2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-56310HIGH8.8REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery...
CVE-2024-12895CRITICAL9.8A vulnerability has been found in TreasureHuntGame TreasureHunt up to 963e0e0 and classified as critical. Affected by th...
CVE-2024-12894CRITICAL9.8A vulnerability, which was classified as critical, was found in TreasureHuntGame TreasureHunt up to 963e0e0. Affected is...
CVE-2024-12893MEDIUM5.4A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar up to 2.9. Affected by this ...
CVE-2024-12892MEDIUM5.4A vulnerability classified as problematic was found in code-projects Online Exam Mastering System 1.0. Affected by this ...
CVE-2024-12891HIGH8.8A vulnerability classified as critical has been found in code-projects Online Exam Mastering System 1.0. Affected is an ...
CVE-2024-12890HIGH8.8A vulnerability was found in code-projects Online Exam Mastering System 1.0. It has been rated as critical. This issue a...
CVE-2024-11852MEDIUM4.3The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for...
CVE-2024-51464MEDIUM4.3IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By sending a specially craft...
CVE-2024-51463MEDIUM5.4IBM i 7.3, 7.4, and 7.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker ...
CVE-2024-12884CRITICAL9.8A vulnerability was found in Codezips E-Commerce Website 1.0. It has been rated as critical. Affected by this issue is s...
CVE-2024-12883MEDIUM6.1A vulnerability was found in code-projects Job Recruitment 1.0. It has been declared as problematic. Affected by this vu...
CVE-2024-12875MEDIUM4.9The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Direct...
CVE-2024-12591MEDIUM6.4The MagicPost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wb_share_social shortco...
CVE-2024-12558MEDIUM6.5The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to unauthorized access of da...
CVE-2024-12408MEDIUM6.1The WP on AWS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST data in all versions up to...
CVE-2024-11722MEDIUM5.9The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all ...
CVE-2024-11688MEDIUM6.1The LaTeX2HTML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ver' or 'date' parameter in...
CVE-2024-10453MEDIUM5.4The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2024-9545MEDIUM5.4The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2024-12588MEDIUM5.4The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2024-11808MEDIUM6.1The Pingmeter Uptime Monitoring plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_wpnonce' ...
CVE-2024-10797MEDIUM4.3The Full Screen Menu for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and...
CVE-2024-12771HIGH8.8The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in a...
CVE-2024-12721HIGH7.2The Custom Product Tabs For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now