2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-56231MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Debuggers Studio S...
CVE-2024-56228HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist...
CVE-2024-56227MEDIUM4.3Missing Authorization vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrec...
CVE-2024-56226MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Ele...
CVE-2024-56225HIGH8.8Missing Authorization vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor allows Accessing...
CVE-2024-56224MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ledenbeheer Ledenb...
CVE-2024-56223HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood Gulr...
CVE-2024-56221MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elicus WPMozo Addo...
CVE-2024-56219MEDIUM4.3Missing Authorization vulnerability in Marketing Fire Widget Options widget-options allows Exploiting Incorrectly Config...
CVE-2024-56217MEDIUM6.3Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configur...
CVE-2024-56215MEDIUM4.3Missing Authorization vulnerability in DBAR Productions Member Directory and Contact Form pta-member-directory allows Ex...
CVE-2024-56210HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DeluxeThemes Userp...
CVE-2024-56209HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeventhQueen Kleo ...
CVE-2024-13069MEDIUM5.4A vulnerability was found in SourceCodester Multi Role Login System 1.0. It has been classified as problematic. Affected...
CVE-2024-12108CRITICAL9.6In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public...
CVE-2024-12106HIGH7.5In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.
CVE-2024-12105MEDIUM6.5In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that c...
CVE-2024-56232HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Alex Volkov WP Nice Loader wp-nice-loader allows Stored XSS.This issu...
CVE-2024-56230HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-56229MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in SearchIQ SearchIQ searchiq.This issue affects SearchIQ: from n/a thro...
CVE-2024-56222MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in CodeBard CodeBard Help Desk codebard-help-desk allows Cross Site Requ...
CVE-2024-56220CRITICAL9.8Incorrect Privilege Assignment vulnerability in sslplugins SSL Wireless SMS Notification ssl-wireless-sms-notification a...
CVE-2024-56218MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in sevenspark Contact Form 7 – Dynamic Text Extension contact-form-7-dyn...
CVE-2024-56216MEDIUM6.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-56214HIGH8.3Path Traversal: '.../...//' vulnerability in DeluxeThemes Userpro userpro allows Path Traversal.This issue affects Userp...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now