2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-43710MEDIUM4.3A server side request forgery vulnerability was identified in Kibana where the /api/fleet/health_check API could be used...
CVE-2024-43707MEDIUM6.5An issue was identified in Kibana where a user without access to Fleet can view Elastic Agent policies that could contai...
CVE-2024-42187MEDIUM5.3BigFix Patch Download Plug-ins are affected by path traversal vulnerability. The application could allow operators to d...
CVE-2024-42186LOW2.8BigFix Patch Download Plug-ins are affected by an insecure protocol support. The application can allow improper handlin...
CVE-2024-42185LOW2.5BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This ...
CVE-2024-42184LOW2.5BigFix Patch Download Plug-ins are affected by insecure support for file URI scheme. It could allow a malicious operato...
CVE-2024-42183LOW2.5BigFix Patch Download Plug-ins are affected by an arbitrary file download vulnerability. It could allow a malicious ope...
CVE-2024-57724MEDIUM6.5lunasvg v3.0.0 was discovered to contain a segmentation violation via the component gray_record_cell.
CVE-2024-57723MEDIUM6.5lunasvg v3.0.0 was discovered to contain a segmentation violation via the component composition_source_over.
CVE-2024-57722HIGH7.5lunasvg v3.0.0 was discovered to contain a allocation-size-too-big bug via the component plutovg_surface_create.
CVE-2024-57721MEDIUM6.5lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_path_add_path.
CVE-2024-57720MEDIUM6.5lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_blend.
CVE-2024-57719MEDIUM6.5lunasvg v3.0.0 was discovered to contain a segmentation violation via the component blend_transformed_tiled_argb.isra.0.
CVE-2024-42182LOW2.5BigFix Patch Download Plug-ins are affected by Server-Side Request Forgery (SSRF) vulnerability. It may allow the appli...
CVE-2024-12477MEDIUM5.4The Avada Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all v...
CVE-2024-56924HIGH7.3A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to...
CVE-2024-56923MEDIUM5.4Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silver...
CVE-2024-56914MEDIUM5.7D-Link DSL-3782 v1.01 is vulnerable to Buffer Overflow in /New_GUI/ParentalControl.asp.
CVE-2024-9310MEDIUM6By utilizing software-defined radios and a custom low-latency processing pipeline, RF signals with spoofed location data...
CVE-2024-11166HIGH7.1For TCAS II systems using transponders compliant with MOPS earlier than RTCA DO-181F, an attacker can impersonate a grou...
CVE-2024-55957HIGH7.8In Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Thermo Foundation Instrument Control Software (ICSW) before 3.1 ...
CVE-2024-51457MEDIUM5.4IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 is vulnerable to cross-...
CVE-2024-55488MEDIUM6.5A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scrip...
CVE-2024-42013MEDIUM6.4In GRAU DATA Blocky before 3.1, Blocky-Gui has a Client-Side Enforcement of Server-Side Security vulnerability. An attac...
CVE-2024-42012MEDIUM5.7GRAU DATA Blocky before 3.1 stores passwords encrypted rather than hashed. At the login screen, the user's password is c...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now