2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-55930 | CRITICAL | 9.8 | 0.3% | Jan 23, 2025 | Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete fil... |
| CVE-2024-55929 | MEDIUM | 5.3 | 0.2% | Jan 23, 2025 | A mail spoofing vulnerability in Xerox Workplace Suite allows attackers to forge email headers, making it appear as thou... |
| CVE-2024-55928 | HIGH | 7.5 | 0.1% | Jan 23, 2025 | Xerox Workplace Suite exposes sensitive secrets in clear text, both locally and remotely. This vulnerability allows atta... |
| CVE-2024-55927 | HIGH | 7.5 | 0.3% | Jan 23, 2025 | A vulnerability in Xerox Workplace Suite arises from flawed token generation and the use of hard-coded keys. These weakn... |
| CVE-2024-55926 | CRITICAL | 9.8 | 0.4% | Jan 23, 2025 | A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through cr... |
| CVE-2024-45672 | MEDIUM | 6 | 0.1% | Jan 23, 2025 | IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local privileged user to overwrite files due to excessive ... |
| CVE-2024-55925 | HIGH | 7.5 | 0.4% | Jan 23, 2025 | In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the se... |
| CVE-2024-52331 | HIGH | 7.7 | 0.2% | Jan 23, 2025 | ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can crea... |
| CVE-2024-52330 | CRITICAL | 9.5 | 0.3% | Jan 23, 2025 | ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify... |
| CVE-2024-52329 | HIGH | 7.4 | 0.4% | Jan 23, 2025 | ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attack... |
| CVE-2024-52328 | LOW | 2.3 | 0.2% | Jan 23, 2025 | ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker wi... |
| CVE-2024-52327 | MEDIUM | 6.5 | 0.5% | Jan 23, 2025 | The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry re... |
| CVE-2024-12079 | MEDIUM | 4.8 | 0.1% | Jan 23, 2025 | ECOVACS robot lawnmowers store the anti-theft PIN in cleartext on the device filesystem. An attacker can steal a lawnmow... |
| CVE-2024-12078 | MEDIUM | 6.3 | 0.3% | Jan 23, 2025 | ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated a... |
| CVE-2024-11147 | HIGH | 7.6 | 0.4% | Jan 23, 2025 | ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An at... |
| CVE-2024-55971 | CRITICAL | 10 | 0.6% | Jan 23, 2025 | SQL Injection vulnerability in the default configuration of the Logitime WebClock application <= 5.43.0 allows an unauth... |
| CVE-2024-52325 | CRITICAL | 9.6 | 3.0% | Jan 23, 2025 | ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE con... |
| CVE-2024-10846 | MEDIUM | 5.9 | 0.2% | Jan 23, 2025 | The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to... |
| CVE-2024-57947 | MEDIUM | 5.5 | 0.2% | Jan 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo: fix initial map fill The... |
| CVE-2024-10539 | MEDIUM | 5.5 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uyumsoft In... |
| CVE-2024-13422 | MEDIUM | 6.1 | 0.3% | Jan 23, 2025 | The SEO Blogger to WordPress Migration using 301 Redirection plugin for WordPress is vulnerable to Reflected Cross-Site ... |
| CVE-2024-13389 | MEDIUM | 5.4 | 0.2% | Jan 23, 2025 | The Cliptakes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cliptakes_input_email'... |
| CVE-2024-13340 | MEDIUM | 5.4 | 0.3% | Jan 23, 2025 | The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu... |
| CVE-2024-13236 | MEDIUM | 6.5 | 0.4% | Jan 23, 2025 | The Tainacan plugin for WordPress is vulnerable to SQL Injection via the 'collection_id' parameter in all versions up to... |
| CVE-2024-12504 | MEDIUM | 5.4 | 0.2% | Jan 23, 2025 | The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now