CVEs from 2024

6,583 normalized CVEs published or assigned in this year.

Total
6,583
critical
critical 174
high
high 1,069
medium
medium 2,083
low
low 49
% Critical
2.6%
% with KEV
2.5%
% with exploit
3.4%

Top vendors

Top products

  • mbed_tls 15
  • operations_analytics_log_analysis 14
  • surveillance_station 12
  • checkmk 10
  • office 8
  • profilegrid 8
  • office_long_term_servicing_channel 6
  • propertyhive 5
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-11233 medium 5.5 1y ago Moderate: php:8.1 security update
CVE-2024-11234 medium 5.5 1y ago Moderate: php:8.1 security update
CVE-2024-8929 medium 5.5 1y ago Moderate: php:8.1 security update
CVE-2024-45341 medium 5.5 1y ago RHSA-2025:3772: go-toolset:rhel8 security update (Moderate)
CVE-2024-8176 medium 5.5 1y ago RHSA-2025:4048: xmlrpc-c security update (Moderate)
CVE-2024-43855 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: md: fix deadlock between mddev_suspend and flush bio Deadlock occurs when mddev is being suspended while some flush bio is in pro…
CVE-2024-45336 medium 5.5 1y ago RHSA-2025:3772: go-toolset:rhel8 security update (Moderate)
CVE-2024-7347 medium 5.5 1y ago Moderate: nginx:1.24 security update
CVE-2024-10306 medium 5.5 1y ago Moderate: mod_proxy_cluster security update
CVE-2024-58085 medium 5.5 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: tomoyo: don't emit warning in tomoyo_write_control() syzbot is reporting too large allocation warning at tomoyo_write_control(), …
CVE-2024-58071 medium 5.5 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: team: prevent adding a device which is already a team device lower Prevent adding a device which is already a team device lower, …
CVE-2024-58063 medium 5.5 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: fix memory leaks and invalid access at probe error path Deinitialize at reverse order when probe fails. When init…
CVE-2024-58058 medium 5.5 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: ubifs: skip dumping tnc tree when zroot is null Clearing slab cache will free all znode in memory and make c->zroot.znode = NULL,…
CVE-2024-58051 medium 5.5 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: ipmi: ipmb: Add check devm_kasprintf() returned value devm_kasprintf() can return a NULL pointer on failure but this returned val…
CVE-2024-58020 medium 5.5 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: Add NULL check in mt_input_configured devm_kasprintf() can return a NULL pointer on failure,but this returned va…
CVE-2024-58017 medium 5.5 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: printk: Fix signed integer overflow when defining LOG_BUF_LEN_MAX Shifting 1 << 31 on a 32-bit int causes signed integer overflow…
CVE-2024-58016 medium 5.5 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: safesetid: check size of policy writes syzbot attempts to write a buffer with a large size to a sysfs entry with writes handled b…
CVE-2024-57996 medium 5.5 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: net_sched: sch_sfq: don't allow 1 packet limit The current implementation does not work correctly with a limit of 1. iproute2 act…
CVE-2024-57977 medium 5.5 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: memcg: fix soft lockup in the OOM process A soft lockup issue was found in the product with about 56,000 tasks were in the OOM cg…
CVE-2024-52533 medium 5.5 1y ago RHSA-2025:11327: glib2 security update (Moderate)
CVE-2024-41184 medium 5.5 1y ago RHSA-2025:0743: keepalived security update (Moderate)
CVE-2024-21096 medium 5.5 1y ago Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnera…
CVE-2024-57948 medium 5.5 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: mac802154: check local interfaces before deleting sdata list syzkaller reported a corrupted list in ieee802154_if_remove. [1] Re…
CVE-2024-10539 medium 5.5 5.5 1y ago Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uyumsoft Informatin Systems Uyumsoft ERP allows XSS Using Invalid Characters, Reflected XS…
CVE-2024-53088 medium 5.5 1y ago Moderate: kernel security update
CVE-2024-50275 medium 5.5 1y ago Moderate: kernel security update
CVE-2024-50154 medium 5.5 1y ago Moderate: kernel security update
CVE-2024-57947 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo: fix initial map fill The initial buffer has to be inited to all-ones, but it must restrict it to the si…
CVE-2024-57924 medium 5.5 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: fs: relax assertions on failure to encode file handles Encoding file handles is usually performed by a filesystem >encode_fh() me…
CVE-2024-3661 medium 5.5 1y ago Moderate: Security and bug fixes for NetworkManager
CVE-2024-57902 medium 5.5 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: af_packet: fix vlan_get_tci() vs MSG_PEEK Blamed commit forgot MSG_PEEK case, allowing a crash [1] as found by syzbot. Rework vl…
CVE-2024-57901 medium 5.5 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: af_packet: fix vlan_get_protocol_dgram() vs MSG_PEEK Blamed commit forgot MSG_PEEK case, allowing a crash [1] as found by syzbot.…
CVE-2024-11029 medium 5.5 1y ago Moderate: ipa security update
CVE-2024-47809 medium 5.5 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: dlm: fix possible lkb_resource null dereference This patch fixes a possible null pointer dereference when this function is called…
CVE-2024-56727 medium 5.5 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_flows.c Adding error pointer check after calling otx2_mbox_get_rsp().
CVE-2024-56719 medium 5.5 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix TSO DMA API usage causing oops Commit 66600fac7a98 ("net: stmmac: TSO: Fix unbalanced DMA map/unmap for non-page…
CVE-2024-56657 medium 5.5 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: ALSA: control: Avoid WARN() for symlink errors Using WARN() for showing the error of symlink creations don't give more informatio…
CVE-2024-53221 medium 5.5 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: f2fs: fix null-ptr-deref in f2fs_submit_page_bio() There's issue as follows when concurrently installing the f2fs.ko module and m…
CVE-2024-50255 medium 5.5 2y ago Moderate: kernel security update
CVE-2024-50192 medium 5.5 2y ago Moderate: kernel security update
CVE-2024-50099 medium 5.5 2y ago Moderate: kernel security update
CVE-2024-50223 medium 5.5 2y ago Moderate: kernel security update
CVE-2024-47675 medium 5.5 2y ago Moderate: kernel security update
CVE-2024-38564 medium 5.5 2y ago Moderate: kernel security update
CVE-2024-27399 medium 5.5 2y ago Moderate: kernel security update
CVE-2024-50115 medium 5.5 2y ago Moderate: kernel security update
CVE-2024-50148 medium 5.5 5.5 2y ago Moderate: kernel security update
CVE-2024-50142 medium 5.5 5.5 2y ago Linux kernel vulnerabilities
CVE-2024-50124 medium 5.5 2y ago Moderate: kernel security update
CVE-2024-50125 medium 5.5 2y ago Moderate: kernel security update
CVE-2024-46697 medium 5.5 2y ago Moderate: kernel security update
CVE-2024-49888 medium 5.5 2y ago Moderate: kernel security update
CVE-2024-50110 medium 5.5 2y ago Moderate: kernel security update
CVE-2024-45020 medium 5.5 2y ago Moderate: kernel security update
CVE-2024-50612 medium 5.5 2y ago RHSA-2024:11192: libsndfile security update (Moderate)
CVE-2024-38796 medium 5.5 2y ago RHSA-2024:11185: edk2:20220126gitbb1bba3d77 security update (Moderate)
CVE-2024-10573 medium 5.5 2y ago RHSA-2024:11193: mpg123 security update (Moderate)
CVE-2024-0397 medium 5.5 2y ago A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggere…
CVE-2024-8927 medium 5.5 2y ago RHSA-2024:10952: php:7.4 security update (Moderate)
CVE-2024-46695 medium 5.5 2y ago Moderate: kernel security update
CVE-2024-5458 medium 5.5 2y ago RHSA-2024:10952: php:7.4 security update (Moderate)
CVE-2024-8925 medium 5.5 2y ago RHSA-2024:10952: php:7.4 security update (Moderate)
CVE-2024-9026 medium 5.5 2y ago RHSA-2024:10952: php:7.4 security update (Moderate)
CVE-2024-49949 medium 5.5 5.5 2y ago Moderate: kernel security update
CVE-2024-44994 medium 5.5 2y ago Moderate: kernel security update
CVE-2024-43854 medium 5.5 2y ago Moderate: kernel security update
CVE-2024-3096 medium 5.5 2y ago RHSA-2024:10952: php:7.4 security update (Moderate)
CVE-2024-26615 medium 5.5 2y ago Moderate: kernel security update
CVE-2024-45018 medium 5.5 5.5 2y ago Moderate: kernel security update
CVE-2024-2756 medium 5.5 2y ago RHSA-2024:10952: php:7.4 security update (Moderate)
CVE-2024-31227 medium 5.5 2y ago Moderate: redis:7 security update
CVE-2024-41009 medium 5.5 2y ago Moderate: kernel security update
CVE-2024-50226 medium 5.5 2y ago Moderate: kernel security update
CVE-2024-42244 medium 5.5 2y ago Moderate: kernel security update
CVE-2024-52337 medium 5.5 2y ago RHSA-2024:11161: tuned security update (Moderate)
CVE-2024-53101 medium 5.5 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: fs: Fix uninitialized value issue in from_kuid and from_kgid ocfs2_setattr() uses attr->ia_mode, attr->ia_uid and attr->ia_gid in…
CVE-2024-45321 medium 5.5 2y ago RHSA-2024:10219: perl-App-cpanminus:1.7044 security update (Moderate)
CVE-2024-7130 medium 5.5 5.5 2y ago Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kion Computer KION Exchange Programs Software allows Reflected XSS. This issue affects KI…
CVE-2024-11404 medium 5.5 5.5 2y ago Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in django CMS Association django Filer allows Input Data M…
CVE-2024-5197 medium 5.5 2y ago RHSA-2024:5941: libvpx security update (Moderate)
CVE-2024-46824 medium 5.5 2y ago Moderate: kernel security update
CVE-2024-42283 medium 5.5 5.5 2y ago Moderate: kernel security update
CVE-2024-46858 medium 5.5 2y ago Moderate: kernel security update
CVE-2024-50602 medium 5.5 2y ago RHSA-2024:9502: expat security update (Moderate)
CVE-2024-40907 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: ionic: fix kernel panic in XDP_TX action In the XDP_TX path, ionic driver sends a packet to the TX path with rx page and correspo…
CVE-2024-36977 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: Wait unconditionally after issuing EndXfer command Currently all controller IP/revisions except DWC3_usb3 >= 310a wait…
CVE-2024-36967 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix memory leak in tpm2_key_encode() 'scratch' is never freed. Fix this by calling kfree() in the success, and in …
CVE-2024-36955 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: intel-sdw-acpi: fix usage of device_get_named_child_node() The documentation for device_get_named_child_node() mention…
CVE-2024-41093 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: avoid using null object of framebuffer Instead of using state->fb->obj[0] directly, get object from framebuffer by ca…
CVE-2024-36936 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: efi/unaccepted: touch soft lockup during memory accept Commit 50e782a86c98 ("efi/unaccepted: Fix soft lockups caused by parallel …
CVE-2024-38598 medium 5.5 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: md: fix resync softlockup when bitmap size is less than array size Is is reported that for dm-raid10, lvextend + lvchange --synca…
CVE-2024-38600 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: ALSA: Fix deadlocks with kctl removals at disconnection In snd_card_disconnect(), we set card->shutdown flag at the beginning, ca…
CVE-2024-36930 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: spi: fix null pointer dereference within spi_sync If spi_sync() is called with the non-empty queue and the same spi_message is th…
CVE-2024-38604 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: block: refine the EOF check in blkdev_iomap_begin blkdev_iomap_begin rounds down the offset to the logical block size before stas…
CVE-2024-38605 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: ALSA: core: Fix NULL module pointer assignment at card init The commit 81033c6b584b ("ALSA: core: Warn on empty module") introduc…
CVE-2024-30205 medium 5.5 2y ago RHSA-2024:6987: emacs security update (Moderate)
CVE-2024-36891 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: maple_tree: fix mas_empty_area_rev() null pointer dereference Currently the code calls mas_start() followed by mas_data_end() if …
CVE-2024-38632 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: vfio/pci: fix potential memory leak in vfio_intx_enable() If vfio_irq_ctx_alloc() failed will lead to 'name' memory leak.
CVE-2024-30203 medium 5.5 2y ago RHSA-2024:6987: emacs security update (Moderate)
CVE-2024-8235 medium 5.5 2y ago Moderate: libvirt security update