2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13321 | CRITICAL | 9.8 | 0.4% | Mar 14, 2025 | The AnalyticsWP plugin for WordPress is vulnerable to SQL Injection via the 'custom_sql' parameter in all versions up to... |
| CVE-2024-13824 | CRITICAL | 9.8 | 0.6% | Mar 14, 2025 | The CiyaShop - Multipurpose WooCommerce Theme theme for WordPress is vulnerable to PHP Object Injection in all versions ... |
| CVE-2024-11286 | CRITICAL | 9.8 | 0.6% | Mar 14, 2025 | The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. Th... |
| CVE-2024-11285 | CRITICAL | 9.8 | 0.4% | Mar 14, 2025 | The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an... |
| CVE-2024-11284 | CRITICAL | 9.8 | 0.5% | Mar 14, 2025 | The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an... |
| CVE-2024-10838 | CRITICAL | 9.1 | 0.9% | Mar 12, 2025 | An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory. This m... |
| CVE-2024-13446 | CRITICAL | 9.8 | 0.4% | Mar 12, 2025 | The Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and ... |
| CVE-2024-54085 | CRITICAL | 9.8 | 61.2% | Mar 11, 2025 | AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish H... |
| CVE-2024-56336 | CRITICAL | 9.8 | 0.5% | Mar 11, 2025 | A vulnerability has been identified in SINAMICS S200 (All versions with serial number beginning with SZVS8, SZVS9, SZVS0... |
| CVE-2024-13924 | CRITICAL | 9.1 | 0.4% | Mar 8, 2025 | The Starter Templates by FancyWP plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions... |
| CVE-2024-13359 | CRITICAL | 9.8 | 0.8% | Mar 8, 2025 | The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficien... |
| CVE-2024-11087 | CRITICAL | 9.8 | 0.4% | Mar 8, 2025 | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerab... |
| CVE-2024-42733 | CRITICAL | 9.8 | 1.0% | Mar 7, 2025 | An issue in Docmosis Tornado v.2.9.7 and before allows a remote attacker to execute arbitrary code via a crafted script ... |
| CVE-2024-53695 | CRITICAL | 9.1 | 0.5% | Mar 7, 2025 | A buffer overflow vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability co... |
| CVE-2024-50390 | CRITICAL | 9.8 | 1.1% | Mar 7, 2025 | A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote ... |
| CVE-2024-48864 | CRITICAL | 9.1 | 0.5% | Mar 7, 2025 | A files or directories accessible to external parties vulnerability has been reported to affect File Station 5. If explo... |
| CVE-2024-13904 | CRITICAL | 9.1 | 0.4% | Mar 7, 2025 | The Platform.ly for WooCommerce plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions ... |
| CVE-2024-12876 | CRITICAL | 9.8 | 0.4% | Mar 7, 2025 | The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeo... |
| CVE-2024-12144 | CRITICAL | 9.8 | 0.4% | Mar 6, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Finder Fire Safety... |
| CVE-2024-12799 | CRITICAL | 10 | 0.4% | Mar 5, 2025 | Insufficiently Protected Credentials vulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux, 64 b... |
| CVE-2024-13147 | CRITICAL | 9.8 | 0.4% | Mar 5, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Merkur Software B2... |
| CVE-2024-12097 | CRITICAL | 9.8 | 0.4% | Mar 5, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Boceksoft Informat... |
| CVE-2024-12281 | CRITICAL | 9.8 | 0.4% | Mar 5, 2025 | The Homey theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.2. This is... |
| CVE-2024-11951 | CRITICAL | 9.8 | 0.4% | Mar 5, 2025 | The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including... |
| CVE-2024-13787 | CRITICAL | 9.8 | 0.6% | Mar 5, 2025 | The VEDA - MultiPurpose WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to,... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now