.4% | Sep 11, 2024 | A stored cross-site scripting (XSS) vulnerability in the Discussion section of Perfex CRM v1.1.0 allows attackers to exe... |
| CVE-2024-44466 | CRITICAL | 9.8 | 10.7% | Sep 11, 2024 | COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request mes... |
| CVE-2024-41868 | MEDIUM | 5.5 | 0.2% | Sep 11, 2024 | Audition versions 24.4.1, 23.6.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disc... |
| CVE-2024-39378 | HIGH | 7.8 | 0.2% | Sep 11, 2024 | Audition versions 24.4.1, 23.6.6 and earlier are affected by an out-of-bounds write vulnerability that could result in a... |
| CVE-2024-8306 | HIGH | 7.8 | 0.2% | Sep 11, 2024 | CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentialit... |
| CVE-2024-4465 | MEDIUM | 5 | 0.2% | Sep 11, 2024 | An access control vulnerability was discovered in the Reports section due to a specific access restriction not being pro... |
| CVE-2024-43793 | MEDIUM | 6.4 | 0.3% | Sep 11, 2024 | Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.19.0 o... |
| CVE-2024-8646 | MEDIUM | 6.1 | 0.4% | Sep 11, 2024 | In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerab... |
| CVE-2024-8642 | HIGH | 8.1 | 0.4% | Sep 11, 2024 | In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApi... |
| CVE-2024-8639 | HIGH | 8.8 | 0.3% | Sep 11, 2024 | Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially ... |
| CVE-2024-8638 | HIGH | 8.8 | 0.4% | Sep 11, 2024 | Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object co... |
| CVE-2024-8637 | HIGH | 8.8 | 0.4% | Sep 11, 2024 | Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentia... |
| CVE-2024-8636 | HIGH | 8.8 | 0.4% | Sep 11, 2024 | Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit h... |
| CVE-2024-7805 | — | — | — | Sep 11, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-27115 | CRITICAL | 9.8 | 4.6% | Sep 11, 2024 | A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this ... |
| CVE-2024-27114 | CRITICAL | 9.8 | 0.5% | Sep 11, 2024 | A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the pub... |
| CVE-2024-27113 | CRITICAL | 9.8 | 0.4% | Sep 11, 2024 | An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that o... |
| CVE-2024-27112 | CRITICAL | 9.8 | 0.4% | Sep 11, 2024 | A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabl... |
| CVE-2024-6091 | CRITICAL | 9.8 | 0.8% | Sep 11, 2024 | A vulnerability in significant-gravitas/autogpt version 0.5.1 allows an attacker to bypass the shell commands denylist s... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now