2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50665 | MEDIUM | 5.5 | 0.2% | Jan 23, 2025 | gpac 2.4 contains a SEGV at src/isomedia/drm_sample.c:1562:96 in isom_cenc_get_sai_by_saiz_saio in MP4Box. |
| CVE-2024-55929 | MEDIUM | 5.3 | 0.2% | Jan 23, 2025 | A mail spoofing vulnerability in Xerox Workplace Suite allows attackers to forge email headers, making it appear as thou... |
| CVE-2024-45672 | MEDIUM | 6 | 0.1% | Jan 23, 2025 | IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local privileged user to overwrite files due to excessive ... |
| CVE-2024-52327 | MEDIUM | 6.5 | 0.5% | Jan 23, 2025 | The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry re... |
| CVE-2024-12079 | MEDIUM | 4.8 | 0.1% | Jan 23, 2025 | ECOVACS robot lawnmowers store the anti-theft PIN in cleartext on the device filesystem. An attacker can steal a lawnmow... |
| CVE-2024-12078 | MEDIUM | 6.3 | 0.3% | Jan 23, 2025 | ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated a... |
| CVE-2024-10846 | MEDIUM | 5.9 | 0.2% | Jan 23, 2025 | The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to... |
| CVE-2024-57947 | MEDIUM | 5.5 | 0.2% | Jan 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo: fix initial map fill The... |
| CVE-2024-10539 | MEDIUM | 5.5 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uyumsoft In... |
| CVE-2024-13422 | MEDIUM | 6.1 | 0.3% | Jan 23, 2025 | The SEO Blogger to WordPress Migration using 301 Redirection plugin for WordPress is vulnerable to Reflected Cross-Site ... |
| CVE-2024-13389 | MEDIUM | 5.4 | 0.2% | Jan 23, 2025 | The Cliptakes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cliptakes_input_email'... |
| CVE-2024-13340 | MEDIUM | 5.4 | 0.3% | Jan 23, 2025 | The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu... |
| CVE-2024-13236 | MEDIUM | 6.5 | 0.4% | Jan 23, 2025 | The Tainacan plugin for WordPress is vulnerable to SQL Injection via the 'collection_id' parameter in all versions up to... |
| CVE-2024-12504 | MEDIUM | 5.4 | 0.2% | Jan 23, 2025 | The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored ... |
| CVE-2024-12118 | MEDIUM | 5.4 | 0.3% | Jan 23, 2025 | The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Wi... |
| CVE-2024-43708 | MEDIUM | 6.5 | 0.4% | Jan 23, 2025 | An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payl... |
| CVE-2024-12043 | MEDIUM | 5.4 | 0.2% | Jan 23, 2025 | The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) plugin f... |
| CVE-2024-13511 | MEDIUM | 4.3 | 0.2% | Jan 23, 2025 | The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerabilit... |
| CVE-2024-53299 | MEDIUM | 6.5 | 1.5% | Jan 23, 2025 | The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple ... |
| CVE-2024-52972 | MEDIUM | 6.5 | 0.4% | Jan 23, 2025 | An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted requ... |
| CVE-2024-43710 | MEDIUM | 4.3 | 0.2% | Jan 23, 2025 | A server side request forgery vulnerability was identified in Kibana where the /api/fleet/health_check API could be used... |
| CVE-2024-43707 | MEDIUM | 6.5 | 0.4% | Jan 23, 2025 | An issue was identified in Kibana where a user without access to Fleet can view Elastic Agent policies that could contai... |
| CVE-2024-42187 | MEDIUM | 5.3 | 0.2% | Jan 23, 2025 | BigFix Patch Download Plug-ins are affected by path traversal vulnerability. The application could allow operators to d... |
| CVE-2024-57724 | MEDIUM | 6.5 | 0.3% | Jan 23, 2025 | lunasvg v3.0.0 was discovered to contain a segmentation violation via the component gray_record_cell. |
| CVE-2024-57723 | MEDIUM | 6.5 | 0.3% | Jan 23, 2025 | lunasvg v3.0.0 was discovered to contain a segmentation violation via the component composition_source_over. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now