2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42181 | HIGH | 7.5 | 0.2% | Jan 12, 2025 | HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmit... |
| CVE-2024-57876 | HIGH | 7 | 0.2% | Jan 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/dp_mst: Fix resetting msg rx state after topolo... |
| CVE-2024-57850 | HIGH | 7.8 | 0.2% | Jan 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: jffs2: Prevent rtime decompress memory corruption ... |
| CVE-2024-57849 | HIGH | 7.8 | 0.2% | Jan 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: s390/cpum_sf: Handle CPU hotplug remove during samp... |
| CVE-2024-57838 | HIGH | 7.1 | 0.2% | Jan 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: s390/entry: Mark IRQ entries to fix stack depot war... |
| CVE-2024-57798 | HIGH | 7.8 | 0.2% | Jan 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/dp_mst: Ensure mst_primary pointer is valid in ... |
| CVE-2024-57792 | HIGH | 7.8 | 0.3% | Jan 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: power: supply: gpio-charger: Fix set charge current... |
| CVE-2024-57791 | HIGH | 7.5 | 0.8% | Jan 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/smc: check return value of sock_recvmsg when dr... |
| CVE-2024-52332 | HIGH | 7.1 | 0.2% | Jan 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: igb: Fix potential invalid memory access in igb_ini... |
| CVE-2024-52319 | HIGH | 7.8 | 0.2% | Jan 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm: use aligned address in clear_gigantic_page() I... |
| CVE-2024-51729 | HIGH | 7.8 | 0.2% | Jan 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm: use aligned address in copy_user_gigantic_page(... |
| CVE-2024-50051 | HIGH | 7.8 | 0.2% | Jan 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: Add cancel_work_sync before module re... |
| CVE-2024-41935 | HIGH | 7.1 | 0.2% | Jan 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to shrink read extent node in batches We... |
| CVE-2024-41149 | HIGH | 7.8 | 0.2% | Jan 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: block: avoid to reuse `hctx` not removed from cpuhp... |
| CVE-2024-42169 | HIGH | 8.1 | 0.3% | Jan 11, 2025 | HCL MyXalytics is affected by insecure direct object references. It occurs due to missing access control checks, which ... |
| CVE-2024-12627 | HIGH | 7.5 | 0.5% | Jan 11, 2025 | The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulne... |
| CVE-2024-12404 | HIGH | 7.5 | 0.8% | Jan 11, 2025 | The CF Internal Link Shortcode plugin for WordPress is vulnerable to SQL Injection via the 'post_title' parameter in all... |
| CVE-2024-9188 | HIGH | 8.8 | 0.5% | Jan 10, 2025 | Specially constructed queries cause cross platform scripting leaking administrator tokens |
| CVE-2024-9134 | HIGH | 8.3 | 0.6% | Jan 10, 2025 | Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application acce... |
| CVE-2024-9131 | HIGH | 7.2 | 1.4% | Jan 10, 2025 | A user with administrator privileges can perform command injection |
| CVE-2024-47520 | HIGH | 7.6 | 0.4% | Jan 10, 2025 | A user with advanced report application access rights can perform actions for which they are not authorized |
| CVE-2024-47519 | HIGH | 7.1 | 0.3% | Jan 10, 2025 | Backup uploads to ETM subject to man-in-the-middle interception |
| CVE-2024-47518 | HIGH | 7.6 | 0.4% | Jan 10, 2025 | Specially constructed queries targeting ETM could discover active remote access sessions |
| CVE-2024-54996 | HIGH | 8.8 | 0.8% | Jan 10, 2025 | MonicaHQ v4.1.2 was discovered to contain multiple authenticated Client-Side Injection vulnerabilities via the title and... |
| CVE-2024-6662 | HIGH | 8.7 | 0.3% | Jan 10, 2025 | Websites managed by MegaBIP in versions below 5.15 are vulnerable to Cross-Site Request Forgery (CSRF) as the form avail... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now