2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-54384MEDIUM4.3Missing Authorization vulnerability in Anh Tran Falcon – WordPress Optimizations & Tweaks falcon allows Exploiting Incor...
CVE-2024-54382MEDIUM4.9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in boldthemes Bold Page Bui...
CVE-2024-54380HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Filippo Bodei WP Cookies...
CVE-2024-54379HIGH8.8Missing Authorization vulnerability in blokhauswp Minterpress minterpress allows Privilege Escalation.This issue affects...
CVE-2024-54378HIGH8.8Missing Authorization vulnerability in Quietly Quietly Insights quietly-insights allows Privilege Escalation.This issue ...
CVE-2024-54375HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sabri Woolook woolook al...
CVE-2024-54374HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sabri Sogrid sogrid allo...
CVE-2024-54373HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chris Gardenberg EduAdmi...
CVE-2024-54372CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in Sourov Amin Insertify insertify allows Code Injection.This issue affe...
CVE-2024-54370CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member ...
CVE-2024-54369CRITICAL9.1Missing Authorization vulnerability in ThemeHunk Zita Site Builder ai-site-builder allows Accessing Functionality Not Pr...
CVE-2024-54368CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in rubengarzajr GitSync git-sync allows Code Injection.This issue affect...
CVE-2024-54367CRITICAL9.8Deserialization of Untrusted Data vulnerability in Ultimate Member ForumWP forumwp allows Object Injection.This issue af...
CVE-2024-54366MEDIUM5.3Generation of Error Message Containing Sensitive Information vulnerability in videogallery Vimeography vimeography allow...
CVE-2024-54365HIGH8.8Incorrect Privilege Assignment vulnerability in Knowhalim KH Easy User Settings kh-easy-user-settings allows Privilege E...
CVE-2024-54364HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spartac Feedpress ...
CVE-2024-54363CRITICAL9.8Incorrect Privilege Assignment vulnerability in saiful.total Wp NssUser Register wp-nssuser-register allows Privilege Es...
CVE-2024-54361CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tenteeglobal Insta...
CVE-2024-54360MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in premila Gutensee g...
CVE-2024-54359HIGH8.2Missing Authorization vulnerability in Saul Morales Pacheco Banner System banner-system allows Exploiting Incorrectly Co...
CVE-2024-54358HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Enrico Cantori 3D ...
CVE-2024-54356MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita mee...
CVE-2024-54355HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in brandtoss WP Mailster wp-mailster allows Cross Site Request Forgery.T...
CVE-2024-54354MEDIUM6.5Missing Authorization vulnerability in beat.k Termin-Kalender termin-kalender allows Stored XSS.This issue affects Termi...
CVE-2024-54353HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in wpgear Hack-Info hack-info allows Stored XSS.This issue affects Hack-...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now