2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-52328LOW2.3ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker wi...
CVE-2024-52327MEDIUM6.5The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry re...
CVE-2024-12079MEDIUM4.8ECOVACS robot lawnmowers store the anti-theft PIN in cleartext on the device filesystem. An attacker can steal a lawnmow...
CVE-2024-12078MEDIUM6.3ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated a...
CVE-2024-11147HIGH7.6ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An at...
CVE-2024-55971CRITICAL10SQL Injection vulnerability in the default configuration of the Logitime WebClock application <= 5.43.0 allows an unauth...
CVE-2024-52325CRITICAL9.6ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE con...
CVE-2024-10846MEDIUM5.9The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to...
CVE-2024-57947MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo: fix initial map fill The...
CVE-2024-10539MEDIUM5.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uyumsoft In...
CVE-2024-13422MEDIUM6.1The SEO Blogger to WordPress Migration using 301 Redirection plugin for WordPress is vulnerable to Reflected Cross-Site ...
CVE-2024-13389MEDIUM5.4The Cliptakes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cliptakes_input_email'...
CVE-2024-13340MEDIUM5.4The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu...
CVE-2024-13236MEDIUM6.5The Tainacan plugin for WordPress is vulnerable to SQL Injection via the 'collection_id' parameter in all versions up to...
CVE-2024-12504MEDIUM5.4The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored ...
CVE-2024-12118MEDIUM5.4The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Wi...
CVE-2024-43708MEDIUM6.5An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payl...
CVE-2024-13234CRITICAL9.8The Product Table by WBW plugin for WordPress is vulnerable to SQL Injection via the 'additionalCondition' parameter in ...
CVE-2024-12043MEDIUM5.4The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) plugin f...
CVE-2024-13593HIGH8.8The BMLT Meeting Map plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2....
CVE-2024-13511MEDIUM4.3The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerabilit...
CVE-2024-12957HIGH8.4A file handling command vulnerability in certain versions of Armoury Crate may result in arbitrary file deletion. Refer ...
CVE-2024-53299MEDIUM6.5The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple ...
CVE-2024-52975CRITICAL9An issue was identified in Fleet Server where Fleet policies that could contain sensitive information were logged on INF...
CVE-2024-52972MEDIUM6.5An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted requ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now