2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-56282HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-56281HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-56280HIGH8.8Incorrect Privilege Assignment vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Privilege Escalat...
CVE-2024-56279MEDIUM6.4Server-Side Request Forgery (SSRF) vulnerability in mra13 Compact WP Audio Player compact-wp-audio-player allows Server ...
CVE-2024-56278CRITICAL9.1Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders Inc., WP Ultimate Exporter wp-ult...
CVE-2024-56276HIGH8.8Missing Authorization vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Exploiting Incorrectly Co...
CVE-2024-56275MEDIUM4.1Server-Side Request Forgery (SSRF) vulnerability in Envato Envato Elements allows Server Side Request Forgery.This issue...
CVE-2024-56274MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force A...
CVE-2024-56273CRITICAL9.8Missing Authorization vulnerability in wpvividplugins WPvivid Backup and Migration wpvivid-backuprestore allows Accessin...
CVE-2024-56271MEDIUM4.3Missing Authorization vulnerability in SecureSubmit WP SecureSubmit securesubmit allows Exploiting Incorrectly Configure...
CVE-2024-51715HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickWhale ClickWh...
CVE-2024-51700HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eutrue NAVER Analy...
CVE-2024-51651MEDIUM5.3Missing Authorization vulnerability in Imran Tauqeer CubeWP Forms cubewp-forms allows Exploiting Incorrectly Configured ...
CVE-2024-49649CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-49644HIGH8.8Incorrect Privilege Assignment vulnerability in AllAccessible Accessibility by AllAccessible allaccessible allows Privil...
CVE-2024-49633MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Designinvento Dire...
CVE-2024-49294MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-bo...
CVE-2024-49249HIGH8.6Path Traversal: '.../...//' vulnerability in SMSA Express SMSA Shipping smsa-shipping-official allows Path Traversal.Thi...
CVE-2024-49222CRITICAL9.8Deserialization of Untrusted Data vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Object Injecti...
CVE-2024-43243CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in themeglow JobBoard Job listing job-board-light allows U...
CVE-2024-12719MEDIUM4.3The WordPress File Upload plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ...
CVE-2024-12699MEDIUM6.4The Service Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, ...
CVE-2024-12152HIGH7.5The MIPL WC Multisite Sync plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includin...
CVE-2024-54030MEDIUM5.5in OpenHarmony v4.1.2 and prior versions allow a local attacker cause DOS through use after free.
CVE-2024-47398HIGH8.8in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the device is unable to boot up through out-of-bou...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now