CVEs from 2024
Total
6,613
critical
critical 169
high
high 1,066
medium
medium 2,079
low
low 49
% Critical
2.6%
% with KEV
2.5%
% with exploit
3.4%
Top products
- surveillance_station 12
- checkmk 10
- profilegrid 8
- office 8
- office_long_term_servicing_channel 6
- propertyhive 5
- glibc 5
- element_pack 5
Top packages
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-11187 | high | — | 8.0 | 1y ago | Important: bind security update | |||
| CVE-2024-21196 | high | — | 8.0 | 1y ago | RHSA-2025:1673: mysql:8.0 security update (Important) | |||
| CVE-2024-7264 | high | — | 8.0 | 1y ago | libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length… | |||
| CVE-2024-21213 | high | — | 8.0 | 1y ago | RHSA-2025:1673: mysql:8.0 security update (Important) | |||
| CVE-2024-21198 | high | — | 8.0 | 1y ago | RHSA-2025:1673: mysql:8.0 security update (Important) | |||
| CVE-2024-21201 | high | — | 8.0 | 1y ago | RHSA-2025:1673: mysql:8.0 security update (Important) | |||
| CVE-2024-12797 | high | — | 8.0 | 1y ago | Important: openssl security update | |||
| CVE-2024-11218 | high | — | 8.0 | 1y ago | RHSA-2025:1372: container-tools:rhel8 security update (Important) | |||
| CVE-2024-52531 | high | — | 8.0 | 1y ago | RHSA-2025:0838: libsoup security update (Important) | |||
| CVE-2024-46981 | high | — | 8.0 | 1y ago | Important: redis security update | |||
| CVE-2024-51741 | high | — | 8.0 | 1y ago | Important: redis:7 security update | |||
| CVE-2024-53263 | high | — | 8.0 | 1y ago | Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without ch… | |||
| CVE-2024-12085 | high | — | 8.0 | 1y ago | RHSA-2025:0325: rsync security update (Important) | |||
| CVE-2024-56201 | high | — | 8.0 | 1y ago | Important: fence-agents security update | |||
| CVE-2024-56326 | high | — | 8.0 | 1y ago | RHSA-2025:0711: python-jinja2 security update (Important) | |||
| CVE-2024-57823 | high | — | 8.0 | 1y ago | In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path(). | |||
| CVE-2024-11614 | high | — | 8.0 | 1y ago | RHSA-2025:0222: dpdk security update (Important) | |||
| CVE-2024-53580 | high | — | 8.0 | 1y ago | RHSA-2025:0168: iperf3 security update (Important) | |||
| CVE-2024-54502 | high | — | 8.0 | 1y ago | The issue was addressed with improved checks. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing malici… | |||
| CVE-2024-54479 | high | — | 8.0 | 1y ago | The issue was addressed with improved checks. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing malici… | |||
| CVE-2024-54505 | high | — | 8.0 | 1y ago | A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 1… | |||
| CVE-2024-50252 | high | — | 8.0 | 1y ago | Important: kernel security update | |||
| CVE-2024-53122 | high | — | 8.0 | 1y ago | Important: kernel security update | |||
| CVE-2024-50208 | high | — | 8.0 | 1y ago | Important: kernel security update | |||
| CVE-2024-46713 | high | — | 8.0 | 1y ago | Important: kernel security update | |||
| CVE-2024-8508 | high | — | 8.0 | 2y ago | RHSA-2025:0837: unbound security update (Important) | |||
| CVE-2024-34156 | high | — | 8.0 | 2y ago | RHSA-2024:8038: container-tools:rhel8 security update (Important) | |||
| CVE-2024-10041 | high | — | 8.0 | 2y ago | RHSA-2024:10379: pam security update (Important) | |||
| CVE-2024-47607 | high | — | 8.0 | 2y ago | RHSA-2024:11345: gstreamer1-plugins-base security update (Important) | |||
| CVE-2024-47540 | high | — | 8.0 | 2y ago | GStreamer is a library for constructing graphs of media-handling components. An uninitialized stack variable vulnerability has been identified in the gst_matroska_demux_add_wvpk_header function withi… | |||
| CVE-2024-47537 | high | — | 8.0 | 2y ago | GStreamer is a library for constructing graphs of media-handling components. The program attempts to reallocate the memory pointed to by stream->samples to accommodate stream->n_samples + samples_cou… | |||
| CVE-2024-47606 | high | — | 8.0 | 2y ago | GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in the function qtdemux_parse_theora_extension within qtdemux.c. The vulnerability … | |||
| CVE-2024-47613 | high | — | 8.0 | 2y ago | GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been identified in `gst_gdk_pixbuf_dec_flush` within `gstgdkpixbufdec.c`. Thi… | |||
| CVE-2024-47615 | high | — | 8.0 | 2y ago | RHSA-2024:11345: gstreamer1-plugins-base security update (Important) | |||
| CVE-2024-47538 | high | — | 8.0 | 2y ago | RHSA-2024:11345: gstreamer1-plugins-base security update (Important) | |||
| CVE-2024-47539 | high | — | 8.0 | 2y ago | GStreamer is a library for constructing graphs of media-handling components. An out-of-bounds write vulnerability was identified in the convert_to_s334_1a function in isomp4/qtdemux.c. The vulnerabil… | |||
| CVE-2024-11168 | high | — | 8.0 | 2y ago | The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and poten… | |||
| CVE-2024-9287 | high | — | 8.0 | 2y ago | A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands int… | |||
| CVE-2024-12254 | high | — | 8.0 | 2y ago | RHSA-2024:10980: python3.12 security update (Important) | |||
| CVE-2024-31228 | high | — | 8.0 | 2y ago | Important: redis security update | |||
| CVE-2024-31449 | high | — | 8.0 | 2y ago | Important: redis security update | |||
| CVE-2024-10979 | high | — | 8.0 | 2y ago | RHSA-2024:10832: postgresql:13 security update (Important) | |||
| CVE-2024-10978 | high | — | 8.0 | 2y ago | RHSA-2024:10832: postgresql:13 security update (Important) | |||
| CVE-2024-10976 | high | — | 8.0 | 2y ago | RHSA-2024:10832: postgresql:13 security update (Important) | |||
| CVE-2024-52804 | high | — | 8.0 | 2y ago | RHSA-2025:2872: pcs security update (Important) | |||
| CVE-2024-11692 | high | — | 8.0 | 2y ago | An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133, Firefox ESR < 12… | |||
| CVE-2024-11159 | high | — | 8.0 | 2y ago | RHSA-2024:10591: thunderbird security update (Important) | |||
| CVE-2024-11697 | high | — | 8.0 | 2y ago | When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have led to malicious code execution. This vul… | |||
| CVE-2024-11695 | high | — | 8.0 | 2y ago | A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 133, Fir… | |||
| CVE-2024-11696 | high | — | 8.0 | 2y ago | The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest… | |||
| CVE-2024-11699 | high | — | 8.0 | 2y ago | Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could… | |||
| CVE-2024-11694 | high | — | 8.0 | 2y ago | Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue c… | |||
| CVE-2024-52336 | high | — | 8.0 | 2y ago | Important: tuned security update | |||
| CVE-2024-10963 | high | — | 8.0 | 2y ago | RHSA-2024:10379: pam security update (Important) | |||
| CVE-2024-53899 | high | — | 8.0 | 2y ago | virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same… | |||
| CVE-2024-9632 | high | — | 8.0 | 2y ago | A flaw was found in the X.org server. Due to improperly tracked allocation size in _XkbSetCompatMap, a local attacker may be able to trigger a buffer overflow condition via a specially crafted payloa… | |||
| CVE-2024-45802 | high | — | 8.0 | 2y ago | RHSA-2024:9644: squid:4 security update (Important) | |||
| CVE-2024-52530 | high | — | 8.0 | 2y ago | RHSA-2024:9573: libsoup security update (Important) | |||
| CVE-2024-52532 | high | — | 8.0 | 2y ago | RHSA-2024:9573: libsoup security update (Important) | |||
| CVE-2024-44296 | high | — | 8.0 | 2y ago | The issue was addressed with improved checks. This issue is fixed in Safari 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Pr… | |||
| CVE-2024-9050 | high | — | 8.0 | 2y ago | RHSA-2024:8353: NetworkManager-libreswan security update (Important) | |||
| CVE-2024-44244 | high | — | 8.0 | 2y ago | A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Proces… | |||
| CVE-2024-43498 | high | — | 8.0 | 2y ago | Important: .NET 9.0 security update | |||
| CVE-2024-43499 | high | — | 8.0 | 2y ago | Important: .NET 9.0 security update | |||
| CVE-2024-26759 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: mm/swap: fix race when skipping swapcache When skipping swapcache for SWP_SYNCHRONOUS_IO, if two or more threads swapin the same … | |||
| CVE-2024-40997 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: cpufreq: amd-pstate: fix memory leak on CPU EPP exit The cpudata memory from kzalloc() in amd_pstate_epp_cpu_init() is not freed … | |||
| CVE-2024-35810 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix the lifetime of the bo cursor memory The cleanup can be dispatched while the atomic update is still active, which… | |||
| CVE-2024-40989 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Disassociate vcpus from redistributor region on teardown When tearing down a redistributor region, make sure we don't… | |||
| CVE-2024-38627 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: stm class: Fix a double free in stm_register_device() The put_device(&stm->dev) call will trigger stm_device_release() which free… | |||
| CVE-2024-42159 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Sanitise num_phys Information is stored in mr_sas_port->phy_mask, values larger then size of this field shouldn't b… | |||
| CVE-2024-26614 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: tcp: make sure init the accept_queue's spinlocks once When I run syz's reproduction C program locally, it causes the following is… | |||
| CVE-2024-26686 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: fs/proc: do_task_stat: use sig->stats_lock to gather the threads/children stats lock_task_sighand() can trigger a hard lockup. I… | |||
| CVE-2024-27011 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix memleak in map from abort path The delete set command does not rely on the transaction object for eleme… | |||
| CVE-2024-39501 | high | — | 8.0 | 2y ago | RHSA-2024:7001: kernel-rt security update (Important) | |||
| CVE-2024-35947 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: dyndbg: fix old BUG_ON in >control parser Fix a BUG_ON from 2009. Even if it looks "unreachable" (I didn't really look), lets ma… | |||
| CVE-2024-41007 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: tcp: avoid too many retransmit packets If a TCP socket is using TCP_USER_TIMEOUT, and the other peer retracted its window to zero… | |||
| CVE-2024-42154 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: tcp_metrics: validate source addr length I don't see anything checking that TCP_METRICS_ATTR_SADDR_IPV4 is at least 4 bytes long,… | |||
| CVE-2024-26939 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: drm/i915/vma: Fix UAF on destroy against retire race Object debugging tools were sporadically reporting illegal attempts to free … | |||
| CVE-2024-35809 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: PCI/PM: Drain runtime-idle callbacks before driver removal A race condition between the .runtime_idle() callback and the .remove(… | |||
| CVE-2024-36896 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix access violation during port device removal Testing with KASAN and syzkaller revealed a bug in port.c:disable_stor… | |||
| CVE-2024-27010 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: net/sched: Fix mirred deadlock on device recursion When the mirred action is used on a classful egress qdisc and a packet is mirr… | |||
| CVE-2024-26940 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Create debugfs ttm_resource_manager entry only if needed The driver creates /sys/kernel/debug/dri/0/mob_ttm even when… | |||
| CVE-2024-36917 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: block: fix overflow in blk_ioctl_discard() There is no check for overflow of 'start + len' in blk_ioctl_discard(). Hung task occu… | |||
| CVE-2024-35847 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Prevent double free on error The error handling path in its_vpe_irq_domain_alloc() causes a double free when … | |||
| CVE-2024-35855 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix possible use-after-free during activity update The rule activity update delayed work periodically t… | |||
| CVE-2024-35835 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: fix a double-free in arfs_create_groups When `in` allocated by kvzalloc fails, arfs_create_groups will free ft->g and … | |||
| CVE-2024-42228 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc Initialize the size before calling amdgpu_vce_cs_rel… | |||
| CVE-2024-35854 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix possible use-after-free during rehash The rehash delayed work migrates filters from one region to a… | |||
| CVE-2024-26675 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: ppp_async: limit MRU to 64K syzbot triggered a warning [1] in __alloc_pages(): WARN_ON_ONCE_GFP(order > MAX_PAGE_ORDER, gfp) Wi… | |||
| CVE-2024-35824 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: misc: lis3lv02d_i2c: Fix regulators getting en-/dis-abled twice on suspend/resume When not configured for wakeup lis3lv02d_i2c_su… | |||
| CVE-2024-39276 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: ext4: fix mb_cache_entry's e_refcnt leak in ext4_xattr_block_cache_find() Syzbot reports a warning as follows: =================… | |||
| CVE-2024-44970 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: SHAMPO, Fix invalid WQ linked list unlink When all the strides in a WQE have been consumed, the WQE is unlinked from t… | |||
| CVE-2024-26921 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: inet: inet_defrag: prevent sk release while still in use ip_local_out() and other functions can pass skb->sk as function argument… | |||
| CVE-2024-41008 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: change vm->task_info handling This patch changes the handling and lifecycle of vm->task_info object. The major change… | |||
| CVE-2024-41012 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: filelock: Remove locks reliably when fcntl/close race is detected When fcntl_setlk() races with close(), it removes the created l… | |||
| CVE-2024-35838 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix potential sta-link leak When a station is allocated, links are added but not set to valid yet (e.g. during co… | |||
| CVE-2024-42240 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: x86/bhi: Avoid warning in #DB handler due to BHI mitigation When BHI mitigation is enabled, if SYSENTER is invoked with the TF fl… | |||
| CVE-2024-35853 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix memory leak during rehash The rehash delayed work migrates filters from one region to another. This… | |||
| CVE-2024-31076 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: genirq/cpuhotplug, x86/vector: Prevent vector leak during CPU offline The absence of IRQD_MOVE_PCNTXT prevents immediate effectiv… | |||
| CVE-2024-27410 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: reject iftype change with mesh ID change It's currently possible to change the mesh ID when the interface isn't ye… |