CVEs from 2024

6,597 normalized CVEs published or assigned in this year.

Total
6,597
critical
critical 174
high
high 1,069
medium
medium 2,083
low
low 49
% Critical
2.6%
% with KEV
2.5%
% with exploit
3.4%

Top vendors

Top products

  • mbed_tls 15
  • operations_analytics_log_analysis 14
  • surveillance_station 12
  • checkmk 10
  • office 8
  • profilegrid 8
  • office_long_term_servicing_channel 6
  • propertyhive 5
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-42246 high 8.0 2y ago Important: kernel security update
CVE-2024-26931 high 8.0 2y ago Important: kernel security update
CVE-2024-27022 high 8.0 2y ago Important: kernel security update
CVE-2024-26595 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix NULL pointer dereference in error path When calling mlxsw_sp_acl_tcam_region_destroy() from an erro…
CVE-2024-41064 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: powerpc/eeh: avoid possible crash when edev->pdev changes If a PCI device is removed during eeh_pe_report_edev(), edev->pdev will…
CVE-2024-45026 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: s390/dasd: fix error recovery leading to data corruption on ESE devices Extent Space Efficient (ESE) or thin provisioned volumes …
CVE-2024-38573 high 8.0 2y ago Important: kernel security update
CVE-2024-36953 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-v2: Check for non-NULL vCPU in vgic_v2_parse_attr() vgic_v2_parse_attr() is responsible for finding the vCPU tha…
CVE-2024-26665 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: tunnels: fix out of bounds access when building IPv6 PMTU error If the ICMPv6 error is built from a non-linear skb we get the fol…
CVE-2024-38570 high 8.0 2y ago Important: kernel security update
CVE-2024-41023 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: sched/deadline: Fix task_struct reference leak During the execution of the following stress test with linux-rt: stress-ng --cycl…
CVE-2024-41035 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix duplicate endpoint bug by clearing reserved bits in the descriptor Syzbot has identified a bug in usbcore (see the…
CVE-2024-39506 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: liquidio: Adjust a NULL pointer handling path in lio_vf_rep_copy_packet In lio_vf_rep_copy_packet() pg_info->page is compared to …
CVE-2024-36919 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: scsi: bnx2fc: Remove spin_lock_bh while releasing resources after upload The session resources are used by FW and driver when ses…
CVE-2024-41071 high 8.0 2y ago Important: kernel security update
CVE-2024-38601 high 8.0 2y ago Important: kernel security update
CVE-2024-38562 high 8.0 2y ago Important: kernel security update
CVE-2024-26769 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: avoid deadlock on delete association path When deleting an association the shutdown path is deadlocking because we try …
CVE-2024-36016 high 8.0 2y ago Important: kernel security update
CVE-2024-26947 high 8.0 2y ago Important: kernel security update
CVE-2024-34155 high 8.0 2y ago RHSA-2024:8038: container-tools:rhel8 security update (Important)
CVE-2024-34158 high 8.0 2y ago RHSA-2024:8038: container-tools:rhel8 security update (Important)
CVE-2024-45769 high 8.0 2y ago RHSA-2024:6837: pcp security update (Important)
CVE-2024-45770 high 8.0 2y ago RHSA-2024:6837: pcp security update (Important)
CVE-2024-7652 high 8.0 2y ago An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affe…
CVE-2024-8385 high 8.0 2y ago A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulnerability affects Firefox < 130, Firefox ESR < 128.2…
CVE-2024-8383 high 8.0 2y ago Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-re…
CVE-2024-8382 high 8.0 2y ago Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those interfaces would not be able to…
CVE-2024-8384 high 8.0 2y ago The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. This could have led to memory corruption. This vulner…
CVE-2024-8386 high 8.0 2y ago If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130…
CVE-2024-8387 high 8.0 2y ago Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could…
CVE-2024-8394 high 8.0 2y ago RHSA-2024:6684: thunderbird security update (Important)
CVE-2024-8381 high 8.0 2y ago A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < …
CVE-2024-42472 high 8.0 2y ago Important: bubblewrap and flatpak security update
CVE-2024-6104 high 8.0 2y ago RHSA-2024:5258: container-tools:rhel8 security update (Important)
CVE-2024-37298 high 8.0 2y ago RHSA-2024:5258: container-tools:rhel8 security update (Important)
CVE-2024-38538 high 8.0 2y ago Important: kernel security update
CVE-2024-36025 high 8.0 2y ago Important: kernel security update
CVE-2024-36003 high 8.0 2y ago Important: kernel security update
CVE-2024-40939 high 8.0 2y ago Important: kernel security update
CVE-2024-7348 high 8.0 2y ago RHSA-2024:6018: postgresql:13 security update (Important)
CVE-2024-40957 high 8.0 2y ago Important: kernel security update
CVE-2024-40983 high 8.0 2y ago Important: kernel security update
CVE-2024-41041 high 8.0 2y ago Important: kernel security update
CVE-2024-26668 high 8.0 2y ago Important: kernel security update
CVE-2024-26581 high 8.0 2y ago Important: kernel security update
CVE-2024-40911 high 8.0 2y ago Important: kernel security update
CVE-2024-40929 high 8.0 2y ago Important: kernel security update
CVE-2024-39476 high 8.0 2y ago Important: kernel security update
CVE-2024-4317 high 8.0 2y ago RHSA-2024:6001: postgresql:15 security update (Important)
CVE-2024-42110 high 8.0 2y ago Important: kernel security update
CVE-2024-40914 high 8.0 2y ago Important: kernel security update
CVE-2024-26908 high 8.0 2y ago Important: kernel security update
CVE-2024-38544 high 8.0 2y ago Important: kernel security update
CVE-2024-42152 high 8.0 2y ago Important: kernel security update
CVE-2024-27415 high 8.0 2y ago Important: kernel security update
CVE-2024-38540 high 8.0 2y ago Important: kernel security update
CVE-2024-41090 high 8.0 2y ago Important: kernel security update
CVE-2024-38608 high 8.0 2y ago Important: kernel security update
CVE-2024-41076 high 8.0 2y ago Important: kernel security update
CVE-2024-35839 high 8.0 2y ago Important: kernel security update
CVE-2024-27016 high 8.0 2y ago Important: kernel security update
CVE-2024-27019 high 8.0 2y ago Important: kernel security update
CVE-2024-41091 high 8.0 2y ago Important: kernel security update
CVE-2024-34750 high 8.0 2y ago Important: tomcat security update
CVE-2024-38286 high 8.0 2y ago Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 …
CVE-2024-6221 high 8.0 2y ago A vulnerability in corydolphin/flask-cors up to version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default, without any configuration option. This behavi…
CVE-2024-26853 high 8.0 2y ago Important: kernel security update
CVE-2024-21823 high 8.0 2y ago Important: kernel security update
CVE-2024-36941 high 8.0 2y ago Important: kernel security update
CVE-2024-27434 high 8.0 2y ago Important: kernel security update
CVE-2024-39487 high 8.0 2y ago Important: kernel security update
CVE-2024-7524 high 8.0 2y ago Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Security Policy in "strict-dynamic" mode, an attacker a…
CVE-2024-40954 high 8.0 2y ago Important: kernel security update
CVE-2024-7521 high 8.0 2y ago Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird …
CVE-2024-7522 high 8.0 2y ago Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1,…
CVE-2024-36017 high 8.0 2y ago Important: kernel security update
CVE-2024-36921 high 8.0 2y ago Important: kernel security update
CVE-2024-7520 high 8.0 2y ago A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
CVE-2024-38391 high 8.0 2y ago Important: kernel security update
CVE-2024-35937 high 8.0 2y ago Important: kernel security update
CVE-2024-37353 high 8.0 2y ago Important: kernel security update
CVE-2024-40928 high 8.0 2y ago Important: kernel security update
CVE-2024-6345 high 8.0 2y ago Important: fence-agents security update
CVE-2024-26808 high 8.0 2y ago Important: kernel security update
CVE-2024-26868 high 8.0 2y ago Important: kernel security update
CVE-2024-35852 high 8.0 2y ago Important: kernel security update
CVE-2024-26828 high 8.0 2y ago Important: kernel security update
CVE-2024-7528 high 8.0 2y ago Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
CVE-2024-35800 high 8.0 2y ago Important: kernel security update
CVE-2024-26600 high 8.0 2y ago Important: kernel security update
CVE-2024-38575 high 8.0 2y ago Important: kernel security update
CVE-2024-7519 high 8.0 2y ago Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox escape. This vulnerability affects Firefox …
CVE-2024-7527 high 8.0 2y ago Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thun…
CVE-2024-27417 high 8.0 2y ago Important: kernel security update
CVE-2024-1737 high 8.0 2y ago RHSA-2024:5524: bind security update (Important)
CVE-2024-7518 high 8.0 2y ago Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, an…
CVE-2024-4076 high 8.0 2y ago RHSA-2024:5390: bind9.16 security update (Important)
CVE-2024-1975 high 8.0 2y ago RHSA-2024:5524: bind security update (Important)
CVE-2024-7526 high 8.0 2y ago ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects Firefox < 129, Firefox ES…