CVEs from 2024

6,613 normalized CVEs published or assigned in this year.

Total
6,613
critical
critical 174
high
high 1,069
medium
medium 2,082
low
low 49
% Critical
2.6%
% with KEV
2.5%
% with exploit
3.4%

Top vendors

Top products

  • mbed_tls 15
  • operations_analytics_log_analysis 14
  • surveillance_station 12
  • checkmk 10
  • office 8
  • profilegrid 8
  • office_long_term_servicing_channel 6
  • propertyhive 5
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-21218 high 8.0 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2024-12705 high 8.0 1y ago Important: bind9.18 security update
CVE-2024-11187 high 8.0 1y ago Important: bind security update
CVE-2024-7264 high 8.0 1y ago libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length…
CVE-2024-21241 high 8.0 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2024-21193 high 8.0 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2024-21231 high 8.0 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2024-21238 high 8.0 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2024-21237 high 8.0 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2024-21236 high 8.0 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2024-21230 high 8.0 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2024-21247 high 8.0 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2024-21239 high 8.0 1y ago RHSA-2025:1673: mysql:8.0 security update (Important)
CVE-2024-12797 high 8.0 1y ago Important: openssl security update
CVE-2024-11218 high 8.0 1y ago RHSA-2025:1372: container-tools:rhel8 security update (Important)
CVE-2024-52531 high 8.0 1y ago RHSA-2025:0838: libsoup security update (Important)
CVE-2024-46981 high 8.0 1y ago Important: redis security update
CVE-2024-51741 high 8.0 1y ago Important: redis:7 security update
CVE-2024-53263 high 8.0 1y ago Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without ch…
CVE-2024-12085 high 8.0 1y ago RHSA-2025:0325: rsync security update (Important)
CVE-2024-56326 high 8.0 1y ago RHSA-2025:0711: python-jinja2 security update (Important)
CVE-2024-57823 high 8.0 1y ago In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().
CVE-2024-56201 high 8.0 1y ago Important: fence-agents security update
CVE-2024-54505 high 8.0 1y ago A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 1…
CVE-2024-54479 high 8.0 1y ago The issue was addressed with improved checks. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing malici…
CVE-2024-11614 high 8.0 1y ago RHSA-2025:0222: dpdk security update (Important)
CVE-2024-53580 high 8.0 1y ago RHSA-2025:0168: iperf3 security update (Important)
CVE-2024-54502 high 8.0 1y ago The issue was addressed with improved checks. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing malici…
CVE-2024-50208 high 8.0 1y ago Important: kernel security update
CVE-2024-50252 high 8.0 1y ago Important: kernel security update
CVE-2024-53122 high 8.0 1y ago Important: kernel security update
CVE-2024-46713 high 8.0 1y ago Important: kernel security update
CVE-2024-34156 high 8.0 2y ago RHSA-2024:8038: container-tools:rhel8 security update (Important)
CVE-2024-8508 high 8.0 2y ago RHSA-2025:0837: unbound security update (Important)
CVE-2024-10041 high 8.0 2y ago RHSA-2024:10379: pam security update (Important)
CVE-2024-47539 high 8.0 2y ago GStreamer is a library for constructing graphs of media-handling components. An out-of-bounds write vulnerability was identified in the convert_to_s334_1a function in isomp4/qtdemux.c. The vulnerabil…
CVE-2024-47540 high 8.0 2y ago GStreamer is a library for constructing graphs of media-handling components. An uninitialized stack variable vulnerability has been identified in the gst_matroska_demux_add_wvpk_header function withi…
CVE-2024-47537 high 8.0 2y ago GStreamer is a library for constructing graphs of media-handling components. The program attempts to reallocate the memory pointed to by stream->samples to accommodate stream->n_samples + samples_cou…
CVE-2024-47615 high 8.0 2y ago RHSA-2024:11345: gstreamer1-plugins-base security update (Important)
CVE-2024-47613 high 8.0 2y ago GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been identified in `gst_gdk_pixbuf_dec_flush` within `gstgdkpixbufdec.c`. Thi…
CVE-2024-47607 high 8.0 2y ago RHSA-2024:11345: gstreamer1-plugins-base security update (Important)
CVE-2024-47606 high 8.0 2y ago GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in the function qtdemux_parse_theora_extension within qtdemux.c. The vulnerability …
CVE-2024-47538 high 8.0 2y ago RHSA-2024:11345: gstreamer1-plugins-base security update (Important)
CVE-2024-9287 high 8.0 2y ago A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands int…
CVE-2024-11168 high 8.0 2y ago The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and poten…
CVE-2024-12254 high 8.0 2y ago RHSA-2024:10980: python3.12 security update (Important)
CVE-2024-31449 high 8.0 2y ago Important: redis security update
CVE-2024-31228 high 8.0 2y ago Important: redis security update
CVE-2024-10978 high 8.0 2y ago RHSA-2024:10832: postgresql:13 security update (Important)
CVE-2024-10979 high 8.0 2y ago RHSA-2024:10832: postgresql:13 security update (Important)
CVE-2024-10976 high 8.0 2y ago RHSA-2024:10832: postgresql:13 security update (Important)
CVE-2024-11697 high 8.0 2y ago When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have led to malicious code execution. This vul…
CVE-2024-11696 high 8.0 2y ago The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest…
CVE-2024-11694 high 8.0 2y ago Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue c…
CVE-2024-11695 high 8.0 2y ago A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 133, Fir…
CVE-2024-11699 high 8.0 2y ago Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could…
CVE-2024-52804 high 8.0 2y ago RHSA-2025:2872: pcs security update (Important)
CVE-2024-11159 high 8.0 2y ago RHSA-2024:10591: thunderbird security update (Important)
CVE-2024-11692 high 8.0 2y ago An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133, Firefox ESR < 12…
CVE-2024-52336 high 8.0 2y ago Important: tuned security update
CVE-2024-10963 high 8.0 2y ago RHSA-2024:10379: pam security update (Important)
CVE-2024-53899 high 8.0 2y ago virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same…
CVE-2024-9632 high 8.0 2y ago A flaw was found in the X.org server. Due to improperly tracked allocation size in _XkbSetCompatMap, a local attacker may be able to trigger a buffer overflow condition via a specially crafted payloa…
CVE-2024-45802 high 8.0 2y ago RHSA-2024:9644: squid:4 security update (Important)
CVE-2024-44296 high 8.0 2y ago The issue was addressed with improved checks. This issue is fixed in Safari 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Pr…
CVE-2024-9050 high 8.0 2y ago RHSA-2024:8353: NetworkManager-libreswan security update (Important)
CVE-2024-52532 high 8.0 2y ago RHSA-2024:9573: libsoup security update (Important)
CVE-2024-44244 high 8.0 2y ago A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Proces…
CVE-2024-43498 high 8.0 2y ago Important: .NET 9.0 security update
CVE-2024-52530 high 8.0 2y ago RHSA-2024:9573: libsoup security update (Important)
CVE-2024-43499 high 8.0 2y ago Important: .NET 9.0 security update
CVE-2024-35959 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix mlx5e_priv_init() cleanup flow When mlx5e_priv_init() fails, the cleanup flow calls mlx5e_selq_cleanup which calls…
CVE-2024-35801 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Keep xfd_state in sync with MSR_IA32_XFD Commit 672365477ae8 ("x86/fpu: Update XFD state where required") and commit 8bf…
CVE-2024-31076 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: genirq/cpuhotplug, x86/vector: Prevent vector leak during CPU offline The absence of IRQD_MOVE_PCNTXT prevents immediate effectiv…
CVE-2024-26733 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: arp: Prevent overflow in arp_req_get(). syzkaller reported an overflown write in arp_req_get(). [0] When ioctl(SIOCGARP) is issu…
CVE-2024-26717 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: HID: i2c-hid-of: fix NULL-deref on failed power up A while back the I2C HID implementation was split in an ACPI and OF part, but …
CVE-2024-27410 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: reject iftype change with mesh ID change It's currently possible to change the mesh ID when the interface isn't ye…
CVE-2024-36010 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: igb: Fix string truncation warnings in igb_set_fw_version Commit 1978d3ead82c ("intel: fix string truncation warnings") fixes '-W…
CVE-2024-26939 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: drm/i915/vma: Fix UAF on destroy against retire race Object debugging tools were sporadically reporting illegal attempts to free …
CVE-2024-26940 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Create debugfs ttm_resource_manager entry only if needed The driver creates /sys/kernel/debug/dri/0/mob_ttm even when…
CVE-2024-42084 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: ftruncate: pass a signed offset The old ftruncate() syscall, using the 32-bit off_t misses a sign extension when called in compat…
CVE-2024-26921 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: inet: inet_defrag: prevent sk release while still in use ip_local_out() and other functions can pass skb->sk as function argument…
CVE-2024-39471 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: add error handle to avoid out-of-bounds if the sdma_v4_0_irq_id_to_seq return -EINVAL, the process should be stop to …
CVE-2024-26686 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: fs/proc: do_task_stat: use sig->stats_lock to gather the threads/children stats lock_task_sighand() can trigger a hard lockup. I…
CVE-2024-40901 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Avoid test/set_bit() operating in non-allocated memory There is a potential out-of-bounds access when using test_b…
CVE-2024-26740 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: net/sched: act_mirred: use the backlog for mirred ingress The test Davide added in commit ca22da2fbd69 ("act_mirred: use the back…
CVE-2024-26846 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: nvme-fc: do not wait in vain when unloading module The module exit path has race between deleting all controllers and freeing 'le…
CVE-2024-36933 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: nsh: Restore skb->{protocol,data,mac_header} for outer header in nsh_gso_segment(). syzbot triggered various splats (see [0] and …
CVE-2024-26840 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: cachefiles: fix memory leak in cachefiles_add_cache() The following memory leak was reported after unbinding /dev/cachefiles: ==…
CVE-2024-35947 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: dyndbg: fix old BUG_ON in >control parser Fix a BUG_ON from 2009. Even if it looks "unreachable" (I didn't really look), lets ma…
CVE-2024-36945 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: net/smc: fix neighbour and rtable leak in smc_ib_find_route() In smc_ib_find_route(), the neighbour found by neigh_lookup() and r…
CVE-2024-42124 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: scsi: qedf: Make qedf_execute_tmf() non-preemptible Stop calling smp_processor_id() from preemptible code in qedf_execute_tmf90. …
CVE-2024-26645 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: tracing: Ensure visibility when inserting an element into tracing_map Running the following two commands in parallel on a multi-p…
CVE-2024-26614 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: tcp: make sure init the accept_queue's spinlocks once When I run syz's reproduction C program locally, it causes the following is…
CVE-2024-38555 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Discard command completions in internal error Fix use after free when FW completion arrives while device is in internal…
CVE-2024-40989 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Disassociate vcpus from redistributor region on teardown When tearing down a redistributor region, make sure we don't…
CVE-2024-40997 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: cpufreq: amd-pstate: fix memory leak on CPU EPP exit The cpudata memory from kzalloc() in amd_pstate_epp_cpu_init() is not freed …
CVE-2024-35924 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: Limit read size on v1.2 Between UCSI 1.2 and UCSI 2.0, the size of the MESSAGE_IN region was increased from 16 …
CVE-2024-40906 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Always stop health timer during driver removal Currently, if teardown_hca fails to execute during driver removal, mlx5 …
CVE-2024-40988 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: drm/radeon: fix UBSAN warning in kv_dpm.c Adds bounds check for sumo_vid_mapping_entry.