2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-56221 | MEDIUM | 6.5 | 0.2% | Dec 31, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elicus WPMozo Addo... |
| CVE-2024-56219 | MEDIUM | 4.3 | 0.3% | Dec 31, 2024 | Missing Authorization vulnerability in Marketing Fire Widget Options widget-options allows Exploiting Incorrectly Config... |
| CVE-2024-56217 | MEDIUM | 6.3 | 0.3% | Dec 31, 2024 | Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configur... |
| CVE-2024-56215 | MEDIUM | 4.3 | 0.2% | Dec 31, 2024 | Missing Authorization vulnerability in DBAR Productions Member Directory and Contact Form pta-member-directory allows Ex... |
| CVE-2024-56210 | HIGH | 7.1 | 0.3% | Dec 31, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DeluxeThemes Userp... |
| CVE-2024-56209 | HIGH | 7.1 | 0.3% | Dec 31, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeventhQueen Kleo ... |
| CVE-2024-13069 | MEDIUM | 5.4 | 0.4% | Dec 31, 2024 | A vulnerability was found in SourceCodester Multi Role Login System 1.0. It has been classified as problematic. Affected... |
| CVE-2024-12108 | CRITICAL | 9.6 | 6.8% | Dec 31, 2024 | In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public... |
| CVE-2024-12106 | HIGH | 7.5 | 9.4% | Dec 31, 2024 | In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings. |
| CVE-2024-12105 | MEDIUM | 6.5 | 42.4% | Dec 31, 2024 | In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that c... |
| CVE-2024-56232 | HIGH | 7.1 | 0.1% | Dec 31, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Alex Volkov WP Nice Loader wp-nice-loader allows Stored XSS.This issu... |
| CVE-2024-56230 | HIGH | 7.5 | 0.5% | Dec 31, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-56229 | MEDIUM | 4.3 | 0.2% | Dec 31, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in SearchIQ SearchIQ searchiq.This issue affects SearchIQ: from n/a thro... |
| CVE-2024-56222 | MEDIUM | 5.4 | 0.2% | Dec 31, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in CodeBard CodeBard Help Desk codebard-help-desk allows Cross Site Requ... |
| CVE-2024-56220 | CRITICAL | 9.8 | 0.4% | Dec 31, 2024 | Incorrect Privilege Assignment vulnerability in sslplugins SSL Wireless SMS Notification ssl-wireless-sms-notification a... |
| CVE-2024-56218 | MEDIUM | 4.3 | 0.1% | Dec 31, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in sevenspark Contact Form 7 – Dynamic Text Extension contact-form-7-dyn... |
| CVE-2024-56216 | MEDIUM | 6.5 | 0.4% | Dec 31, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-56214 | HIGH | 8.3 | 0.4% | Dec 31, 2024 | Path Traversal: '.../...//' vulnerability in DeluxeThemes Userpro userpro allows Path Traversal.This issue affects Userp... |
| CVE-2024-56213 | HIGH | 8.8 | 0.5% | Dec 31, 2024 | Path Traversal: '.../...//' vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affect... |
| CVE-2024-56212 | HIGH | 8.5 | 0.4% | Dec 31, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DeluxeThemes Userp... |
| CVE-2024-56211 | HIGH | 8.8 | 0.4% | Dec 31, 2024 | Missing Authorization vulnerability in DeluxeThemes Userpro userpro.This issue affects Userpro: from n/a through <= 5.1.... |
| CVE-2024-49422 | LOW | 3.9 | 0.2% | Dec 31, 2024 | Protection Mechanism Failure in bootloader prior to SMR Oct-2024 Release 1 allows physical attackers to reset lockscreen... |
| CVE-2024-13067 | MEDIUM | 5.3 | 0.8% | Dec 31, 2024 | A vulnerability was found in CodeAstro Online Food Ordering System 1.0 and classified as critical. This issue affects so... |
| CVE-2024-11972 | CRITICAL | 9.8 | 54.8% | Dec 31, 2024 | The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthen... |
| CVE-2024-45497 | HIGH | 7.6 | 0.6% | Dec 31, 2024 | A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume m... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now