2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39276MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ext4: fix mb_cache_entry's e_refcnt leak in ext4_xa...
CVE-2024-38661MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: s390/ap: Fix crash in AP internal function modify_b...
CVE-2024-38385MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: genirq/irqdesc: Prevent use-after-free in irq_find_...
CVE-2024-38306MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: btrfs: protect folio::private when attaching extent...
CVE-2024-37354MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: btrfs: fix crash on racing fsync and size-extending...
CVE-2024-37087MEDIUM5.3The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server m...
CVE-2024-37086MEDIUM6.8VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a v...
CVE-2024-37085HIGH7.2VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) per...
CVE-2024-37078HIGH7.1In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential kernel bug due to lack of wri...
CVE-2024-5451MEDIUM6.4The The7 — Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2024-38952HIGH7.5PX4-Autopilot v1.14.3 was discovered to contain a buffer overflow via the topic_name parameter at /logger/logged_topics....
CVE-2024-38951MEDIUM6.5A buffer overflow in PX4-Autopilot v1.12.3 allows attackers to cause a Denial of Service (DoS) via a crafted MavLink mes...
CVE-2024-32111MEDIUM5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic WordPress all...
CVE-2024-21827HIGH7.2A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Rou...
CVE-2024-6303HIGH8.8Missing authorization in Client-Server API in Conduit <=0.7.0, allowing for any alias to be removed and added to another...
CVE-2024-6302MEDIUM5.5Lack of privilege checking when processing a redaction in Conduit versions v0.6.0 and lower, allowing a local user to re...
CVE-2024-6301HIGH7.5Lack of validation of origin in federation API in Conduit, allowing any remote server to impersonate any user from any s...
CVE-2024-6300MEDIUM5.3Incomplete cleanup when performing redactions in Conduit, allowing an attacker to check whether certain strings were pre...
CVE-2024-6299LOW3.7Lack of consideration of key expiry when validating signatures in Conduit, allowing an attacker which has compromised an...
CVE-2024-5261CRITICAL9.8Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verificati...
CVE-2024-4846MEDIUM6.3Authentication bypass in the 2FA feature in Devolutions Server 2024.1.14.0 and earlier allows an authenticated attacker ...
CVE-2024-31111MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic ...
CVE-2024-28832MEDIUM4.8Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users...
CVE-2024-28831MEDIUM5.4Stored XSS in some confirmation pop-ups in Checkmk before versions 2.3.0p7 and 2.2.0p28 allows Checkmk users to execute ...
CVE-2024-6307MEDIUM6.4WordPress Core is vulnerable to Stored Cross-Site Scripting via the HTML API in various versions prior to 6.5.5 due to i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now