2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-56274MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force A...
CVE-2024-56273CRITICAL9.8Missing Authorization vulnerability in wpvividplugins WPvivid Backup and Migration wpvivid-backuprestore allows Accessin...
CVE-2024-56271MEDIUM4.3Missing Authorization vulnerability in SecureSubmit WP SecureSubmit securesubmit allows Exploiting Incorrectly Configure...
CVE-2024-51715HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickWhale ClickWh...
CVE-2024-51700HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eutrue NAVER Analy...
CVE-2024-51651MEDIUM5.3Missing Authorization vulnerability in Imran Tauqeer CubeWP Forms cubewp-forms allows Exploiting Incorrectly Configured ...
CVE-2024-49649CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-49644HIGH8.8Incorrect Privilege Assignment vulnerability in AllAccessible Accessibility by AllAccessible allaccessible allows Privil...
CVE-2024-49633MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Designinvento Dire...
CVE-2024-49294MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-bo...
CVE-2024-49249HIGH8.6Path Traversal: '.../...//' vulnerability in SMSA Express SMSA Shipping smsa-shipping-official allows Path Traversal.Thi...
CVE-2024-49222CRITICAL9.8Deserialization of Untrusted Data vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Object Injecti...
CVE-2024-43243CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in themeglow JobBoard Job listing job-board-light allows U...
CVE-2024-12719MEDIUM4.3The WordPress File Upload plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ...
CVE-2024-12699MEDIUM6.4The Service Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, ...
CVE-2024-12152HIGH7.5The MIPL WC Multisite Sync plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includin...
CVE-2024-54030MEDIUM5.5in OpenHarmony v4.1.2 and prior versions allow a local attacker cause DOS through use after free.
CVE-2024-47398HIGH8.8in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the device is unable to boot up through out-of-bou...
CVE-2024-45070MEDIUM5.5in OpenHarmony v4.1.2 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
CVE-2024-12516MEDIUM6.4The Coupon Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Coupon Code' parameter in a...
CVE-2024-12202HIGH8.8The Croma Music plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escal...
CVE-2024-12077MEDIUM6.1The Booking Calendar and Booking Calendar Pro plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via...
CVE-2024-11627HIGH8.1: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Site...
CVE-2024-11626MEDIUM4.8Improper Neutralization of Input During CMS Backend (adminstrative section) Web Page Generation (XSS or 'Cross-site Scri...
CVE-2024-11625MEDIUM5.3Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affec...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now