2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10539 | MEDIUM | 5.5 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uyumsoft In... |
| CVE-2024-13422 | MEDIUM | 6.1 | 0.3% | Jan 23, 2025 | The SEO Blogger to WordPress Migration using 301 Redirection plugin for WordPress is vulnerable to Reflected Cross-Site ... |
| CVE-2024-13389 | MEDIUM | 5.4 | 0.2% | Jan 23, 2025 | The Cliptakes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cliptakes_input_email'... |
| CVE-2024-13340 | MEDIUM | 5.4 | 0.3% | Jan 23, 2025 | The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu... |
| CVE-2024-13236 | MEDIUM | 6.5 | 0.4% | Jan 23, 2025 | The Tainacan plugin for WordPress is vulnerable to SQL Injection via the 'collection_id' parameter in all versions up to... |
| CVE-2024-12504 | MEDIUM | 5.4 | 0.2% | Jan 23, 2025 | The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored ... |
| CVE-2024-12118 | MEDIUM | 5.4 | 0.3% | Jan 23, 2025 | The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Wi... |
| CVE-2024-43708 | MEDIUM | 6.5 | 0.4% | Jan 23, 2025 | An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payl... |
| CVE-2024-12043 | MEDIUM | 5.4 | 0.2% | Jan 23, 2025 | The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) plugin f... |
| CVE-2024-13511 | MEDIUM | 4.3 | 0.2% | Jan 23, 2025 | The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerabilit... |
| CVE-2024-53299 | MEDIUM | 6.5 | 1.5% | Jan 23, 2025 | The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple ... |
| CVE-2024-52972 | MEDIUM | 6.5 | 0.4% | Jan 23, 2025 | An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted requ... |
| CVE-2024-43710 | MEDIUM | 4.3 | 0.2% | Jan 23, 2025 | A server side request forgery vulnerability was identified in Kibana where the /api/fleet/health_check API could be used... |
| CVE-2024-43707 | MEDIUM | 6.5 | 0.4% | Jan 23, 2025 | An issue was identified in Kibana where a user without access to Fleet can view Elastic Agent policies that could contai... |
| CVE-2024-42187 | MEDIUM | 5.3 | 0.2% | Jan 23, 2025 | BigFix Patch Download Plug-ins are affected by path traversal vulnerability. The application could allow operators to d... |
| CVE-2024-57724 | MEDIUM | 6.5 | 0.3% | Jan 23, 2025 | lunasvg v3.0.0 was discovered to contain a segmentation violation via the component gray_record_cell. |
| CVE-2024-57723 | MEDIUM | 6.5 | 0.3% | Jan 23, 2025 | lunasvg v3.0.0 was discovered to contain a segmentation violation via the component composition_source_over. |
| CVE-2024-57721 | MEDIUM | 6.5 | 0.3% | Jan 23, 2025 | lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_path_add_path. |
| CVE-2024-57720 | MEDIUM | 6.5 | 0.3% | Jan 23, 2025 | lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_blend. |
| CVE-2024-57719 | MEDIUM | 6.5 | 0.4% | Jan 23, 2025 | lunasvg v3.0.0 was discovered to contain a segmentation violation via the component blend_transformed_tiled_argb.isra.0. |
| CVE-2024-12477 | MEDIUM | 5.4 | 0.2% | Jan 22, 2025 | The Avada Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all v... |
| CVE-2024-56923 | MEDIUM | 5.4 | 0.3% | Jan 22, 2025 | Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silver... |
| CVE-2024-56914 | MEDIUM | 5.7 | 0.3% | Jan 22, 2025 | D-Link DSL-3782 v1.01 is vulnerable to Buffer Overflow in /New_GUI/ParentalControl.asp. |
| CVE-2024-9310 | MEDIUM | 6 | 0.2% | Jan 22, 2025 | By utilizing software-defined radios and a custom low-latency processing pipeline, RF signals with spoofed location data... |
| CVE-2024-51457 | MEDIUM | 5.4 | 0.2% | Jan 22, 2025 | IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 is vulnerable to cross-... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now