CVEs from 2024
Total
7,195
critical
critical 114
high
high 1,020
medium
medium 2,013
low
low 42
% Critical
1.6%
% with KEV
2.3%
% with exploit
2.3%
Top products
- surveillance_station 12
- checkmk 10
- profilegrid 8
- office 8
- office_long_term_servicing_channel 6
- glibc 5
- virtual_traffic_manager 5
- element_pack 5
Top packages
| CVE | Severity | CVSS | Risk | Published | Description | Impact |
|---|---|---|---|---|---|---|
| CVE-2024-21230 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-11187 | high | — | 8.0 | 1y ago | Important: bind security update | |
| CVE-2024-21199 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-21198 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-11053 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-21238 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-21247 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-21219 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-21201 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-21241 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-12705 | high | — | 8.0 | 1y ago | Important: bind9.18 security update | |
| CVE-2024-12797 | high | — | 8.0 | 1y ago | Important: openssl security update | |
| CVE-2024-11218 | high | — | 8.0 | 1y ago | Important: podman security update | |
| CVE-2024-52531 | high | — | 8.0 | 1y ago | Important: libsoup security update | |
| CVE-2024-51741 | high | — | 8.0 | 1y ago | Important: redis:7 security update | |
| CVE-2024-46981 | high | — | 8.0 | 1y ago | Important: redis:6 security update | |
| CVE-2024-53263 | high | — | 8.0 | 1y ago | Important: git-lfs security update | |
| CVE-2024-12085 | high | — | 8.0 | 1y ago | Important: rsync security update | |
| CVE-2024-11831 | high | — | 8.0 | 1y ago | A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object type… | |
| CVE-2024-57823 | high | — | 8.0 | 1y ago | Important: raptor2 security update | |
| CVE-2024-56326 | high | — | 8.0 | 1y ago | Important: fence-agents security update | |
| CVE-2024-56201 | high | — | 8.0 | 1y ago | Important: fence-agents security update | |
| CVE-2024-54479 | high | — | 8.0 | 1y ago | Important: webkit2gtk3 security update | |
| CVE-2024-54505 | high | — | 8.0 | 1y ago | Important: webkit2gtk3 security update | |
| CVE-2024-54502 | high | — | 8.0 | 1y ago | Important: webkit2gtk3 security update | |
| CVE-2024-11614 | high | — | 8.0 | 1y ago | Important: dpdk security update | |
| CVE-2024-53580 | high | — | 8.0 | 1y ago | Important: iperf3 security update | |
| CVE-2024-50252 | high | — | 8.0 | 1y ago | In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_ipip: Fix memory leak when changing remote IPv6 address The device stores IPv6 addresses that are used for encaps… | |
| CVE-2024-53122 | high | — | 8.0 | 1y ago | In the Linux kernel, the following vulnerability has been resolved: mptcp: cope racing subflow creation in mptcp_rcv_space_adjust Additional active subflows - i.e. created by the in kernel path man… | |
| CVE-2024-50208 | high | — | 8.0 | 1y ago | In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix a bug while setting up Level-2 PBL pages Avoid memory corruption while setting up Level-2 PBL pages for the non… | |
| CVE-2024-46713 | high | — | 8.0 | 1y ago | In the Linux kernel, the following vulnerability has been resolved: perf/aux: Fix AUX buffer serialization Ole reported that event->mmap_mutex is strictly insufficient to serialize the AUX buffer, … | |
| CVE-2024-8508 | high | — | 8.0 | 2y ago | Important: unbound security update | |
| CVE-2024-34156 | high | — | 8.0 | 2y ago | Important: delve and golang security update | |
| CVE-2024-47540 | high | — | 8.0 | 2y ago | Important: gstreamer1-plugins-good security update | |
| CVE-2024-47539 | high | — | 8.0 | 2y ago | Important: gstreamer1-plugins-good security update | |
| CVE-2024-47537 | high | — | 8.0 | 2y ago | Important: gstreamer1-plugins-good security update | |
| CVE-2024-47615 | high | — | 8.0 | 2y ago | Important: gstreamer1-plugins-base security update | |
| CVE-2024-47613 | high | — | 8.0 | 2y ago | Important: gstreamer1-plugins-good security update | |
| CVE-2024-47607 | high | — | 8.0 | 2y ago | Important: gstreamer1-plugins-base security update | |
| CVE-2024-47538 | high | — | 8.0 | 2y ago | Important: gstreamer1-plugins-base security update | |
| CVE-2024-47606 | high | — | 8.0 | 2y ago | Important: gstreamer1-plugins-good security update | |
| CVE-2024-12254 | high | — | 8.0 | 2y ago | Important: python3.12 security update | |
| CVE-2024-10976 | high | — | 8.0 | 2y ago | Important: postgresql:16 security update | |
| CVE-2024-10978 | high | — | 8.0 | 2y ago | Important: postgresql:16 security update | |
| CVE-2024-10979 | high | — | 8.0 | 2y ago | Important: postgresql:16 security update | |
| CVE-2024-11697 | high | — | 8.0 | 2y ago | Important: thunderbird security update | |
| CVE-2024-11692 | high | — | 8.0 | 2y ago | Important: thunderbird security update | |
| CVE-2024-52804 | high | — | 8.0 | 2y ago | Important: python-tornado security update | |
| CVE-2024-11699 | high | — | 8.0 | 2y ago | Important: thunderbird security update | |
| CVE-2024-11159 | high | — | 8.0 | 2y ago | Important: thunderbird security update | |
| CVE-2024-11694 | high | — | 8.0 | 2y ago | Important: thunderbird security update | |
| CVE-2024-11696 | high | — | 8.0 | 2y ago | Important: thunderbird security update | |
| CVE-2024-11695 | high | — | 8.0 | 2y ago | Important: thunderbird security update | |
| CVE-2024-52336 | high | — | 8.0 | 2y ago | Important: tuned security update | |
| CVE-2024-52337 | high | — | 8.0 | 2y ago | Important: tuned security update | |
| CVE-2024-10963 | high | — | 8.0 | 2y ago | Important: pam:1.5.1 security update | |
| CVE-2024-53899 | high | — | 8.0 | 2y ago | Important: python36:3.6 security update | |
| CVE-2024-9632 | high | — | 8.0 | 2y ago | Important: tigervnc security update | |
| CVE-2024-45802 | high | — | 8.0 | 2y ago | Important: squid security update | |
| CVE-2024-52530 | high | — | 8.0 | 2y ago | Important: libsoup security update | |
| CVE-2024-44296 | high | — | 8.0 | 2y ago | Important: webkit2gtk3 security update | |
| CVE-2024-44244 | high | — | 8.0 | 2y ago | Important: webkit2gtk3 security update | |
| CVE-2024-52532 | high | — | 8.0 | 2y ago | Important: libsoup security update | |
| CVE-2024-43499 | high | — | 8.0 | 2y ago | Important: .NET 9.0 security update | |
| CVE-2024-43498 | high | — | 8.0 | 2y ago | Important: .NET 9.0 security update | |
| CVE-2024-9050 | high | — | 8.0 | 2y ago | Important: NetworkManager-libreswan security update | |
| CVE-2024-26772 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: ext4: avoid allocating blocks from corrupted group in ext4_mb_find_by_goal() Places the logic for checking if the group's block b… | |
| CVE-2024-35946 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix null pointer access when abort scan During cancel scan we might use vif that weren't scanning. Fix this by using… | |
| CVE-2024-26759 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: mm/swap: fix race when skipping swapcache When skipping swapcache for SWP_SYNCHRONOUS_IO, if two or more threads swapin the same … | |
| CVE-2024-27010 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: net/sched: Fix mirred deadlock on device recursion When the mirred action is used on a classful egress qdisc and a packet is mirr… | |
| CVE-2024-26656 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix use-after-free bug The bug can be triggered by sending a single amdgpu_gem_userptr_ioctl to the AMDGPU DRM driver… | |
| CVE-2024-35947 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: dyndbg: fix old BUG_ON in >control parser Fix a BUG_ON from 2009. Even if it looks "unreachable" (I didn't really look), lets ma… | |
| CVE-2024-42226 | high | — | 8.0 | 2y ago | Important: kernel security update | |
| CVE-2024-26846 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: nvme-fc: do not wait in vain when unloading module The module exit path has race between deleting all controllers and freeing 'le… | |
| CVE-2024-26614 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: tcp: make sure init the accept_queue's spinlocks once When I run syz's reproduction C program locally, it causes the following is… | |
| CVE-2024-26840 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: cachefiles: fix memory leak in cachefiles_add_cache() The following memory leak was reported after unbinding /dev/cachefiles: ==… | |
| CVE-2024-35938 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: decrease MHI channel buffer length to 8KB Currently buf_len field of ath11k_mhi_config_qca6390 is assigned with 0, … | |
| CVE-2024-42237 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Validate payload length before processing block Move the payload length check in cs_dsp_load() and cs_dsp_coeff… | |
| CVE-2024-35854 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix possible use-after-free during rehash The rehash delayed work migrates filters from one region to a… | |
| CVE-2024-26645 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: tracing: Ensure visibility when inserting an element into tracing_map Running the following two commands in parallel on a multi-p… | |
| CVE-2024-42084 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: ftruncate: pass a signed offset The old ftruncate() syscall, using the 32-bit off_t misses a sign extension when called in compat… | |
| CVE-2024-26638 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: nbd: always initialize struct msghdr completely syzbot complains that msg->msg_get_inq value can be uninitialized [1] struct msg… | |
| CVE-2024-26704 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: ext4: fix double-free of blocks due to wrong extents moved_len In ext4_move_extents(), moved_len is only updated when all moves a… | |
| CVE-2024-41008 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: change vm->task_info handling This patch changes the handling and lifecycle of vm->task_info object. The major change… | |
| CVE-2024-35924 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: Limit read size on v1.2 Between UCSI 1.2 and UCSI 2.0, the size of the MESSAGE_IN region was increased from 16 … | |
| CVE-2024-26686 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: fs/proc: do_task_stat: use sig->stats_lock to gather the threads/children stats lock_task_sighand() can trigger a hard lockup. I… | |
| CVE-2024-44970 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: SHAMPO, Fix invalid WQ linked list unlink When all the strides in a WQE have been consumed, the WQE is unlinked from t… | |
| CVE-2024-26843 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: efi: runtime: Fix potential overflow of soft-reserved region size md_size will have been narrowed if we have >= 4GB worth of page… | |
| CVE-2024-26837 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: net: bridge: switchdev: Skip MDB replays of deferred events on offload Before this change, generation of the list of MDB events t… | |
| CVE-2024-35912 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: rfi: fix potential response leaks If the rx payload length check fails, or if kmemdup() fails, we still need … | |
| CVE-2024-27011 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix memleak in map from abort path The delete set command does not rely on the transaction object for eleme… | |
| CVE-2024-35809 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: PCI/PM: Drain runtime-idle callbacks before driver removal A race condition between the .runtime_idle() callback and the .remove(… | |
| CVE-2024-35810 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix the lifetime of the bo cursor memory The cleanup can be dispatched while the atomic update is still active, which… | |
| CVE-2024-42228 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc Initialize the size before calling amdgpu_vce_cs_rel… | |
| CVE-2024-35824 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: misc: lis3lv02d_i2c: Fix regulators getting en-/dis-abled twice on suspend/resume When not configured for wakeup lis3lv02d_i2c_su… | |
| CVE-2024-41012 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: filelock: Remove locks reliably when fcntl/close race is detected When fcntl_setlk() races with close(), it removes the created l… | |
| CVE-2024-36896 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix access violation during port device removal Testing with KASAN and syzkaller revealed a bug in port.c:disable_stor… | |
| CVE-2024-36010 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: igb: Fix string truncation warnings in igb_set_fw_version Commit 1978d3ead82c ("intel: fix string truncation warnings") fixes '-W… | |
| CVE-2024-41007 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: tcp: avoid too many retransmit packets If a TCP socket is using TCP_USER_TIMEOUT, and the other peer retracted its window to zero… | |
| CVE-2024-36920 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Avoid memcpy field-spanning write WARNING When the "storcli2 show" command is executed for eHBA-9600, mpi3mr driver… |