2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13098MEDIUM5.4The WordPress Email Newsletter WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting i...
CVE-2024-13097MEDIUM5.4The WP Finance WordPress plugin through 1.3.6 does not sanitise and escape a parameter before outputting it back in the ...
CVE-2024-13096MEDIUM4.6The WP Finance WordPress plugin through 1.3.6 does not have CSRF check in some places, and is missing sanitisation as we...
CVE-2024-12768MEDIUM5.4The Responsive iframe WordPress plugin through 1.2.0 does not validate and escape some of its block options before outpu...
CVE-2024-12041MEDIUM5.3The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vul...
CVE-2024-53295HIGH7.8Dell PowerProtect DD versions prior to 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain an improper access control vulnerabilit...
CVE-2024-53296MEDIUM4.9Dell PowerProtect DD versions prior to 7.10.1.50 and 7.13.1.20 contain a Stack-based Buffer Overflow vulnerability in th...
CVE-2024-51534HIGH7.1Dell PowerProtect DD versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain a path traversal vulnerability. A ...
CVE-2024-13651MEDIUM4.3The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized modification of dat...
CVE-2024-13547MEDIUM5.4The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordi...
CVE-2024-13343HIGH8.8The WooCommerce Customers Manager plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability...
CVE-2024-12620MEDIUM5.3The AnimateGL Animations for WordPress – Elementor & Gutenberg Blocks Animations plugin for WordPress is vulnerable to u...
CVE-2024-12184MEDIUM5.3The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to unauthorized access of data due to a missin...
CVE-2024-12171HIGH8.8The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to privilege escalation due t...
CVE-2024-11780MEDIUM5.4The Site Search 360 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ss360-resultbloc...
CVE-2024-57587CRITICAL9.1Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated ...
CVE-2024-57435MEDIUM6.5In macrozheng mall-tiny 1.0.1, an attacker can send null data through the resource creation interface resulting in a nul...
CVE-2024-57434HIGH8.8macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control. The project imports users by default, and the test...
CVE-2024-57433HIGH7.5macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control via the logout function. After a user logs out, the...
CVE-2024-55062CRITICAL9.8Code Injection vulnerability in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers ...
CVE-2024-53357HIGH7.5Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated at...
CVE-2024-53356CRITICAL9.8Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JW...
CVE-2024-53355HIGH8.8Multiple incorrect access control issues in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated ...
CVE-2024-53354MEDIUM6.5Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated at...
CVE-2024-57432HIGH7.5macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do no...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now