2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-25595MEDIUM5.3Authentication Bypass by Spoofing vulnerability in WPMU DEV Defender Security allows Functionality Bypass.This issue aff...
CVE-2024-24934HIGH8.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Webs...
CVE-2024-24882CRITICAL9.8Incorrect Privilege Assignment vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects ...
CVE-2024-24874MEDIUM5.3Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in CodePeople CP Polls allow...
CVE-2024-24873MEDIUM5.3: Improper Control of Interaction Frequency vulnerability in CodePeople CP Polls allows Flooding.This issue affects CP P...
CVE-2024-24869HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BoldGrid Total Upkeep al...
CVE-2024-24715MEDIUM6.5Improper Validation of Specified Quantity in Input vulnerability in The Events Calendar BookIt allows Manipulating Hidde...
CVE-2024-23522MEDIUM6.1Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Form Builder T...
CVE-2024-22157CRITICAL9.8Improper Privilege Management vulnerability in WebWizards SalesKing allows Privilege Escalation.This issue affects Sales...
CVE-2024-22145HIGH8.8Incorrect Privilege Assignment vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Conne...
CVE-2024-22139LOW3.7Authentication Bypass by Spoofing vulnerability in Filipe Seabra WordPress Manutenção allows Functionality Bypass.This i...
CVE-2024-21746HIGH7.5Authentication Bypass by Spoofing vulnerability in Roxnor Wp Ultimate Review wp-ultimate-review allows Identity Spoofing...
CVE-2024-35110MEDIUM5.5A reflected XSS vulnerability has been found in YzmCMS 7.1. The vulnerability exists in yzmphp/core/class/application.cl...
CVE-2024-33556CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in 8theme XStore Core.This issue affects XStore Core: from...
CVE-2024-31351CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Copymatic Copymatic – AI Content Writer & Generator.Thi...
CVE-2024-3580MEDIUM6.1The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-3231MEDIUM6.1The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some parameters, which could allow unauthent...
CVE-2024-34757MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visualmodo Borderl...
CVE-2024-34752HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PluginOps L...
CVE-2024-34575MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in deTheme Det...
CVE-2024-34567MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in GhozyLab, I...
CVE-2024-32800MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Felix Moira...
CVE-2024-2744MEDIUM4.3The NextGEN Gallery WordPress plugin before 3.59.1 does not sanitise and escape some of its settings, which could allow...
CVE-2024-2697MEDIUM6.5The socialdriver-framework WordPress plugin before 2024.0.0 does not validate and escape some of its shortcode attribute...
CVE-2024-3551CRITICAL9.8The Penci Soledad Data Migrator plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now