2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12118 | MEDIUM | 5.4 | 0.3% | Jan 23, 2025 | The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Wi... |
| CVE-2024-43708 | MEDIUM | 6.5 | 0.4% | Jan 23, 2025 | An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payl... |
| CVE-2024-13234 | CRITICAL | 9.8 | 0.5% | Jan 23, 2025 | The Product Table by WBW plugin for WordPress is vulnerable to SQL Injection via the 'additionalCondition' parameter in ... |
| CVE-2024-12043 | MEDIUM | 5.4 | 0.2% | Jan 23, 2025 | The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) plugin f... |
| CVE-2024-13593 | HIGH | 8.8 | 0.7% | Jan 23, 2025 | The BMLT Meeting Map plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.... |
| CVE-2024-13511 | MEDIUM | 4.3 | 0.2% | Jan 23, 2025 | The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerabilit... |
| CVE-2024-12957 | HIGH | 8.4 | 0.2% | Jan 23, 2025 | A file handling command vulnerability in certain versions of Armoury Crate may result in arbitrary file deletion. Refer ... |
| CVE-2024-53299 | MEDIUM | 6.5 | 1.5% | Jan 23, 2025 | The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple ... |
| CVE-2024-52975 | CRITICAL | 9 | 0.3% | Jan 23, 2025 | An issue was identified in Fleet Server where Fleet policies that could contain sensitive information were logged on INF... |
| CVE-2024-52972 | MEDIUM | 6.5 | 0.4% | Jan 23, 2025 | An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted requ... |
| CVE-2024-43710 | MEDIUM | 4.3 | 0.2% | Jan 23, 2025 | A server side request forgery vulnerability was identified in Kibana where the /api/fleet/health_check API could be used... |
| CVE-2024-43707 | MEDIUM | 6.5 | 0.4% | Jan 23, 2025 | An issue was identified in Kibana where a user without access to Fleet can view Elastic Agent policies that could contai... |
| CVE-2024-42187 | MEDIUM | 5.3 | 0.2% | Jan 23, 2025 | BigFix Patch Download Plug-ins are affected by path traversal vulnerability. The application could allow operators to d... |
| CVE-2024-42186 | LOW | 2.8 | 0.1% | Jan 23, 2025 | BigFix Patch Download Plug-ins are affected by an insecure protocol support. The application can allow improper handlin... |
| CVE-2024-42185 | LOW | 2.5 | 0.1% | Jan 23, 2025 | BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This ... |
| CVE-2024-42184 | LOW | 2.5 | 0.1% | Jan 23, 2025 | BigFix Patch Download Plug-ins are affected by insecure support for file URI scheme. It could allow a malicious operato... |
| CVE-2024-42183 | LOW | 2.5 | 0.1% | Jan 23, 2025 | BigFix Patch Download Plug-ins are affected by an arbitrary file download vulnerability. It could allow a malicious ope... |
| CVE-2024-57724 | MEDIUM | 6.5 | 0.3% | Jan 23, 2025 | lunasvg v3.0.0 was discovered to contain a segmentation violation via the component gray_record_cell. |
| CVE-2024-57723 | MEDIUM | 6.5 | 0.3% | Jan 23, 2025 | lunasvg v3.0.0 was discovered to contain a segmentation violation via the component composition_source_over. |
| CVE-2024-57722 | HIGH | 7.5 | 0.4% | Jan 23, 2025 | lunasvg v3.0.0 was discovered to contain a allocation-size-too-big bug via the component plutovg_surface_create. |
| CVE-2024-57721 | MEDIUM | 6.5 | 0.3% | Jan 23, 2025 | lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_path_add_path. |
| CVE-2024-57720 | MEDIUM | 6.5 | 0.3% | Jan 23, 2025 | lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_blend. |
| CVE-2024-57719 | MEDIUM | 6.5 | 0.4% | Jan 23, 2025 | lunasvg v3.0.0 was discovered to contain a segmentation violation via the component blend_transformed_tiled_argb.isra.0. |
| CVE-2024-42182 | LOW | 2.5 | 0.1% | Jan 23, 2025 | BigFix Patch Download Plug-ins are affected by Server-Side Request Forgery (SSRF) vulnerability. It may allow the appli... |
| CVE-2024-12477 | MEDIUM | 5.4 | 0.2% | Jan 22, 2025 | The Avada Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all v... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now