2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-56221MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elicus WPMozo Addo...
CVE-2024-56219MEDIUM4.3Missing Authorization vulnerability in Marketing Fire Widget Options widget-options allows Exploiting Incorrectly Config...
CVE-2024-56217MEDIUM6.3Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configur...
CVE-2024-56215MEDIUM4.3Missing Authorization vulnerability in DBAR Productions Member Directory and Contact Form pta-member-directory allows Ex...
CVE-2024-56210HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DeluxeThemes Userp...
CVE-2024-56209HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeventhQueen Kleo ...
CVE-2024-13069MEDIUM5.4A vulnerability was found in SourceCodester Multi Role Login System 1.0. It has been classified as problematic. Affected...
CVE-2024-12108CRITICAL9.6In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public...
CVE-2024-12106HIGH7.5In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.
CVE-2024-12105MEDIUM6.5In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that c...
CVE-2024-56232HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Alex Volkov WP Nice Loader wp-nice-loader allows Stored XSS.This issu...
CVE-2024-56230HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-56229MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in SearchIQ SearchIQ searchiq.This issue affects SearchIQ: from n/a thro...
CVE-2024-56222MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in CodeBard CodeBard Help Desk codebard-help-desk allows Cross Site Requ...
CVE-2024-56220CRITICAL9.8Incorrect Privilege Assignment vulnerability in sslplugins SSL Wireless SMS Notification ssl-wireless-sms-notification a...
CVE-2024-56218MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in sevenspark Contact Form 7 – Dynamic Text Extension contact-form-7-dyn...
CVE-2024-56216MEDIUM6.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-56214HIGH8.3Path Traversal: '.../...//' vulnerability in DeluxeThemes Userpro userpro allows Path Traversal.This issue affects Userp...
CVE-2024-56213HIGH8.8Path Traversal: '.../...//' vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affect...
CVE-2024-56212HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DeluxeThemes Userp...
CVE-2024-56211HIGH8.8Missing Authorization vulnerability in DeluxeThemes Userpro userpro.This issue affects Userpro: from n/a through <= 5.1....
CVE-2024-49422LOW3.9Protection Mechanism Failure in bootloader prior to SMR Oct-2024 Release 1 allows physical attackers to reset lockscreen...
CVE-2024-13067MEDIUM5.3A vulnerability was found in CodeAstro Online Food Ordering System 1.0 and classified as critical. This issue affects so...
CVE-2024-11972CRITICAL9.8The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthen...
CVE-2024-45497HIGH7.6A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume m...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now