2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12118MEDIUM5.4The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Wi...
CVE-2024-43708MEDIUM6.5An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payl...
CVE-2024-13234CRITICAL9.8The Product Table by WBW plugin for WordPress is vulnerable to SQL Injection via the 'additionalCondition' parameter in ...
CVE-2024-12043MEDIUM5.4The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) plugin f...
CVE-2024-13593HIGH8.8The BMLT Meeting Map plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2....
CVE-2024-13511MEDIUM4.3The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerabilit...
CVE-2024-12957HIGH8.4A file handling command vulnerability in certain versions of Armoury Crate may result in arbitrary file deletion. Refer ...
CVE-2024-53299MEDIUM6.5The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple ...
CVE-2024-52975CRITICAL9An issue was identified in Fleet Server where Fleet policies that could contain sensitive information were logged on INF...
CVE-2024-52972MEDIUM6.5An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted requ...
CVE-2024-43710MEDIUM4.3A server side request forgery vulnerability was identified in Kibana where the /api/fleet/health_check API could be used...
CVE-2024-43707MEDIUM6.5An issue was identified in Kibana where a user without access to Fleet can view Elastic Agent policies that could contai...
CVE-2024-42187MEDIUM5.3BigFix Patch Download Plug-ins are affected by path traversal vulnerability. The application could allow operators to d...
CVE-2024-42186LOW2.8BigFix Patch Download Plug-ins are affected by an insecure protocol support. The application can allow improper handlin...
CVE-2024-42185LOW2.5BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This ...
CVE-2024-42184LOW2.5BigFix Patch Download Plug-ins are affected by insecure support for file URI scheme. It could allow a malicious operato...
CVE-2024-42183LOW2.5BigFix Patch Download Plug-ins are affected by an arbitrary file download vulnerability. It could allow a malicious ope...
CVE-2024-57724MEDIUM6.5lunasvg v3.0.0 was discovered to contain a segmentation violation via the component gray_record_cell.
CVE-2024-57723MEDIUM6.5lunasvg v3.0.0 was discovered to contain a segmentation violation via the component composition_source_over.
CVE-2024-57722HIGH7.5lunasvg v3.0.0 was discovered to contain a allocation-size-too-big bug via the component plutovg_surface_create.
CVE-2024-57721MEDIUM6.5lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_path_add_path.
CVE-2024-57720MEDIUM6.5lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_blend.
CVE-2024-57719MEDIUM6.5lunasvg v3.0.0 was discovered to contain a segmentation violation via the component blend_transformed_tiled_argb.isra.0.
CVE-2024-42182LOW2.5BigFix Patch Download Plug-ins are affected by Server-Side Request Forgery (SSRF) vulnerability. It may allow the appli...
CVE-2024-12477MEDIUM5.4The Avada Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all v...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now