2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-13321CRITICAL9.8The AnalyticsWP plugin for WordPress is vulnerable to SQL Injection via the 'custom_sql' parameter in all versions up to...
CVE-2024-13824CRITICAL9.8The CiyaShop - Multipurpose WooCommerce Theme theme for WordPress is vulnerable to PHP Object Injection in all versions ...
CVE-2024-11286CRITICAL9.8The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. Th...
CVE-2024-11285CRITICAL9.8The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an...
CVE-2024-11284CRITICAL9.8The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an...
CVE-2024-10838CRITICAL9.1An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory. This m...
CVE-2024-13446CRITICAL9.8The Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and ...
CVE-2024-54085CRITICAL9.8AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish H...
CVE-2024-56336CRITICAL9.8A vulnerability has been identified in SINAMICS S200 (All versions with serial number beginning with SZVS8, SZVS9, SZVS0...
CVE-2024-13924CRITICAL9.1The Starter Templates by FancyWP plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions...
CVE-2024-13359CRITICAL9.8The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficien...
CVE-2024-11087CRITICAL9.8The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerab...
CVE-2024-42733CRITICAL9.8An issue in Docmosis Tornado v.2.9.7 and before allows a remote attacker to execute arbitrary code via a crafted script ...
CVE-2024-53695CRITICAL9.1A buffer overflow vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability co...
CVE-2024-50390CRITICAL9.8A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote ...
CVE-2024-48864CRITICAL9.1A files or directories accessible to external parties vulnerability has been reported to affect File Station 5. If explo...
CVE-2024-13904CRITICAL9.1The Platform.ly for WooCommerce plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions ...
CVE-2024-12876CRITICAL9.8The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeo...
CVE-2024-12144CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Finder Fire Safety...
CVE-2024-12799CRITICAL10Insufficiently Protected Credentials vulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux, 64 b...
CVE-2024-13147CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Merkur Software B2...
CVE-2024-12097CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Boceksoft Informat...
CVE-2024-12281CRITICAL9.8The Homey theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.2. This is...
CVE-2024-11951CRITICAL9.8The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including...
CVE-2024-13787CRITICAL9.8The VEDA - MultiPurpose WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to,...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now