2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52328 | LOW | 2.3 | 0.2% | Jan 23, 2025 | ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker wi... |
| CVE-2024-52327 | MEDIUM | 6.5 | 0.5% | Jan 23, 2025 | The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry re... |
| CVE-2024-12079 | MEDIUM | 4.8 | 0.1% | Jan 23, 2025 | ECOVACS robot lawnmowers store the anti-theft PIN in cleartext on the device filesystem. An attacker can steal a lawnmow... |
| CVE-2024-12078 | MEDIUM | 6.3 | 0.3% | Jan 23, 2025 | ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated a... |
| CVE-2024-11147 | HIGH | 7.6 | 0.4% | Jan 23, 2025 | ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An at... |
| CVE-2024-55971 | CRITICAL | 10 | 0.6% | Jan 23, 2025 | SQL Injection vulnerability in the default configuration of the Logitime WebClock application <= 5.43.0 allows an unauth... |
| CVE-2024-52325 | CRITICAL | 9.6 | 3.0% | Jan 23, 2025 | ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE con... |
| CVE-2024-10846 | MEDIUM | 5.9 | 0.2% | Jan 23, 2025 | The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to... |
| CVE-2024-57947 | MEDIUM | 5.5 | 0.2% | Jan 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo: fix initial map fill The... |
| CVE-2024-10539 | MEDIUM | 5.5 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uyumsoft In... |
| CVE-2024-13422 | MEDIUM | 6.1 | 0.3% | Jan 23, 2025 | The SEO Blogger to WordPress Migration using 301 Redirection plugin for WordPress is vulnerable to Reflected Cross-Site ... |
| CVE-2024-13389 | MEDIUM | 5.4 | 0.2% | Jan 23, 2025 | The Cliptakes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cliptakes_input_email'... |
| CVE-2024-13340 | MEDIUM | 5.4 | 0.3% | Jan 23, 2025 | The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu... |
| CVE-2024-13236 | MEDIUM | 6.5 | 0.4% | Jan 23, 2025 | The Tainacan plugin for WordPress is vulnerable to SQL Injection via the 'collection_id' parameter in all versions up to... |
| CVE-2024-12504 | MEDIUM | 5.4 | 0.2% | Jan 23, 2025 | The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored ... |
| CVE-2024-12118 | MEDIUM | 5.4 | 0.3% | Jan 23, 2025 | The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Wi... |
| CVE-2024-43708 | MEDIUM | 6.5 | 0.4% | Jan 23, 2025 | An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payl... |
| CVE-2024-13234 | CRITICAL | 9.8 | 0.5% | Jan 23, 2025 | The Product Table by WBW plugin for WordPress is vulnerable to SQL Injection via the 'additionalCondition' parameter in ... |
| CVE-2024-12043 | MEDIUM | 5.4 | 0.2% | Jan 23, 2025 | The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) plugin f... |
| CVE-2024-13593 | HIGH | 8.8 | 0.7% | Jan 23, 2025 | The BMLT Meeting Map plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.... |
| CVE-2024-13511 | MEDIUM | 4.3 | 0.2% | Jan 23, 2025 | The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerabilit... |
| CVE-2024-12957 | HIGH | 8.4 | 0.2% | Jan 23, 2025 | A file handling command vulnerability in certain versions of Armoury Crate may result in arbitrary file deletion. Refer ... |
| CVE-2024-53299 | MEDIUM | 6.5 | 1.5% | Jan 23, 2025 | The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple ... |
| CVE-2024-52975 | CRITICAL | 9 | 0.3% | Jan 23, 2025 | An issue was identified in Fleet Server where Fleet policies that could contain sensitive information were logged on INF... |
| CVE-2024-52972 | MEDIUM | 6.5 | 0.4% | Jan 23, 2025 | An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted requ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now