2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-55930CRITICAL9.8Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete fil...
CVE-2024-55929MEDIUM5.3A mail spoofing vulnerability in Xerox Workplace Suite allows attackers to forge email headers, making it appear as thou...
CVE-2024-55928HIGH7.5Xerox Workplace Suite exposes sensitive secrets in clear text, both locally and remotely. This vulnerability allows atta...
CVE-2024-55927HIGH7.5A vulnerability in Xerox Workplace Suite arises from flawed token generation and the use of hard-coded keys. These weakn...
CVE-2024-55926CRITICAL9.8A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through cr...
CVE-2024-45672MEDIUM6IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local privileged user to overwrite files due to excessive ...
CVE-2024-55925HIGH7.5In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the se...
CVE-2024-52331HIGH7.7ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can crea...
CVE-2024-52330CRITICAL9.5ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify...
CVE-2024-52329HIGH7.4ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attack...
CVE-2024-52328LOW2.3ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker wi...
CVE-2024-52327MEDIUM6.5The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry re...
CVE-2024-12079MEDIUM4.8ECOVACS robot lawnmowers store the anti-theft PIN in cleartext on the device filesystem. An attacker can steal a lawnmow...
CVE-2024-12078MEDIUM6.3ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated a...
CVE-2024-11147HIGH7.6ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An at...
CVE-2024-55971CRITICAL10SQL Injection vulnerability in the default configuration of the Logitime WebClock application <= 5.43.0 allows an unauth...
CVE-2024-52325CRITICAL9.6ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE con...
CVE-2024-10846MEDIUM5.9The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to...
CVE-2024-57947MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo: fix initial map fill The...
CVE-2024-10539MEDIUM5.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uyumsoft In...
CVE-2024-13422MEDIUM6.1The SEO Blogger to WordPress Migration using 301 Redirection plugin for WordPress is vulnerable to Reflected Cross-Site ...
CVE-2024-13389MEDIUM5.4The Cliptakes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cliptakes_input_email'...
CVE-2024-13340MEDIUM5.4The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu...
CVE-2024-13236MEDIUM6.5The Tainacan plugin for WordPress is vulnerable to SQL Injection via the 'collection_id' parameter in all versions up to...
CVE-2024-12504MEDIUM5.4The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now