2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-45014MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: s390/boot: Avoid possible physmem_info segment corr...
CVE-2024-45013MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nvme: move stopping keep-alive into nvme_uninit_ctr...
CVE-2024-45012MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nouveau/firmware: use dma non-coherent allocator C...
CVE-2024-45011MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: char: xillybus: Check USB endpoints when probing de...
CVE-2024-45010MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: only mark 'subflow' endp as available A...
CVE-2024-45009MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: only decrement add_addr_accepted for MPJ...
CVE-2024-44851MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Discussion section of Perfex CRM v1.1.0 allows attackers to exe...
CVE-2024-44466CRITICAL9.8COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request mes...
CVE-2024-41868MEDIUM5.5Audition versions 24.4.1, 23.6.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disc...
CVE-2024-39378HIGH7.8Audition versions 24.4.1, 23.6.6 and earlier are affected by an out-of-bounds write vulnerability that could result in a...
CVE-2024-8306HIGH7.8CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentialit...
CVE-2024-4465MEDIUM5An access control vulnerability was discovered in the Reports section due to a specific access restriction not being pro...
CVE-2024-43793MEDIUM6.4Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.19.0 o...
CVE-2024-8646MEDIUM6.1In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerab...
CVE-2024-8642HIGH8.1In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApi...
CVE-2024-8639HIGH8.8Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially ...
CVE-2024-8638HIGH8.8Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object co...
CVE-2024-8637HIGH8.8Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentia...
CVE-2024-8636HIGH8.8Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit h...
CVE-2024-7805Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-27115CRITICAL9.8A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this ...
CVE-2024-27114CRITICAL9.8A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the pub...
CVE-2024-27113CRITICAL9.8An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that o...
CVE-2024-27112CRITICAL9.8A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabl...
CVE-2024-6091CRITICAL9.8A vulnerability in significant-gravitas/autogpt version 0.5.1 allows an attacker to bypass the shell commands denylist s...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now