2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-50665MEDIUM5.5gpac 2.4 contains a SEGV at src/isomedia/drm_sample.c:1562:96 in isom_cenc_get_sai_by_saiz_saio in MP4Box.
CVE-2024-55929MEDIUM5.3A mail spoofing vulnerability in Xerox Workplace Suite allows attackers to forge email headers, making it appear as thou...
CVE-2024-45672MEDIUM6IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local privileged user to overwrite files due to excessive ...
CVE-2024-52327MEDIUM6.5The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry re...
CVE-2024-12079MEDIUM4.8ECOVACS robot lawnmowers store the anti-theft PIN in cleartext on the device filesystem. An attacker can steal a lawnmow...
CVE-2024-12078MEDIUM6.3ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated a...
CVE-2024-10846MEDIUM5.9The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to...
CVE-2024-57947MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo: fix initial map fill The...
CVE-2024-10539MEDIUM5.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uyumsoft In...
CVE-2024-13422MEDIUM6.1The SEO Blogger to WordPress Migration using 301 Redirection plugin for WordPress is vulnerable to Reflected Cross-Site ...
CVE-2024-13389MEDIUM5.4The Cliptakes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cliptakes_input_email'...
CVE-2024-13340MEDIUM5.4The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu...
CVE-2024-13236MEDIUM6.5The Tainacan plugin for WordPress is vulnerable to SQL Injection via the 'collection_id' parameter in all versions up to...
CVE-2024-12504MEDIUM5.4The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored ...
CVE-2024-12118MEDIUM5.4The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Wi...
CVE-2024-43708MEDIUM6.5An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payl...
CVE-2024-12043MEDIUM5.4The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) plugin f...
CVE-2024-13511MEDIUM4.3The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerabilit...
CVE-2024-53299MEDIUM6.5The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple ...
CVE-2024-52972MEDIUM6.5An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted requ...
CVE-2024-43710MEDIUM4.3A server side request forgery vulnerability was identified in Kibana where the /api/fleet/health_check API could be used...
CVE-2024-43707MEDIUM6.5An issue was identified in Kibana where a user without access to Fleet can view Elastic Agent policies that could contai...
CVE-2024-42187MEDIUM5.3BigFix Patch Download Plug-ins are affected by path traversal vulnerability. The application could allow operators to d...
CVE-2024-57724MEDIUM6.5lunasvg v3.0.0 was discovered to contain a segmentation violation via the component gray_record_cell.
CVE-2024-57723MEDIUM6.5lunasvg v3.0.0 was discovered to contain a segmentation violation via the component composition_source_over.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now