CVEs from 2024

6,622 normalized CVEs published or assigned in this year.

Total
6,622
critical
critical 169
high
high 1,066
medium
medium 2,079
low
low 49
% Critical
2.6%
% with KEV
2.5%
% with exploit
3.4%

Top vendors

Top products

  • surveillance_station 12
  • checkmk 10
  • profilegrid 8
  • office 8
  • office_long_term_servicing_channel 6
  • propertyhive 5
  • glibc 5
  • element_pack 5
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-9341 high 8.0 2y ago RHSA-2024:8846: container-tools:rhel8 security update (Important)
CVE-2024-43484 high 8.0 2y ago RHSA-2024:7868: .NET 8.0 security update (Important)
CVE-2024-38229 high 8.0 2y ago RHSA-2024:7868: .NET 8.0 security update (Important)
CVE-2024-43483 high 8.0 2y ago RHSA-2024:7868: .NET 8.0 security update (Important)
CVE-2024-43485 high 8.0 2y ago RHSA-2024:7868: .NET 8.0 security update (Important)
CVE-2024-8900 high 8.0 2y ago An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129, Firefox ESR < 128.3, and T…
CVE-2024-9397 high 8.0 2y ago A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 1…
CVE-2024-9398 high 8.0 2y ago By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vuln…
CVE-2024-9396 high 8.0 2y ago It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulnerability affects Firefox < 131,…
CVE-2024-9392 high 8.0 2y ago A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 12…
CVE-2024-9394 high 8.0 2y ago An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This ac…
CVE-2024-9393 high 8.0 2y ago An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This acces…
CVE-2024-9402 high 8.0 2y ago Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could…
CVE-2024-9401 high 8.0 2y ago Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort…
CVE-2024-9403 high 8.0 2y ago Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code…
CVE-2024-9400 high 8.0 2y ago A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a specific moment during JIT compilation. This vulnerability affects Firefox < 131, …
CVE-2024-9399 high 8.0 2y ago A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects Firefox < 131, Firefox E…
CVE-2024-47850 high 8.0 2y ago RHSA-2024:7463: cups-filters security update (Important)
CVE-2024-36016 high 8.0 2y ago Important: kernel security update
CVE-2024-38562 high 8.0 2y ago Important: kernel security update
CVE-2024-38601 high 8.0 2y ago Important: kernel security update
CVE-2024-41071 high 8.0 2y ago Important: kernel security update
CVE-2024-38573 high 8.0 2y ago Important: kernel security update
CVE-2024-38570 high 8.0 2y ago Important: kernel security update
CVE-2024-45026 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: s390/dasd: fix error recovery leading to data corruption on ESE devices Extent Space Efficient (ESE) or thin provisioned volumes …
CVE-2024-26947 high 8.0 2y ago Important: kernel security update
CVE-2024-26595 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix NULL pointer dereference in error path When calling mlxsw_sp_acl_tcam_region_destroy() from an erro…
CVE-2024-42246 high 8.0 2y ago Important: kernel security update
CVE-2024-42225 high 8.0 2y ago Important: kernel security update
CVE-2024-26930 high 8.0 2y ago Important: kernel security update
CVE-2024-26991 high 8.0 2y ago Important: kernel security update
CVE-2024-26739 high 8.0 2y ago Important: kernel security update
CVE-2024-26929 high 8.0 2y ago Important: kernel security update
CVE-2024-27022 high 8.0 2y ago Important: kernel security update
CVE-2024-39506 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: liquidio: Adjust a NULL pointer handling path in lio_vf_rep_copy_packet In lio_vf_rep_copy_packet() pg_info->page is compared to …
CVE-2024-41064 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: powerpc/eeh: avoid possible crash when edev->pdev changes If a PCI device is removed during eeh_pe_report_edev(), edev->pdev will…
CVE-2024-41023 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: sched/deadline: Fix task_struct reference leak During the execution of the following stress test with linux-rt: stress-ng --cycl…
CVE-2024-36953 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-v2: Check for non-NULL vCPU in vgic_v2_parse_attr() vgic_v2_parse_attr() is responsible for finding the vCPU tha…
CVE-2024-41097 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: usb: atm: cxacru: fix endpoint checking in cxacru_bind() Syzbot is still reporting quite an old issue [1] that occurs due to inco…
CVE-2024-26931 high 8.0 2y ago Important: kernel security update
CVE-2024-36919 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: scsi: bnx2fc: Remove spin_lock_bh while releasing resources after upload The session resources are used by FW and driver when ses…
CVE-2024-26665 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: tunnels: fix out of bounds access when building IPv6 PMTU error If the ICMPv6 error is built from a non-linear skb we get the fol…
CVE-2024-41035 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix duplicate endpoint bug by clearing reserved bits in the descriptor Syzbot has identified a bug in usbcore (see the…
CVE-2024-26769 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: avoid deadlock on delete association path When deleting an association the shutdown path is deadlocking because we try …
CVE-2024-34155 high 8.0 2y ago RHSA-2024:8038: container-tools:rhel8 security update (Important)
CVE-2024-34158 high 8.0 2y ago RHSA-2024:8038: container-tools:rhel8 security update (Important)
CVE-2024-45769 high 8.0 2y ago RHSA-2024:6837: pcp security update (Important)
CVE-2024-45770 high 8.0 2y ago RHSA-2024:6837: pcp security update (Important)
CVE-2024-7652 high 8.0 2y ago An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affe…
CVE-2024-8394 high 8.0 2y ago RHSA-2024:6684: thunderbird security update (Important)
CVE-2024-8381 high 8.0 2y ago A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < …
CVE-2024-8382 high 8.0 2y ago Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those interfaces would not be able to…
CVE-2024-8386 high 8.0 2y ago If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130…
CVE-2024-8384 high 8.0 2y ago The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. This could have led to memory corruption. This vulner…
CVE-2024-8383 high 8.0 2y ago Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-re…
CVE-2024-8387 high 8.0 2y ago Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could…
CVE-2024-8385 high 8.0 2y ago A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulnerability affects Firefox < 130, Firefox ESR < 128.2…
CVE-2024-42472 high 8.0 2y ago Important: bubblewrap and flatpak security update
CVE-2024-6104 high 8.0 2y ago RHSA-2024:5258: container-tools:rhel8 security update (Important)
CVE-2024-37298 high 8.0 2y ago RHSA-2024:5258: container-tools:rhel8 security update (Important)
CVE-2024-26668 high 8.0 2y ago Important: kernel security update
CVE-2024-41090 high 8.0 2y ago Important: kernel security update
CVE-2024-41091 high 8.0 2y ago Important: kernel security update
CVE-2024-41076 high 8.0 2y ago Important: kernel security update
CVE-2024-7348 high 8.0 2y ago RHSA-2024:6018: postgresql:13 security update (Important)
CVE-2024-36003 high 8.0 2y ago Important: kernel security update
CVE-2024-42152 high 8.0 2y ago Important: kernel security update
CVE-2024-26581 high 8.0 2y ago Important: kernel security update
CVE-2024-27016 high 8.0 2y ago Important: kernel security update
CVE-2024-26908 high 8.0 2y ago Important: kernel security update
CVE-2024-35839 high 8.0 2y ago Important: kernel security update
CVE-2024-38538 high 8.0 2y ago Important: kernel security update
CVE-2024-41041 high 8.0 2y ago Important: kernel security update
CVE-2024-36025 high 8.0 2y ago Important: kernel security update
CVE-2024-40957 high 8.0 2y ago Important: kernel security update
CVE-2024-40983 high 8.0 2y ago Important: kernel security update
CVE-2024-38608 high 8.0 2y ago Important: kernel security update
CVE-2024-40911 high 8.0 2y ago Important: kernel security update
CVE-2024-38540 high 8.0 2y ago Important: kernel security update
CVE-2024-38544 high 8.0 2y ago Important: kernel security update
CVE-2024-40929 high 8.0 2y ago Important: kernel security update
CVE-2024-27415 high 8.0 2y ago Important: kernel security update
CVE-2024-40939 high 8.0 2y ago Important: kernel security update
CVE-2024-27019 high 8.0 2y ago Important: kernel security update
CVE-2024-42110 high 8.0 2y ago Important: kernel security update
CVE-2024-40914 high 8.0 2y ago Important: kernel security update
CVE-2024-39476 high 8.0 2y ago Important: kernel security update
CVE-2024-4317 high 8.0 2y ago RHSA-2024:6001: postgresql:15 security update (Important)
CVE-2024-38286 high 8.0 2y ago Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 …
CVE-2024-34750 high 8.0 2y ago Important: tomcat security update
CVE-2024-6221 high 8.0 2y ago A vulnerability in corydolphin/flask-cors up to version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default, without any configuration option. This behavi…
CVE-2024-21823 high 8.0 2y ago Important: kernel security update
CVE-2024-26853 high 8.0 2y ago Important: kernel security update
CVE-2024-38575 high 8.0 2y ago Important: kernel security update
CVE-2024-38391 high 8.0 2y ago Important: kernel security update
CVE-2024-36921 high 8.0 2y ago Important: kernel security update
CVE-2024-39487 high 8.0 2y ago Important: kernel security update
CVE-2024-7520 high 8.0 2y ago A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
CVE-2024-7521 high 8.0 2y ago Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird …
CVE-2024-7522 high 8.0 2y ago Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1,…