2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39493MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: crypto: qat - Fix ADF_DEV_RESET_SYNC memory leak U...
CVE-2024-39492HIGH7In the Linux kernel, the following vulnerability has been resolved: mailbox: mtk-cmdq: Fix pm_runtime_get_sync() warnin...
CVE-2024-39491MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: cs35l56: Fix lifetime of cs_dsp instance...
CVE-2024-39490MEDIUM6.2In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix missing sk_buff release in seg6_input...
CVE-2024-39489MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix memleak in seg6_hmac_init_algo seg6_...
CVE-2024-39488MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: arm64: asm-bug: Add .align 2 to the end of __BUG_EN...
CVE-2024-39927HIGH8.2Out-of-bounds write vulnerability exists in Ricoh MFPs and printers. If a remote attacker sends a specially crafted requ...
CVE-2024-39886LOW3.7TONE store App version 3.4.2 and earlier contains an issue with unprotected primary channel. Since TONE store App commun...
CVE-2024-36453MEDIUM6.1Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions pr...
CVE-2024-36452LOW3.1Cross-site request forgery vulnerability exists in ajaxterm module of Webmin versions prior to 2.003. If this vulnerabil...
CVE-2024-36451HIGH8.8Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2...
CVE-2024-36450MEDIUM5.4Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exp...
CVE-2024-6411HIGH8.8The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in al...
CVE-2024-6410MEDIUM4.3The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Ref...
CVE-2024-39614HIGH7.5An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject t...
CVE-2024-39330MEDIUM4.3An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. Derived classes of the django.core.files.stora...
CVE-2024-39329MEDIUM5.3An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. The django.contrib.auth.backends.ModelBackend....
CVE-2024-38875HIGH7.5An issue was discovered in Django 4.2 before 4.2.14 and 5.0 before 5.0.7. urlize and urlizetrunc were subject to a poten...
CVE-2024-21526HIGH7.5All versions of the package speaker are vulnerable to Denial of Service (DoS) when providing unexpected input types to t...
CVE-2024-21525HIGH8.3All versions of the package node-twain are vulnerable to Improper Check or Handling of Exceptional Conditions due to the...
CVE-2024-21524CRITICAL9.1All versions of the package node-stringbuilder are vulnerable to Out-of-bounds Read due to incorrect memory length calcu...
CVE-2024-21523HIGH7.5All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to ...
CVE-2024-21522HIGH7.5All versions of the package audify are vulnerable to Improper Validation of Array Index when frameSize is provided to th...
CVE-2024-21521HIGH7.5All versions of the package @discordjs/opus are vulnerable to Denial of Service (DoS) due to providing an input object w...
CVE-2024-6550MEDIUM5.3The Gravity Forms: Multiple Form Instances plugin for WordPress is vulnerable to Full Path Disclosure in all versions up...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now