2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13147CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Merkur Software B2...
CVE-2024-12097CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Boceksoft Informat...
CVE-2024-11216HIGH7.6Authorization Bypass Through User-Controlled Key, Exposure of Private Personal Information to an Unauthorized Actor vuln...
CVE-2024-13471HIGH7.5The DesignThemes Core Features plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi...
CVE-2024-13423MEDIUM5.3The Sparkling theme for WordPress is vulnerable to unauthorized plugin activation/deactivation due to a missing capabili...
CVE-2024-12650MEDIUM5.4An attacker with low privileges can manipulate the requested memory size, causing the application to use an invalid memo...
CVE-2024-12281CRITICAL9.8The Homey theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.2. This is...
CVE-2024-11951CRITICAL9.8The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including...
CVE-2024-11153MEDIUM5.3The Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More plugin...
CVE-2024-5667MEDIUM6.4Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Featherlight.js Ja...
CVE-2024-13839MEDIUM6.1The Staff Directory Plugin: Company Directory plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t...
CVE-2024-13815MEDIUM6.5The The Listingo theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including...
CVE-2024-13811MEDIUM4.3The Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce Theme theme for WordPress is vulnerable to unauthoriz...
CVE-2024-13810MEDIUM4.3The Zass - WooCommerce Theme for Handmade Artists and Artisans theme for WordPress is vulnerable to unauthorized access ...
CVE-2024-13809MEDIUM6.5The Hero Slider - WordPress Slider Plugin plugin for WordPress is vulnerable to SQL Injection via several parameters in ...
CVE-2024-13787CRITICAL9.8The VEDA - MultiPurpose WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to,...
CVE-2024-13780MEDIUM6.5The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to arbitrary file deletion due ...
CVE-2024-13779MEDIUM6.1The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripti...
CVE-2024-13778MEDIUM6.5The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to SQL Injection via several fu...
CVE-2024-13777CRITICAL9.8The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to PHP Object Injection in...
CVE-2024-13757MEDIUM5.4The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2024-13747MEDIUM4.3The WooMail - WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized loss of data due to a miss...
CVE-2024-13232HIGH8.8The WordPress Awesome Import & Export Plugin - Import & Export WordPress Data plugin for WordPress is vulnerable arbitra...
CVE-2024-12815MEDIUM6.4The Point Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'point_maker' shortco...
CVE-2024-11731MEDIUM5.4The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now