2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-56282 | HIGH | 7.5 | 0.6% | Jan 7, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-56281 | HIGH | 7.5 | 0.8% | Jan 7, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-56280 | HIGH | 8.8 | 0.4% | Jan 7, 2025 | Incorrect Privilege Assignment vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Privilege Escalat... |
| CVE-2024-56279 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | Server-Side Request Forgery (SSRF) vulnerability in mra13 Compact WP Audio Player compact-wp-audio-player allows Server ... |
| CVE-2024-56278 | CRITICAL | 9.1 | 1.8% | Jan 7, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders Inc., WP Ultimate Exporter wp-ult... |
| CVE-2024-56276 | HIGH | 8.8 | 0.4% | Jan 7, 2025 | Missing Authorization vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Exploiting Incorrectly Co... |
| CVE-2024-56275 | MEDIUM | 4.1 | 0.4% | Jan 7, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Envato Envato Elements allows Server Side Request Forgery.This issue... |
| CVE-2024-56274 | MEDIUM | 5.4 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force A... |
| CVE-2024-56273 | CRITICAL | 9.8 | 0.4% | Jan 7, 2025 | Missing Authorization vulnerability in wpvividplugins WPvivid Backup and Migration wpvivid-backuprestore allows Accessin... |
| CVE-2024-56271 | MEDIUM | 4.3 | 0.3% | Jan 7, 2025 | Missing Authorization vulnerability in SecureSubmit WP SecureSubmit securesubmit allows Exploiting Incorrectly Configure... |
| CVE-2024-51715 | HIGH | 8.5 | 0.4% | Jan 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickWhale ClickWh... |
| CVE-2024-51700 | HIGH | 7.1 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eutrue NAVER Analy... |
| CVE-2024-51651 | MEDIUM | 5.3 | 0.4% | Jan 7, 2025 | Missing Authorization vulnerability in Imran Tauqeer CubeWP Forms cubewp-forms allows Exploiting Incorrectly Configured ... |
| CVE-2024-49649 | CRITICAL | 9.8 | 0.6% | Jan 7, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-49644 | HIGH | 8.8 | 0.4% | Jan 7, 2025 | Incorrect Privilege Assignment vulnerability in AllAccessible Accessibility by AllAccessible allaccessible allows Privil... |
| CVE-2024-49633 | MEDIUM | 6.1 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Designinvento Dire... |
| CVE-2024-49294 | MEDIUM | 4.3 | 0.2% | Jan 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-bo... |
| CVE-2024-49249 | HIGH | 8.6 | 0.5% | Jan 7, 2025 | Path Traversal: '.../...//' vulnerability in SMSA Express SMSA Shipping smsa-shipping-official allows Path Traversal.Thi... |
| CVE-2024-49222 | CRITICAL | 9.8 | 0.5% | Jan 7, 2025 | Deserialization of Untrusted Data vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Object Injecti... |
| CVE-2024-43243 | CRITICAL | 10 | 0.5% | Jan 7, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in themeglow JobBoard Job listing job-board-light allows U... |
| CVE-2024-12719 | MEDIUM | 4.3 | 0.3% | Jan 7, 2025 | The WordPress File Upload plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ... |
| CVE-2024-12699 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Service Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, ... |
| CVE-2024-12152 | HIGH | 7.5 | 1.0% | Jan 7, 2025 | The MIPL WC Multisite Sync plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includin... |
| CVE-2024-54030 | MEDIUM | 5.5 | 0.2% | Jan 7, 2025 | in OpenHarmony v4.1.2 and prior versions allow a local attacker cause DOS through use after free. |
| CVE-2024-47398 | HIGH | 8.8 | 0.2% | Jan 7, 2025 | in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the device is unable to boot up through out-of-bou... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now