2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-56059 | CRITICAL | 9.8 | 1.7% | Dec 18, 2024 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in farinspace Pa... |
| CVE-2024-56058 | CRITICAL | 9.8 | 1.7% | Dec 18, 2024 | Deserialization of Untrusted Data vulnerability in denniskravetstns VRPConnector vrpconnector allows Object Injection.Th... |
| CVE-2024-56016 | HIGH | 7.1 | 0.3% | Dec 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in maartenhemmes Imag... |
| CVE-2024-56010 | HIGH | 7.1 | 0.3% | Dec 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lannoy Devi... |
| CVE-2024-56008 | HIGH | 7.5 | 0.4% | Dec 18, 2024 | Missing Authorization vulnerability in spreadr Spreadr Woocommerce spreadr-for-woocomerce allows Accessing Functionality... |
| CVE-2024-55997 | MEDIUM | 6.5 | 0.4% | Dec 18, 2024 | Missing Authorization vulnerability in webchunky Order Delivery & Pickup Location Date Time order-delivery-pickup-locati... |
| CVE-2024-55985 | HIGH | 8.5 | 0.5% | Dec 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ydesignservices YD... |
| CVE-2024-55984 | HIGH | 8.5 | 0.5% | Dec 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in susheelhbti Saksh ... |
| CVE-2024-55983 | HIGH | 8.5 | 0.4% | Dec 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PowerFormBuilder P... |
| CVE-2024-55975 | HIGH | 8.5 | 0.4% | Dec 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rohit Urane Dr Aff... |
| CVE-2024-54350 | HIGH | 7.1 | 0.3% | Dec 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hjyl hmd hmd allow... |
| CVE-2024-54270 | HIGH | 8.1 | 0.7% | Dec 18, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-52485 | MEDIUM | 6.5 | 0.3% | Dec 18, 2024 | Missing Authorization vulnerability in Yudiz Solutions Ltd. WP Menu Image wp-menu-image allows Exploiting Incorrectly Co... |
| CVE-2024-51646 | HIGH | 7.1 | 0.3% | Dec 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in saoshyant1994 Saos... |
| CVE-2024-4996 | CRITICAL | 9.8 | 0.5% | Dec 18, 2024 | Use of a hard-coded password for a database administrator account created during Wapro ERP installation allows an attack... |
| CVE-2024-4995 | CRITICAL | 9.8 | 0.9% | Dec 18, 2024 | Wapro ERP Desktop is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypt... |
| CVE-2024-49677 | HIGH | 7.1 | 0.3% | Dec 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Cramer Boots... |
| CVE-2024-11926 | MEDIUM | 6.5 | 0.3% | Dec 18, 2024 | The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2024-11912 | HIGH | 7.5 | 0.5% | Dec 18, 2024 | The Travel Booking WordPress Theme theme for WordPress is vulnerable to blind time-based SQL Injection via the ‘order_id... |
| CVE-2024-11291 | MEDIUM | 5.3 | 0.5% | Dec 18, 2024 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres... |
| CVE-2024-47104 | MEDIUM | 6.8 | 0.3% | Dec 18, 2024 | IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with auth... |
| CVE-2024-12554 | MEDIUM | 5.4 | 0.2% | Dec 18, 2024 | The Peter’s Custom Anti-Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and... |
| CVE-2024-12454 | MEDIUM | 6.1 | 0.2% | Dec 18, 2024 | The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all... |
| CVE-2024-12340 | MEDIUM | 4.3 | 0.3% | Dec 18, 2024 | The Animation Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ... |
| CVE-2024-11614 | HIGH | 7.4 | 0.6% | Dec 18, 2024 | An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an un... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now