2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-43870MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: perf: Fix event leak upon exit When a task is sche...
CVE-2024-43869MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: perf: Fix event leak upon exec and file release Th...
CVE-2024-8023CRITICAL9.8A vulnerability classified as critical has been found in chillzhuang SpringBlade 4.1.0. Affected is an unknown function ...
CVE-2024-8022MEDIUM5.3A vulnerability was found in Genexis Tilgin Home Gateway 322_AS0500-03_05_13_05. It has been rated as problematic. This ...
CVE-2024-43868MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: riscv/purgatory: align riscv_kernel_entry When ali...
CVE-2024-43867MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: prime: fix refcount underflow Calling...
CVE-2024-43866MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Always drain health in shutdown callback ...
CVE-2024-43865MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: s390/fpu: Re-add exception handling in load_fpu_sta...
CVE-2024-43864MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix CT entry update leaks of modify head...
CVE-2024-43863MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix a deadlock in dma buf fence polling...
CVE-2024-43862MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: wan: fsl_qmc_hdlc: Convert carrier_lock spinlo...
CVE-2024-22281HIGH7.5** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacke...
CVE-2024-43861MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: usb: qmi_wwan: fix memory leak for not ip pack...
CVE-2024-43403HIGH8.8Kanister is a data protection workflow management tool. The kanister has a deployment called default-kanister-operator, ...
CVE-2024-43396MEDIUM5.4Khoj is an application that creates personal AI agents. The Automation feature allows a user to insert arbitrary HTML in...
CVE-2024-42363HIGH8.8Prior to 3385, the user-controlled role parameter enters the application in the Kubernetes::RoleVerificationsController....
CVE-2024-42362HIGH8.8Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe dese...
CVE-2024-42361CRITICAL9.8Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId...
CVE-2024-41658MEDIUM6.1Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earl...
CVE-2024-41657HIGH8.8Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earli...
CVE-2024-7711MEDIUM4.3An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the ...
CVE-2024-6800CRITICAL9.8An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication wi...
CVE-2024-6337MEDIUM6.5An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a GitHub App with only ...
CVE-2024-41773MEDIUM6.5IBM Global Configuration Management 7.0.2 and 7.0.3 could allow an authenticated user to archive a global baseline due t...
CVE-2024-41659HIGH8.1memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier wh...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now