CVEs from 2024

6,597 normalized CVEs published or assigned in this year.

Total
6,597
critical
critical 174
high
high 1,069
medium
medium 2,083
low
low 49
% Critical
2.6%
% with KEV
2.5%
% with exploit
3.4%

Top vendors

Top products

  • mbed_tls 15
  • operations_analytics_log_analysis 14
  • surveillance_station 12
  • checkmk 10
  • office 8
  • profilegrid 8
  • office_long_term_servicing_channel 6
  • propertyhive 5
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-36953 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-v2: Check for non-NULL vCPU in vgic_v2_parse_attr() vgic_v2_parse_attr() is responsible for finding the vCPU tha…
CVE-2024-41035 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix duplicate endpoint bug by clearing reserved bits in the descriptor Syzbot has identified a bug in usbcore (see the…
CVE-2024-26930 high 8.0 2y ago Important: kernel security update
CVE-2024-27022 high 8.0 2y ago Important: kernel security update
CVE-2024-36016 high 8.0 2y ago Important: kernel security update
CVE-2024-38601 high 8.0 2y ago Important: kernel security update
CVE-2024-26931 high 8.0 2y ago Important: kernel security update
CVE-2024-41071 high 8.0 2y ago Important: kernel security update
CVE-2024-26595 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix NULL pointer dereference in error path When calling mlxsw_sp_acl_tcam_region_destroy() from an erro…
CVE-2024-26665 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: tunnels: fix out of bounds access when building IPv6 PMTU error If the ICMPv6 error is built from a non-linear skb we get the fol…
CVE-2024-38570 high 8.0 2y ago Important: kernel security update
CVE-2024-42246 high 8.0 2y ago Important: kernel security update
CVE-2024-26991 high 8.0 2y ago Important: kernel security update
CVE-2024-38573 high 8.0 2y ago Important: kernel security update
CVE-2024-38562 high 8.0 2y ago Important: kernel security update
CVE-2024-26929 high 8.0 2y ago Important: kernel security update
CVE-2024-36919 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: scsi: bnx2fc: Remove spin_lock_bh while releasing resources after upload The session resources are used by FW and driver when ses…
CVE-2024-26769 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: avoid deadlock on delete association path When deleting an association the shutdown path is deadlocking because we try …
CVE-2024-26739 high 8.0 2y ago Important: kernel security update
CVE-2024-42225 high 8.0 2y ago Important: kernel security update
CVE-2024-34158 high 8.0 2y ago RHSA-2024:8038: container-tools:rhel8 security update (Important)
CVE-2024-34155 high 8.0 2y ago RHSA-2024:8038: container-tools:rhel8 security update (Important)
CVE-2024-45770 high 8.0 2y ago RHSA-2024:6837: pcp security update (Important)
CVE-2024-45769 high 8.0 2y ago RHSA-2024:6837: pcp security update (Important)
CVE-2024-8381 high 8.0 2y ago A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < …
CVE-2024-8394 high 8.0 2y ago RHSA-2024:6684: thunderbird security update (Important)
CVE-2024-8382 high 8.0 2y ago Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those interfaces would not be able to…
CVE-2024-8387 high 8.0 2y ago Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could…
CVE-2024-8386 high 8.0 2y ago If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130…
CVE-2024-8385 high 8.0 2y ago A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulnerability affects Firefox < 130, Firefox ESR < 128.2…
CVE-2024-8384 high 8.0 2y ago The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. This could have led to memory corruption. This vulner…
CVE-2024-8383 high 8.0 2y ago Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-re…
CVE-2024-7652 high 8.0 2y ago An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affe…
CVE-2024-42472 high 8.0 2y ago Important: bubblewrap and flatpak security update
CVE-2024-6104 high 8.0 2y ago RHSA-2024:5258: container-tools:rhel8 security update (Important)
CVE-2024-37298 high 8.0 2y ago RHSA-2024:5258: container-tools:rhel8 security update (Important)
CVE-2024-41090 high 8.0 2y ago Important: kernel security update
CVE-2024-4317 high 8.0 2y ago RHSA-2024:6001: postgresql:15 security update (Important)
CVE-2024-40914 high 8.0 2y ago Important: kernel security update
CVE-2024-7348 high 8.0 2y ago RHSA-2024:6018: postgresql:13 security update (Important)
CVE-2024-41041 high 8.0 2y ago Important: kernel security update
CVE-2024-38538 high 8.0 2y ago Important: kernel security update
CVE-2024-38544 high 8.0 2y ago Important: kernel security update
CVE-2024-40957 high 8.0 2y ago Important: kernel security update
CVE-2024-41076 high 8.0 2y ago Important: kernel security update
CVE-2024-40939 high 8.0 2y ago Important: kernel security update
CVE-2024-40911 high 8.0 2y ago Important: kernel security update
CVE-2024-38608 high 8.0 2y ago Important: kernel security update
CVE-2024-38540 high 8.0 2y ago Important: kernel security update
CVE-2024-36003 high 8.0 2y ago Important: kernel security update
CVE-2024-27415 high 8.0 2y ago Important: kernel security update
CVE-2024-35839 high 8.0 2y ago Important: kernel security update
CVE-2024-42110 high 8.0 2y ago Important: kernel security update
CVE-2024-27016 high 8.0 2y ago Important: kernel security update
CVE-2024-27019 high 8.0 2y ago Important: kernel security update
CVE-2024-26908 high 8.0 2y ago Important: kernel security update
CVE-2024-26581 high 8.0 2y ago Important: kernel security update
CVE-2024-40983 high 8.0 2y ago Important: kernel security update
CVE-2024-40929 high 8.0 2y ago Important: kernel security update
CVE-2024-36025 high 8.0 2y ago Important: kernel security update
CVE-2024-26668 high 8.0 2y ago Important: kernel security update
CVE-2024-39476 high 8.0 2y ago Important: kernel security update
CVE-2024-42152 high 8.0 2y ago Important: kernel security update
CVE-2024-41091 high 8.0 2y ago Important: kernel security update
CVE-2024-38286 high 8.0 2y ago Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 …
CVE-2024-34750 high 8.0 2y ago Important: tomcat security update
CVE-2024-6221 high 8.0 2y ago A vulnerability in corydolphin/flask-cors up to version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default, without any configuration option. This behavi…
CVE-2024-21823 high 8.0 2y ago Important: kernel security update
CVE-2024-27434 high 8.0 2y ago Important: kernel security update
CVE-2024-26853 high 8.0 2y ago Important: kernel security update
CVE-2024-6345 high 8.0 2y ago Important: fence-agents security update
CVE-2024-40954 high 8.0 2y ago Important: kernel security update
CVE-2024-27417 high 8.0 2y ago Important: kernel security update
CVE-2024-35937 high 8.0 2y ago Important: kernel security update
CVE-2024-36017 high 8.0 2y ago Important: kernel security update
CVE-2024-36941 high 8.0 2y ago Important: kernel security update
CVE-2024-1737 high 8.0 2y ago RHSA-2024:5524: bind security update (Important)
CVE-2024-40928 high 8.0 2y ago Important: kernel security update
CVE-2024-38391 high 8.0 2y ago Important: kernel security update
CVE-2024-35911 high 8.0 2y ago Important: kernel security update
CVE-2024-26808 high 8.0 2y ago Important: kernel security update
CVE-2024-4076 high 8.0 2y ago RHSA-2024:5390: bind9.16 security update (Important)
CVE-2024-1975 high 8.0 2y ago RHSA-2024:5524: bind security update (Important)
CVE-2024-7528 high 8.0 2y ago Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
CVE-2024-7527 high 8.0 2y ago Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thun…
CVE-2024-7526 high 8.0 2y ago ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects Firefox < 129, Firefox ES…
CVE-2024-7525 high 8.0 2y ago It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Fi…
CVE-2024-7524 high 8.0 2y ago Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Security Policy in "strict-dynamic" mode, an attacker a…
CVE-2024-7522 high 8.0 2y ago Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1,…
CVE-2024-7521 high 8.0 2y ago Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird …
CVE-2024-39487 high 8.0 2y ago Important: kernel security update
CVE-2024-37353 high 8.0 2y ago Important: kernel security update
CVE-2024-7529 high 8.0 2y ago The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115…
CVE-2024-7520 high 8.0 2y ago A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
CVE-2024-36921 high 8.0 2y ago Important: kernel security update
CVE-2024-7518 high 8.0 2y ago Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, an…
CVE-2024-35852 high 8.0 2y ago Important: kernel security update
CVE-2024-35848 high 8.0 2y ago Important: kernel security update
CVE-2024-35800 high 8.0 2y ago Important: kernel security update
CVE-2024-36903 high 8.0 2y ago Important: kernel security update