2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-56059CRITICAL9.8Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in farinspace Pa...
CVE-2024-56058CRITICAL9.8Deserialization of Untrusted Data vulnerability in denniskravetstns VRPConnector vrpconnector allows Object Injection.Th...
CVE-2024-56016HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in maartenhemmes Imag...
CVE-2024-56010HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lannoy Devi...
CVE-2024-56008HIGH7.5Missing Authorization vulnerability in spreadr Spreadr Woocommerce spreadr-for-woocomerce allows Accessing Functionality...
CVE-2024-55997MEDIUM6.5Missing Authorization vulnerability in webchunky Order Delivery & Pickup Location Date Time order-delivery-pickup-locati...
CVE-2024-55985HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ydesignservices YD...
CVE-2024-55984HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in susheelhbti Saksh ...
CVE-2024-55983HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PowerFormBuilder P...
CVE-2024-55975HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rohit Urane Dr Aff...
CVE-2024-54350HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hjyl hmd hmd allow...
CVE-2024-54270HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-52485MEDIUM6.5Missing Authorization vulnerability in Yudiz Solutions Ltd. WP Menu Image wp-menu-image allows Exploiting Incorrectly Co...
CVE-2024-51646HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in saoshyant1994 Saos...
CVE-2024-4996CRITICAL9.8Use of a hard-coded password for a database administrator account created during Wapro ERP installation allows an attack...
CVE-2024-4995CRITICAL9.8Wapro ERP Desktop is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypt...
CVE-2024-49677HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Cramer Boots...
CVE-2024-11926MEDIUM6.5The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2024-11912HIGH7.5The Travel Booking WordPress Theme theme for WordPress is vulnerable to blind time-based SQL Injection via the ‘order_id...
CVE-2024-11291MEDIUM5.3The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres...
CVE-2024-47104MEDIUM6.8IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with auth...
CVE-2024-12554MEDIUM5.4The Peter’s Custom Anti-Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and...
CVE-2024-12454MEDIUM6.1The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
CVE-2024-12340MEDIUM4.3The Animation Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ...
CVE-2024-11614HIGH7.4An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an un...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now