2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11613 | CRITICAL | 9.8 | 4.4% | Jan 8, 2025 | The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrar... |
| CVE-2024-12585 | MEDIUM | 6.1 | 0.6% | Jan 8, 2025 | The Property Hive WordPress plugin before 2.1.1 does not sanitise and escape a parameter before outputting it back in th... |
| CVE-2024-10585 | MEDIUM | 5.3 | 0.6% | Jan 8, 2025 | The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 ... |
| CVE-2024-10151 | MEDIUM | 5.4 | 0.3% | Jan 8, 2025 | The Auto iFrame WordPress plugin before 2.0 does not validate and escape some of its shortcode attributes before outputt... |
| CVE-2024-54731 | MEDIUM | 4 | 0.2% | Jan 8, 2025 | cpdf through 2.8 allows stack consumption via a crafted PDF document. |
| CVE-2024-12205 | MEDIUM | 5.4 | 0.3% | Jan 8, 2025 | The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slide... |
| CVE-2024-12030 | MEDIUM | 6.5 | 0.5% | Jan 8, 2025 | The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'key' attribute o... |
| CVE-2024-11271 | MEDIUM | 4.3 | 0.4% | Jan 8, 2025 | The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to modification of data due to a missing ... |
| CVE-2024-11270 | HIGH | 8.8 | 0.9% | Jan 8, 2025 | The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to arbitrary file creation due to a missi... |
| CVE-2024-56456 | MEDIUM | 5.5 | 0.1% | Jan 8, 2025 | Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successfu... |
| CVE-2024-56455 | MEDIUM | 5.5 | 0.1% | Jan 8, 2025 | Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successfu... |
| CVE-2024-56454 | MEDIUM | 5.5 | 0.1% | Jan 8, 2025 | Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successfu... |
| CVE-2024-56453 | MEDIUM | 5.5 | 0.1% | Jan 8, 2025 | Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successfu... |
| CVE-2024-56452 | MEDIUM | 5.5 | 0.1% | Jan 8, 2025 | Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successfu... |
| CVE-2024-56451 | MEDIUM | 5.5 | 0.1% | Jan 8, 2025 | Integer overflow vulnerability during glTF model loading in the 3D engine module Impact: Successful exploitation of this... |
| CVE-2024-56450 | MEDIUM | 5.5 | 0.1% | Jan 8, 2025 | Buffer overflow vulnerability in the component driver module Impact: Successful exploitation of this vulnerability may a... |
| CVE-2024-56449 | HIGH | 7.5 | 0.2% | Jan 8, 2025 | Privilege escalation vulnerability in the Account module Impact: Successful exploitation of this vulnerability may affec... |
| CVE-2024-56448 | HIGH | 7.5 | 0.2% | Jan 8, 2025 | Vulnerability of improper access control in the home screen widget module Impact: Successful exploitation of this vulner... |
| CVE-2024-54121 | HIGH | 7.5 | 0.2% | Jan 8, 2025 | Startup control vulnerability in the ability module Impact: Successful exploitation of this vulnerability may cause feat... |
| CVE-2024-12713 | MEDIUM | 5.3 | 0.3% | Jan 8, 2025 | The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in a... |
| CVE-2024-12521 | MEDIUM | 6.4 | 0.3% | Jan 8, 2025 | The Slotti Ajanvaraus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slotti-embed-g... |
| CVE-2024-12112 | MEDIUM | 6.4 | 0.2% | Jan 8, 2025 | The Easy Form Builder – WordPress plugin form builder: contact form, survey form, payment form, and custom form builder ... |
| CVE-2024-11916 | MEDIUM | 5.4 | 0.2% | Jan 8, 2025 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification and ret... |
| CVE-2024-11816 | HIGH | 8.8 | 0.7% | Jan 8, 2025 | The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Remote Code Execution in version 3.0.... |
| CVE-2024-56447 | HIGH | 7.5 | 0.2% | Jan 8, 2025 | Vulnerability of improper permission control in the window management module Impact: Successful exploitation of this vul... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now