2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-32959HIGH8.8Incorrect Privilege Assignment vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a t...
CVE-2024-32830HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeKraft BuddyForms al...
CVE-2024-32827MEDIUM5.3Authentication Bypass by Spoofing vulnerability in RafflePress Giveaways and Contests allows Functionality Bypass.This i...
CVE-2024-32809CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in JumpDEMAND Inc. ActiveDEMAND allows Using Malicious Fil...
CVE-2024-32802MEDIUM5.3Missing Authorization vulnerability in WordPlus BP Better Messages allows Accessing Functionality Not Properly Constrain...
CVE-2024-32786CRITICAL9.8Authentication Bypass by Spoofing vulnerability in WP Royal Royal Elementor Addons allows Functionality Bypass.This issu...
CVE-2024-32774HIGH8.8Improper Restriction of Excessive Authentication Attempts vulnerability in Metagauss ProfileGrid allows Removing Importa...
CVE-2024-32720MEDIUM5.3Improper Restriction of Excessive Authentication Attempts vulnerability in CodePeople Appointment Hour Booking allows Re...
CVE-2024-32708LOW3.7Authentication Bypass by Spoofing vulnerability in helderk Maintenance Mode allows Functionality Bypass.This issue affec...
CVE-2024-32692HIGH8.2Missing Authorization vulnerability in QuanticaLabs Chauffeur Taxi Booking System for WordPress allows Accessing Functio...
CVE-2024-22120HIGH8.8Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "...
CVE-2024-4789MEDIUM6.4Cost Calculator Builder Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to 3.1....
CVE-2024-4214LOW2.7Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Bill Minozzi Car Dealer al...
CVE-2024-34434MEDIUM6.5Incorrect Authorization vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Code Inclusi...
CVE-2024-34370HIGH7.2Improper Privilege Management vulnerability in WPFactory EAN for WooCommerce allows Privilege Escalation.This issue affe...
CVE-2024-33917MEDIUM5.3Authentication Bypass by Spoofing vulnerability in webtechideas WTI Like Post allows Functionality Bypass.This issue aff...
CVE-2024-33644CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in WPCustomify Customify Site Library allows Cod...
CVE-2024-33569HIGH7.2Improper Privilege Management vulnerability in Darren Cooney Instant Images allows Privilege Escalation.This issue affec...
CVE-2024-33567CRITICAL9.8Improper Privilege Management vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows Privile...
CVE-2024-33552CRITICAL9.8Improper Privilege Management vulnerability in 8theme XStore Core allows Privilege Escalation.This issue affects XStore ...
CVE-2024-33550HIGH8.8Improper Privilege Management vulnerability in JR King/Eran Schoellhorn WP Masquerade allows Privilege Escalation.This i...
CVE-2024-33549HIGH8.8Improper Privilege Management vulnerability in AA-Team WZone allows Privilege Escalation.This issue affects WZone: from ...
CVE-2024-32790MEDIUM4.3Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Supsystic Pricing Table b...
CVE-2024-32685MEDIUM5.3Client-Side Enforcement of Server-Side Security vulnerability in Wpmet Wp Ultimate Review allows Functionality Bypass.Th...
CVE-2024-32680HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code (...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now