2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43900 | HIGH | 7.8 | 0.2% | Aug 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: media: xc2028: avoid use-after-free in load_firmwar... |
| CVE-2024-43899 | MEDIUM | 5.5 | 0.2% | Aug 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix null pointer deref in dcn20_re... |
| CVE-2024-43898 | — | — | — | Aug 26, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-43897 | MEDIUM | 5.5 | 0.2% | Aug 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: drop bad gso csum_start and offset in virtio_n... |
| CVE-2024-43896 | MEDIUM | 5.5 | 0.2% | Aug 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: ASoC: cs-amp-lib: Fix NULL pointer crash if efi.get... |
| CVE-2024-43895 | — | — | — | Aug 26, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-43894 | MEDIUM | 5.5 | 0.2% | Aug 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/client: fix null pointer dereference in drm_cli... |
| CVE-2024-43893 | MEDIUM | 5.5 | 0.3% | Aug 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: serial: core: check uartclk for zero to avoid divid... |
| CVE-2024-43892 | MEDIUM | 4.7 | 0.2% | Aug 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: memcg: protect concurrent access to mem_cgroup_idr ... |
| CVE-2024-43891 | MEDIUM | 4.7 | 0.2% | Aug 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: tracing: Have format file honor EVENT_FILE_FL_FREED... |
| CVE-2024-43890 | MEDIUM | 5.5 | 0.3% | Aug 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fix overflow in get_free_elt() "tracing_m... |
| CVE-2024-43889 | MEDIUM | 5.5 | 0.2% | Aug 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: padata: Fix possible divide-by-0 panic in padata_mt... |
| CVE-2024-43888 | HIGH | 7.8 | 0.2% | Aug 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: mm: list_lru: fix UAF for memory cgroup The mem_cg... |
| CVE-2024-43887 | MEDIUM | 4.7 | 0.2% | Aug 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: net/tcp: Disable TCP-AO static key after RCU grace ... |
| CVE-2024-43886 | MEDIUM | 5.5 | 0.2% | Aug 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add null check in resource_log_pip... |
| CVE-2024-43885 | — | — | — | Aug 26, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-8161 | CRITICAL | 9.8 | 0.5% | Aug 26, 2024 | SQL injection vulnerability in ATISolutions CIGES affecting versions lower than 2.15.5. This vulnerability allows a remo... |
| CVE-2024-43444 | HIGH | 8.2 | 0.4% | Aug 26, 2024 | Passwords of agents and customers are displayed in plain text in the OTRS admin log module if certain configurations reg... |
| CVE-2024-43443 | MEDIUM | 4.9 | 0.4% | Aug 26, 2024 | Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in Process Managemen... |
| CVE-2024-43442 | MEDIUM | 4.9 | 0.4% | Aug 26, 2024 | Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in OTRS (System Con... |
| CVE-2024-43884 | MEDIUM | 5.5 | 0.3% | Aug 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Add error handling to pair_device(... |
| CVE-2024-45256 | CRITICAL | 9.8 | 5.6% | Aug 26, 2024 | An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overw... |
| CVE-2024-45241 | HIGH | 7.5 | 13.6% | Aug 26, 2024 | A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allow... |
| CVE-2024-7313 | MEDIUM | 6.1 | 1.4% | Aug 26, 2024 | The Shield Security WordPress plugin before 20.0.6 does not sanitise and escape a parameter before outputting it back i... |
| CVE-2024-6879 | MEDIUM | 4.7 | 0.4% | Aug 26, 2024 | The Quiz and Survey Master (QSM) WordPress plugin before 9.1.1 fails to validate and escape certain Quiz fields before ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now