CVEs from 2024

6,593 normalized CVEs published or assigned in this year.

Total
6,593
critical
critical 174
high
high 1,069
medium
medium 2,083
low
low 49
% Critical
2.6%
% with KEV
2.5%
% with exploit
3.4%

Top vendors

Top products

  • mbed_tls 15
  • operations_analytics_log_analysis 14
  • surveillance_station 12
  • checkmk 10
  • office 8
  • profilegrid 8
  • office_long_term_servicing_channel 6
  • propertyhive 5
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-35910 medium 5.8 5.8 2y ago In the Linux kernel, the following vulnerability has been resolved: tcp: properly terminate timers for kernel sockets We had various syzbot reports about tcp timers firing after the corresponding n…
CVE-2024-32587 medium 5.8 5.8 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvialoSimple EnvíaloSimple allows Reflected XSS.This issue affects EnvíaloSimple: from n/a throu…
CVE-2024-32547 medium 5.8 5.8 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Max Bond Code Insert Manager (Q2W3 Inc Manager) allows Reflected XSS.This issue affects Code Inse…
CVE-2024-31122 medium 5.8 5.8 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prism IT Systems User Rights Access Manager allows Reflected XSS.This issue affects User Rights A…
CVE-2024-36894 medium 5.6 5.6 2y ago In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix race between aio_cancel() and AIO request complete FFS based applications can utilize the aio_cancel() cal…
CVE-2024-33655 medium 5.5 19d ago Moderate: unbound security update
CVE-2024-51394 medium 5.5 5.5 25d ago Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local attacker to cause a denial of service via the AP_MSP::loop, AP_MSP, AP_MSP.cpp c…
CVE-2024-26766 medium 5.5 4mo ago In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Fix sdma.h tx->num_descs off-by-one error Unfortunately the commit `fd8958efe877` introduced another error causing the `…
CVE-2024-56786 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-57981 medium 5.5 5.5 7mo ago Moderate: kernel security update
CVE-2024-53052 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-57986 medium 5.5 5.5 7mo ago Moderate: kernel security update
CVE-2024-53119 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-47727 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-53680 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-58088 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-56603 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-54456 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-58062 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-53170 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-56662 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-57988 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-49864 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-57989 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-53229 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-53216 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-56690 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-53090 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-57995 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-56709 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-50195 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-53241 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-46689 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-58015 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-58012 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-53135 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-56645 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-57998 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-58083 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-47679 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-58057 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-57987 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-45777 medium 5.5 7mo ago Moderate: grub2 security update
CVE-2024-56675 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-56739 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-50060 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-57990 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-50294 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-49570 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-58075 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-57993 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-58077 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-58068 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-52332 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-13176 medium 5.5 9mo ago Moderate: mysql:8.4 security update
CVE-2024-36357 medium 5.5 9mo ago Moderate: kernel security update
CVE-2024-47252 medium 5.5 9mo ago Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. …
CVE-2024-36350 medium 5.5 10mo ago Moderate: kernel security update
CVE-2024-47081 medium 5.5 10mo ago RHSA-2025:14999: resource-agents security update (Moderate)
CVE-2024-57980 medium 5.5 10mo ago Moderate: kernel security update
CVE-2024-52615 medium 5.5 11mo ago Moderate: avahi security update
CVE-2024-13175 medium 5.5 5.5 11mo ago Authorization Bypass Through User-Controlled Key vulnerability in Vidco Software VOC TESTER allows Forceful Browsing. This issue affects VOC TESTER: before 12.41.0.
CVE-2024-50379 medium 5.5 11mo ago Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (…
CVE-2024-23337 medium 5.5 11mo ago jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning value using an index of 2147483647, the signed integer limit. This causes a denia…
CVE-2024-54661 medium 5.5 11mo ago readline.sh in socat before1.8.0.2 relies on the /tmp/$USER/stderr2 file.
CVE-2024-53064 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: idpf: fix idpf_vc_core_init error path In an event where the platform running the device control plane is rebooted, reset is dete…
CVE-2024-45332 medium 5.5 1y ago RHSA-2025:10991: microcode_ctl security update (Moderate)
CVE-2024-43420 medium 5.5 1y ago RHSA-2025:10991: microcode_ctl security update (Moderate)
CVE-2024-52005 medium 5.5 1y ago RHSA-2025:8414: git security update (Moderate)
CVE-2024-46952 medium 5.5 1y ago RHSA-2025:4362: ghostscript security update (Moderate)
CVE-2024-12747 medium 5.5 1y ago Moderate: rsync security update
CVE-2024-46953 medium 5.5 1y ago RHSA-2025:4362: ghostscript security update (Moderate)
CVE-2024-47544 medium 5.5 1y ago GStreamer is a library for constructing graphs of media-handling components. The function qtdemux_parse_sbgp in qtdemux.c is affected by a null dereference vulnerability. This vulnerability is fixed …
CVE-2024-56605 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: do not leave dangling sk pointer on error in l2cap_sock_create() bt_sock_alloc() allocates the sk object and at…
CVE-2024-47543 medium 5.5 1y ago GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discovered in qtdemux_parse_container function within qtdemux.c. In the parent function…
CVE-2024-42253 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: gpio: pca953x: fix pca953x_irq_bus_sync_unlock race Ensure that `i2c_lock' is held when setting interrupt latch and mask in pca95…
CVE-2024-43820 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: dm-raid: Fix WARN_ON_ONCE check for sync_thread in raid_resume rm-raid devices will occasionally trigger the following warning wh…
CVE-2024-47668 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: lib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc() If we need to increase the tree depth, allocate a new node, and…
CVE-2024-57940 medium 5.5 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: exfat: fix the infinite loop in exfat_readdir() If the file system is corrupted so that a cluster is linked to itself in the clus…
CVE-2024-47715 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: fix oops on non-dbdc mt7986 mt7915_band_config() sets band_idx = 1 on the main phy for mt7986 with MT7975_ONE…
CVE-2024-47601 medium 5.5 1y ago GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_matroska_demux_parse_blockgroup_or_simpleblock fun…
CVE-2024-47545 medium 5.5 1y ago GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in qtdemux_parse_trak function within qtdemux.c. During the strf parsing case, the …
CVE-2024-56611 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: mm/mempolicy: fix migrate_to_node() assuming there is at least one VMA in a MM We currently assume that there is at least one VMA…
CVE-2024-50228 medium 5.5 1y ago RHSA-2025:6966: kernel security update (Moderate)
CVE-2024-4453 medium 5.5 1y ago RHSA-2024:9056: gstreamer1-plugins-base security update (Moderate)
CVE-2024-57890 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: RDMA/uverbs: Prevent integer overflow issue In the expression "cmd.wqe_size * cmd.wr_count", both variables are u32 values that c…
CVE-2024-45775 medium 5.5 1y ago Moderate: grub2 security update
CVE-2024-58009 medium 5.5 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: handle NULL sock pointer in l2cap_sock_alloc A NULL sock pointer is passed into l2cap_sock_alloc() when it is c…
CVE-2024-42316 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: mm/mglru: fix div-by-zero in vmpressure_calc_level() evict_folios() uses a second pass to reclaim folios that have gone through p…
CVE-2024-43828 medium 5.5 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: ext4: fix infinite loop when replaying fast_commit When doing fast_commit replay an infinite loop may occur due to an uninitializ…
CVE-2024-46675 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: core: Prevent USB core invalid event buffer address access This commit addresses an issue where the USB core could acc…
CVE-2024-46754 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: bpf: Remove tst_run from lwt_seg6local_prog_ops. The syzbot reported that the lwt_seg6 related BPF ops can be invoked via bpf_tes…
CVE-2024-35195 medium 5.5 1y ago RHSA-2025:0012: python-requests security update (Moderate)
CVE-2024-46745 medium 5.5 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: Input: uinput - reject requests with unreasonable number of slots When exercising uinput interface syzkaller may try setting up …
CVE-2024-43871 medium 5.5 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: devres: Fix memory leakage caused by driver API devm_free_percpu() It will cause memory leakage when use driver API devm_free_per…
CVE-2024-57798 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: drm/dp_mst: Ensure mst_primary pointer is valid in drm_dp_mst_handle_up_req() While receiving an MST up request message from one …
CVE-2024-44958 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: sched/smt: Fix unbalance sched_smt_present dec/inc I got the following warn report while doing stress test: jump label: negative…
CVE-2024-47835 medium 5.5 1y ago Moderate: gstreamer1-plugins-base security update
CVE-2024-57843 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix overflow inside virtnet_rq_alloc When the frag just got a page, then may lead to regression on VM. Specially if t…
CVE-2024-45000 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: fs/netfs/fscache_cookie: add missing "n_accesses" check This fixes a NULL pointer dereference bug due to a data race which looks …