2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-13797CRITICAL9.8The PressMart - Modern Elementor WooCommerce WordPress Theme theme for WordPress is vulnerable to arbitrary shortcode ex...
CVE-2024-12860CRITICAL9.8The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via accoun...
CVE-2024-13556CRITICAL9.8The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress is vulnerable to PHP Ob...
CVE-2024-13725CRITICAL9.8The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc...
CVE-2024-57971CRITICAL9.1DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:...
CVE-2024-12562CRITICAL9.8The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216...
CVE-2024-13513CRITICAL9.8The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposure ...
CVE-2024-4282CRITICAL9.8Brocade SANnav OVA before SANnav 2.3.1b enables SHA1 deprecated setting for SSH for port 22.
CVE-2024-56973CRITICAL9.8Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker ...
CVE-2024-56180CRITICAL9.8CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch wit...
CVE-2024-13152CRITICAL10Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BSS Software Mobuy...
CVE-2024-52577CRITICAL9In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Igni...
CVE-2024-13182CRITICAL9.8The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and inclu...
CVE-2024-13346CRITICAL9.8The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode executi...
CVE-2024-13345CRITICAL9.8The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includi...
CVE-2024-13770CRITICAL9.8The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Inje...
CVE-2024-10763CRITICAL9.8The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via th...
CVE-2024-57604CRITICAL9.8An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.
CVE-2024-57602CRITICAL9.8An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php f...
CVE-2024-13477CRITICAL9.8The LTL Freight Quotes – Unishippers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' param...
CVE-2024-13365CRITICAL9.8The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin ...
CVE-2024-12213CRITICAL9.8The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to 2.3.16. This is du...
CVE-2024-13421CRITICAL9.8The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and includi...
CVE-2024-27781CRITICAL9An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS...
CVE-2024-12366CRITICAL9.8PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that c...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now