2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43870 | MEDIUM | 5.5 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: perf: Fix event leak upon exit When a task is sche... |
| CVE-2024-43869 | MEDIUM | 5.5 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: perf: Fix event leak upon exec and file release Th... |
| CVE-2024-8023 | CRITICAL | 9.8 | 0.6% | Aug 21, 2024 | A vulnerability classified as critical has been found in chillzhuang SpringBlade 4.1.0. Affected is an unknown function ... |
| CVE-2024-8022 | MEDIUM | 5.3 | 0.3% | Aug 21, 2024 | A vulnerability was found in Genexis Tilgin Home Gateway 322_AS0500-03_05_13_05. It has been rated as problematic. This ... |
| CVE-2024-43868 | MEDIUM | 5.5 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: riscv/purgatory: align riscv_kernel_entry When ali... |
| CVE-2024-43867 | MEDIUM | 5.5 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: prime: fix refcount underflow Calling... |
| CVE-2024-43866 | MEDIUM | 4.7 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Always drain health in shutdown callback ... |
| CVE-2024-43865 | MEDIUM | 5.5 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: s390/fpu: Re-add exception handling in load_fpu_sta... |
| CVE-2024-43864 | MEDIUM | 5.5 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix CT entry update leaks of modify head... |
| CVE-2024-43863 | MEDIUM | 5.5 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix a deadlock in dma buf fence polling... |
| CVE-2024-43862 | MEDIUM | 5.5 | 0.1% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: wan: fsl_qmc_hdlc: Convert carrier_lock spinlo... |
| CVE-2024-22281 | HIGH | 7.5 | 0.7% | Aug 20, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacke... |
| CVE-2024-43861 | MEDIUM | 5.5 | 0.2% | Aug 20, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: usb: qmi_wwan: fix memory leak for not ip pack... |
| CVE-2024-43403 | HIGH | 8.8 | 0.5% | Aug 20, 2024 | Kanister is a data protection workflow management tool. The kanister has a deployment called default-kanister-operator, ... |
| CVE-2024-43396 | MEDIUM | 5.4 | 0.5% | Aug 20, 2024 | Khoj is an application that creates personal AI agents. The Automation feature allows a user to insert arbitrary HTML in... |
| CVE-2024-42363 | HIGH | 8.8 | 1.1% | Aug 20, 2024 | Prior to 3385, the user-controlled role parameter enters the application in the Kubernetes::RoleVerificationsController.... |
| CVE-2024-42362 | HIGH | 8.8 | 1.3% | Aug 20, 2024 | Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe dese... |
| CVE-2024-42361 | CRITICAL | 9.8 | 1.1% | Aug 20, 2024 | Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId... |
| CVE-2024-41658 | MEDIUM | 6.1 | 0.4% | Aug 20, 2024 | Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earl... |
| CVE-2024-41657 | HIGH | 8.8 | 0.7% | Aug 20, 2024 | Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earli... |
| CVE-2024-7711 | MEDIUM | 4.3 | 0.5% | Aug 20, 2024 | An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the ... |
| CVE-2024-6800 | CRITICAL | 9.8 | 1.5% | Aug 20, 2024 | An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication wi... |
| CVE-2024-6337 | MEDIUM | 6.5 | 0.7% | Aug 20, 2024 | An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a GitHub App with only ... |
| CVE-2024-41773 | MEDIUM | 6.5 | 0.3% | Aug 20, 2024 | IBM Global Configuration Management 7.0.2 and 7.0.3 could allow an authenticated user to archive a global baseline due t... |
| CVE-2024-41659 | HIGH | 8.1 | 0.6% | Aug 20, 2024 | memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier wh... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now