2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43710 | MEDIUM | 4.3 | 0.2% | Jan 23, 2025 | A server side request forgery vulnerability was identified in Kibana where the /api/fleet/health_check API could be used... |
| CVE-2024-43707 | MEDIUM | 6.5 | 0.4% | Jan 23, 2025 | An issue was identified in Kibana where a user without access to Fleet can view Elastic Agent policies that could contai... |
| CVE-2024-42187 | MEDIUM | 5.3 | 0.2% | Jan 23, 2025 | BigFix Patch Download Plug-ins are affected by path traversal vulnerability. The application could allow operators to d... |
| CVE-2024-42186 | LOW | 2.8 | 0.1% | Jan 23, 2025 | BigFix Patch Download Plug-ins are affected by an insecure protocol support. The application can allow improper handlin... |
| CVE-2024-42185 | LOW | 2.5 | 0.1% | Jan 23, 2025 | BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This ... |
| CVE-2024-42184 | LOW | 2.5 | 0.1% | Jan 23, 2025 | BigFix Patch Download Plug-ins are affected by insecure support for file URI scheme. It could allow a malicious operato... |
| CVE-2024-42183 | LOW | 2.5 | 0.1% | Jan 23, 2025 | BigFix Patch Download Plug-ins are affected by an arbitrary file download vulnerability. It could allow a malicious ope... |
| CVE-2024-57724 | MEDIUM | 6.5 | 0.3% | Jan 23, 2025 | lunasvg v3.0.0 was discovered to contain a segmentation violation via the component gray_record_cell. |
| CVE-2024-57723 | MEDIUM | 6.5 | 0.3% | Jan 23, 2025 | lunasvg v3.0.0 was discovered to contain a segmentation violation via the component composition_source_over. |
| CVE-2024-57722 | HIGH | 7.5 | 0.4% | Jan 23, 2025 | lunasvg v3.0.0 was discovered to contain a allocation-size-too-big bug via the component plutovg_surface_create. |
| CVE-2024-57721 | MEDIUM | 6.5 | 0.3% | Jan 23, 2025 | lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_path_add_path. |
| CVE-2024-57720 | MEDIUM | 6.5 | 0.3% | Jan 23, 2025 | lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_blend. |
| CVE-2024-57719 | MEDIUM | 6.5 | 0.4% | Jan 23, 2025 | lunasvg v3.0.0 was discovered to contain a segmentation violation via the component blend_transformed_tiled_argb.isra.0. |
| CVE-2024-42182 | LOW | 2.5 | 0.1% | Jan 23, 2025 | BigFix Patch Download Plug-ins are affected by Server-Side Request Forgery (SSRF) vulnerability. It may allow the appli... |
| CVE-2024-12477 | MEDIUM | 5.4 | 0.2% | Jan 22, 2025 | The Avada Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all v... |
| CVE-2024-56924 | HIGH | 7.3 | 0.4% | Jan 22, 2025 | A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to... |
| CVE-2024-56923 | MEDIUM | 5.4 | 0.3% | Jan 22, 2025 | Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silver... |
| CVE-2024-56914 | MEDIUM | 5.7 | 0.3% | Jan 22, 2025 | D-Link DSL-3782 v1.01 is vulnerable to Buffer Overflow in /New_GUI/ParentalControl.asp. |
| CVE-2024-9310 | MEDIUM | 6 | 0.2% | Jan 22, 2025 | By utilizing software-defined radios and a custom low-latency processing pipeline, RF signals with spoofed location data... |
| CVE-2024-11166 | HIGH | 7.1 | 0.3% | Jan 22, 2025 | For TCAS II systems using transponders compliant with MOPS earlier than RTCA DO-181F, an attacker can impersonate a grou... |
| CVE-2024-55957 | HIGH | 7.8 | 0.2% | Jan 22, 2025 | In Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Thermo Foundation Instrument Control Software (ICSW) before 3.1 ... |
| CVE-2024-51457 | MEDIUM | 5.4 | 0.2% | Jan 22, 2025 | IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 is vulnerable to cross-... |
| CVE-2024-55488 | MEDIUM | 6.5 | 0.3% | Jan 22, 2025 | A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scrip... |
| CVE-2024-42013 | MEDIUM | 6.4 | 0.2% | Jan 22, 2025 | In GRAU DATA Blocky before 3.1, Blocky-Gui has a Client-Side Enforcement of Server-Side Security vulnerability. An attac... |
| CVE-2024-42012 | MEDIUM | 5.7 | 0.1% | Jan 22, 2025 | GRAU DATA Blocky before 3.1 stores passwords encrypted rather than hashed. At the login screen, the user's password is c... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now