2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11826 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Quill Forms | The Best Typeform Alternative | Create Conversational Multi Step Form, Survey, Quiz, Cost Estimation o... |
| CVE-2024-56300 | HIGH | 7.5 | 0.5% | Jan 7, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in wpspin Post/Page Copying Tool postpage-import-export-... |
| CVE-2024-56299 | HIGH | 7.1 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pektsekye Notify O... |
| CVE-2024-56298 | MEDIUM | 5.9 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rob @ 5 Star Plugi... |
| CVE-2024-56297 | MEDIUM | 5.9 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Highl... |
| CVE-2024-56296 | HIGH | 7.1 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kitae Park Mang Bo... |
| CVE-2024-56294 | MEDIUM | 6.4 | 0.4% | Jan 7, 2025 | Missing Authorization vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor allows Exploiting Incorre... |
| CVE-2024-56293 | MEDIUM | 5.9 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nasir Ahmed Advanc... |
| CVE-2024-56292 | MEDIUM | 5.9 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Email Re... |
| CVE-2024-56291 | HIGH | 8.1 | 0.4% | Jan 7, 2025 | Deserialization of Untrusted Data vulnerability in plainware PlainInventory z-inventory-manager allows Object Injection.... |
| CVE-2024-56290 | CRITICAL | 9.3 | 0.4% | Jan 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in silverplugins217 M... |
| CVE-2024-56289 | HIGH | 7.1 | 0.7% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adrian Tobey Groun... |
| CVE-2024-56288 | MEDIUM | 4.8 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood WP D... |
| CVE-2024-56287 | MEDIUM | 6.5 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AppJetty WP jQuery... |
| CVE-2024-56286 | HIGH | 7.5 | 0.6% | Jan 7, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in webcodingplace Classic A... |
| CVE-2024-56285 | MEDIUM | 5.4 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpbits WPBITS Addo... |
| CVE-2024-56284 | CRITICAL | 9.3 | 0.4% | Jan 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in sslplugins SSL Wir... |
| CVE-2024-56283 | HIGH | 8.1 | 0.4% | Jan 7, 2025 | Deserialization of Untrusted Data vulnerability in plainware Locatoraid Store Locator locatoraid allows Object Injection... |
| CVE-2024-56282 | HIGH | 7.5 | 0.6% | Jan 7, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-56281 | HIGH | 7.5 | 0.8% | Jan 7, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-56280 | HIGH | 8.8 | 0.4% | Jan 7, 2025 | Incorrect Privilege Assignment vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Privilege Escalat... |
| CVE-2024-56279 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | Server-Side Request Forgery (SSRF) vulnerability in mra13 Compact WP Audio Player compact-wp-audio-player allows Server ... |
| CVE-2024-56278 | CRITICAL | 9.1 | 1.8% | Jan 7, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders Inc., WP Ultimate Exporter wp-ult... |
| CVE-2024-56276 | HIGH | 8.8 | 0.4% | Jan 7, 2025 | Missing Authorization vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Exploiting Incorrectly Co... |
| CVE-2024-56275 | MEDIUM | 4.1 | 0.4% | Jan 7, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Envato Envato Elements allows Server Side Request Forgery.This issue... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now