2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11613CRITICAL9.8The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrar...
CVE-2024-12585MEDIUM6.1The Property Hive WordPress plugin before 2.1.1 does not sanitise and escape a parameter before outputting it back in th...
CVE-2024-10585MEDIUM5.3The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 ...
CVE-2024-10151MEDIUM5.4The Auto iFrame WordPress plugin before 2.0 does not validate and escape some of its shortcode attributes before outputt...
CVE-2024-54731MEDIUM4cpdf through 2.8 allows stack consumption via a crafted PDF document.
CVE-2024-12205MEDIUM5.4The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slide...
CVE-2024-12030MEDIUM6.5The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'key' attribute o...
CVE-2024-11271MEDIUM4.3The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to modification of data due to a missing ...
CVE-2024-11270HIGH8.8The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to arbitrary file creation due to a missi...
CVE-2024-56456MEDIUM5.5Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successfu...
CVE-2024-56455MEDIUM5.5Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successfu...
CVE-2024-56454MEDIUM5.5Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successfu...
CVE-2024-56453MEDIUM5.5Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successfu...
CVE-2024-56452MEDIUM5.5Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successfu...
CVE-2024-56451MEDIUM5.5Integer overflow vulnerability during glTF model loading in the 3D engine module Impact: Successful exploitation of this...
CVE-2024-56450MEDIUM5.5Buffer overflow vulnerability in the component driver module Impact: Successful exploitation of this vulnerability may a...
CVE-2024-56449HIGH7.5Privilege escalation vulnerability in the Account module Impact: Successful exploitation of this vulnerability may affec...
CVE-2024-56448HIGH7.5Vulnerability of improper access control in the home screen widget module Impact: Successful exploitation of this vulner...
CVE-2024-54121HIGH7.5Startup control vulnerability in the ability module Impact: Successful exploitation of this vulnerability may cause feat...
CVE-2024-12713MEDIUM5.3The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in a...
CVE-2024-12521MEDIUM6.4The Slotti Ajanvaraus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slotti-embed-g...
CVE-2024-12112MEDIUM6.4The Easy Form Builder – WordPress plugin form builder: contact form, survey form, payment form, and custom form builder ...
CVE-2024-11916MEDIUM5.4The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification and ret...
CVE-2024-11816HIGH8.8The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Remote Code Execution in version 3.0....
CVE-2024-56447HIGH7.5Vulnerability of improper permission control in the window management module Impact: Successful exploitation of this vul...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now