CVEs from 2024
Total
7,194
critical
critical 114
high
high 1,043
medium
medium 1,991
low
low 40
% Critical
1.6%
% with KEV
2.3%
% with exploit
2.3%
Top vendors
Top products
- checkmk 10
- office 8
- profilegrid 8
- office_long_term_servicing_channel 6
- glibc 5
- virtual_traffic_manager 5
- element_pack 5
- propertyhive 5
Top packages
| CVE | Severity | CVSS | Risk | Published | Description | Impact |
|---|---|---|---|---|---|---|
| CVE-2024-21219 | high | — | 8.0 | 1y ago | Important: mysql:8.0 security update | |
| CVE-2024-21201 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-21199 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-21203 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-21212 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-21194 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-21213 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-21193 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-21236 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-11187 | high | — | 8.0 | 1y ago | Important: bind security update | |
| CVE-2024-21198 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-21197 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-7264 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-21238 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-21230 | high | — | 8.0 | 1y ago | Important: mysql:8.0 security update | |
| CVE-2024-21247 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-12705 | high | — | 8.0 | 1y ago | Important: bind9.18 security update | |
| CVE-2024-21237 | high | — | 8.0 | 1y ago | Important: mysql:8.0 security update | |
| CVE-2024-21218 | high | — | 8.0 | 1y ago | Important: mysql:8.0 security update | |
| CVE-2024-11053 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-21241 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-21196 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-21231 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-21239 | high | — | 8.0 | 1y ago | Important: mysql security update | |
| CVE-2024-12797 | high | — | 8.0 | 1y ago | Important: openssl security update | |
| CVE-2024-11218 | high | — | 8.0 | 1y ago | Important: buildah security update | |
| CVE-2024-52531 | high | — | 8.0 | 1y ago | Important: libsoup security update | |
| CVE-2024-51741 | high | — | 8.0 | 1y ago | Important: redis:7 security update | |
| CVE-2024-46981 | high | — | 8.0 | 1y ago | Important: redis:6 security update | |
| CVE-2024-53263 | high | — | 8.0 | 1y ago | Important: git-lfs security update | |
| CVE-2024-12085 | high | — | 8.0 | 1y ago | Important: rsync security update | |
| CVE-2024-56326 | high | — | 8.0 | 1y ago | Important: fence-agents security update | |
| CVE-2024-57823 | high | — | 8.0 | 1y ago | Important: raptor2 security update | |
| CVE-2024-11831 | high | — | 8.0 | 1y ago | A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object type… | |
| CVE-2024-56201 | high | — | 8.0 | 1y ago | Important: fence-agents security update | |
| CVE-2024-54508 | high | — | 8.0 | 1y ago | Important: webkit2gtk3 security update | |
| CVE-2024-54505 | high | — | 8.0 | 1y ago | Important: webkit2gtk3 security update | |
| CVE-2024-54479 | high | — | 8.0 | 1y ago | Important: webkit2gtk3 security update | |
| CVE-2024-54502 | high | — | 8.0 | 1y ago | Important: webkit2gtk3 security update | |
| CVE-2024-11614 | high | — | 8.0 | 1y ago | Important: dpdk security update | |
| CVE-2024-53580 | high | — | 8.0 | 1y ago | Important: iperf3 security update | |
| CVE-2024-50252 | high | — | 8.0 | 1y ago | In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_ipip: Fix memory leak when changing remote IPv6 address The device stores IPv6 addresses that are used for encaps… | |
| CVE-2024-50208 | high | — | 8.0 | 1y ago | In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix a bug while setting up Level-2 PBL pages Avoid memory corruption while setting up Level-2 PBL pages for the non… | |
| CVE-2024-53122 | high | — | 8.0 | 1y ago | In the Linux kernel, the following vulnerability has been resolved: mptcp: cope racing subflow creation in mptcp_rcv_space_adjust Additional active subflows - i.e. created by the in kernel path man… | |
| CVE-2024-46713 | high | — | 8.0 | 1y ago | In the Linux kernel, the following vulnerability has been resolved: perf/aux: Fix AUX buffer serialization Ole reported that event->mmap_mutex is strictly insufficient to serialize the AUX buffer, … | |
| CVE-2024-34156 | high | — | 8.0 | 2y ago | Important: golang security update | |
| CVE-2024-8508 | high | — | 8.0 | 2y ago | Important: unbound security update | |
| CVE-2024-47615 | high | — | 8.0 | 2y ago | Important: gstreamer1-plugins-base security update | |
| CVE-2024-47607 | high | — | 8.0 | 2y ago | Important: gstreamer1-plugins-base security update | |
| CVE-2024-47538 | high | — | 8.0 | 2y ago | Important: gstreamer1-plugins-base security update | |
| CVE-2024-47606 | high | — | 8.0 | 2y ago | Important: gstreamer1-plugins-good security update | |
| CVE-2024-47539 | high | — | 8.0 | 2y ago | Important: gstreamer1-plugins-good security update | |
| CVE-2024-47540 | high | — | 8.0 | 2y ago | Important: gstreamer1-plugins-good security update | |
| CVE-2024-47613 | high | — | 8.0 | 2y ago | Important: gstreamer1-plugins-good security update | |
| CVE-2024-47537 | high | — | 8.0 | 2y ago | Important: gstreamer1-plugins-good security update | |
| CVE-2024-12254 | high | — | 8.0 | 2y ago | Important: python3.12 security update | |
| CVE-2024-9287 | high | — | 8.0 | 2y ago | Important: python39:3.9 security update | |
| CVE-2024-31228 | high | — | 8.0 | 2y ago | Important: redis:6 security update | |
| CVE-2024-31449 | high | — | 8.0 | 2y ago | Important: redis:6 security update | |
| CVE-2024-10979 | high | — | 8.0 | 2y ago | Important: postgresql security update | |
| CVE-2024-10976 | high | — | 8.0 | 2y ago | Important: postgresql security update | |
| CVE-2024-10978 | high | — | 8.0 | 2y ago | Important: postgresql security update | |
| CVE-2024-11697 | high | — | 8.0 | 2y ago | Important: thunderbird security update | |
| CVE-2024-11699 | high | — | 8.0 | 2y ago | Important: thunderbird security update | |
| CVE-2024-11692 | high | — | 8.0 | 2y ago | Important: thunderbird security update | |
| CVE-2024-11695 | high | — | 8.0 | 2y ago | Important: thunderbird security update | |
| CVE-2024-11694 | high | — | 8.0 | 2y ago | Important: thunderbird security update | |
| CVE-2024-52804 | high | — | 8.0 | 2y ago | Important: python-tornado security update | |
| CVE-2024-11696 | high | — | 8.0 | 2y ago | Important: thunderbird security update | |
| CVE-2024-11159 | high | — | 8.0 | 2y ago | Important: thunderbird security update | |
| CVE-2024-52337 | high | — | 8.0 | 2y ago | Important: tuned security update | |
| CVE-2024-52336 | high | — | 8.0 | 2y ago | Important: tuned security update | |
| CVE-2024-10963 | high | — | 8.0 | 2y ago | Important: pam security update | |
| CVE-2024-53899 | high | — | 8.0 | 2y ago | Important: python36:3.6 security update | |
| CVE-2024-45802 | high | — | 8.0 | 2y ago | Important: squid:4 security update | |
| CVE-2024-43499 | high | — | 8.0 | 2y ago | Important: .NET 9.0 security update | |
| CVE-2024-44296 | high | — | 8.0 | 2y ago | Important: webkit2gtk3 security update | |
| CVE-2024-52530 | high | — | 8.0 | 2y ago | Important: libsoup security update | |
| CVE-2024-52532 | high | — | 8.0 | 2y ago | Important: libsoup security update | |
| CVE-2024-43498 | high | — | 8.0 | 2y ago | Important: .NET 9.0 security update | |
| CVE-2024-44244 | high | — | 8.0 | 2y ago | Important: webkit2gtk3 security update | |
| CVE-2024-9050 | high | — | 8.0 | 2y ago | Important: NetworkManager-libreswan security update | |
| CVE-2024-40997 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: cpufreq: amd-pstate: fix memory leak on CPU EPP exit The cpudata memory from kzalloc() in amd_pstate_epp_cpu_init() is not freed … | |
| CVE-2024-26686 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: fs/proc: do_task_stat: use sig->stats_lock to gather the threads/children stats lock_task_sighand() can trigger a hard lockup. I… | |
| CVE-2024-42084 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: ftruncate: pass a signed offset The old ftruncate() syscall, using the 32-bit off_t misses a sign extension when called in compat… | |
| CVE-2024-40906 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Always stop health timer during driver removal Currently, if teardown_hca fails to execute during driver removal, mlx5 … | |
| CVE-2024-39471 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: add error handle to avoid out-of-bounds if the sdma_v4_0_irq_id_to_seq return -EINVAL, the process should be stop to … | |
| CVE-2024-39276 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: ext4: fix mb_cache_entry's e_refcnt leak in ext4_xattr_block_cache_find() Syzbot reports a warning as follows: =================… | |
| CVE-2024-38627 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: stm class: Fix a double free in stm_register_device() The put_device(&stm->dev) call will trigger stm_device_release() which free… | |
| CVE-2024-41056 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Use strnlen() on name fields in V1 wmfw files Use strnlen() instead of strlen() on the algorithm and coefficien… | |
| CVE-2024-39499 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: vmci: prevent speculation leaks by sanitizing event in event_deliver() Coverity spotted that event_msg is controlled by user-spac… | |
| CVE-2024-38555 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Discard command completions in internal error Fix use after free when FW completion arrives while device is in internal… | |
| CVE-2024-26840 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: cachefiles: fix memory leak in cachefiles_add_cache() The following memory leak was reported after unbinding /dev/cachefiles: ==… | |
| CVE-2024-41065 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries: Whitelist dtl slub object for copying to userspace Reading the dispatch trace log from /sys/kernel/debug/powerpc… | |
| CVE-2024-41060 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: drm/radeon: check bo_va->bo is non-NULL before using it The call to radeon_vm_clear_freed might clear bo_va->bo, so we have to ch… | |
| CVE-2024-40901 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Avoid test/set_bit() operating in non-allocated memory There is a potential out-of-bounds access when using test_b… | |
| CVE-2024-36945 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix neighbour and rtable leak in smc_ib_find_route() In smc_ib_find_route(), the neighbour found by neigh_lookup() and r… | |
| CVE-2024-36960 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix invalid reads in fence signaled events Correctly set the length of the drm_event to the size of the structure tha… | |
| CVE-2024-38581 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/mes: fix use-after-free issue Delete fence fallback timer to fix the ramdom use-after-free issue. v2: move to amdgpu_… | |
| CVE-2024-36933 | high | — | 8.0 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: nsh: Restore skb->{protocol,data,mac_header} for outer header in nsh_gso_segment(). syzbot triggered various splats (see [0] and … |