2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-23997CRITICAL9.6Lukas Bach yana =<1.0.16 is vulnerable to Cross Site Scripting (XSS) via src/electron-main.ts.
CVE-2024-6526MEDIUM6.1A vulnerability classified as problematic has been found in CodeIgniter Ecommerce-CodeIgniter-Bootstrap up to 1998845073...
CVE-2024-6505MEDIUM6.8A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the ind...
CVE-2024-39864CRITICAL9.8The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configur...
CVE-2024-39028CRITICAL9.8An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.
CVE-2024-39027HIGH7.5SeaCMS v12.9 has an unauthorized SQL injection vulnerability. The vulnerability is caused by the SQL injection through t...
CVE-2024-38346CRITICAL9.8The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands...
CVE-2024-23588MEDIUM6.5HCL Nomad server on Domino fails to properly handle users configured with limited Domino access resulting in a possible ...
CVE-2024-6525HIGH8.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20230922. It has been rated as proble...
CVE-2024-6524HIGH8.8A vulnerability was found in ShopXO up to 6.1.0. It has been declared as critical. Affected by this vulnerability is an ...
CVE-2024-6523MEDIUM5.4A vulnerability was found in ZKTeco BioTime up to 9.5.2. It has been classified as problematic. Affected is an unknown f...
CVE-2024-6298CRITICAL9.8Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series ...
CVE-2024-6209HIGH7.5Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series ...
CVE-2024-39485MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: v4l: async: Properly re-initialise notifier ...
CVE-2024-39484MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mmc: davinci: Don't strip remove function when driv...
CVE-2024-39483MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: WARN on vNMI + NMI window iff NMIs are ou...
CVE-2024-39482MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bcache: fix variable length array abuse in btree_it...
CVE-2024-39481MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: mc: Fix graph walk in media_pipeline_start ...
CVE-2024-39480HIGH7.8In the Linux kernel, the following vulnerability has been resolved: kdb: Fix buffer overflow during tab-complete Curre...
CVE-2024-39479HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/i915/hwmon: Get rid of devm When both hwmon an...
CVE-2024-39478MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA te...
CVE-2024-39477MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: do not call vma_add_reservation upon EN...
CVE-2024-39476MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: md/raid5: fix deadlock that raid5d() wait for itsel...
CVE-2024-39475MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fbdev: savage: Handle err return when savagefb_chec...
CVE-2024-39474MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: fix vmalloc which may return null if ca...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now