2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54384 | MEDIUM | 4.3 | 0.4% | Dec 16, 2024 | Missing Authorization vulnerability in Anh Tran Falcon – WordPress Optimizations & Tweaks falcon allows Exploiting Incor... |
| CVE-2024-54382 | MEDIUM | 4.9 | 2.2% | Dec 16, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in boldthemes Bold Page Bui... |
| CVE-2024-54380 | HIGH | 7.5 | 0.7% | Dec 16, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Filippo Bodei WP Cookies... |
| CVE-2024-54379 | HIGH | 8.8 | 0.8% | Dec 16, 2024 | Missing Authorization vulnerability in blokhauswp Minterpress minterpress allows Privilege Escalation.This issue affects... |
| CVE-2024-54378 | HIGH | 8.8 | 0.8% | Dec 16, 2024 | Missing Authorization vulnerability in Quietly Quietly Insights quietly-insights allows Privilege Escalation.This issue ... |
| CVE-2024-54375 | HIGH | 7.5 | 0.7% | Dec 16, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sabri Woolook woolook al... |
| CVE-2024-54374 | HIGH | 7.5 | 1.2% | Dec 16, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sabri Sogrid sogrid allo... |
| CVE-2024-54373 | HIGH | 7.5 | 0.7% | Dec 16, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chris Gardenberg EduAdmi... |
| CVE-2024-54372 | CRITICAL | 9.6 | 0.3% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Sourov Amin Insertify insertify allows Code Injection.This issue affe... |
| CVE-2024-54370 | CRITICAL | 9.9 | 0.6% | Dec 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member ... |
| CVE-2024-54369 | CRITICAL | 9.1 | 1.5% | Dec 16, 2024 | Missing Authorization vulnerability in ThemeHunk Zita Site Builder ai-site-builder allows Accessing Functionality Not Pr... |
| CVE-2024-54368 | CRITICAL | 9.6 | 0.3% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in rubengarzajr GitSync git-sync allows Code Injection.This issue affect... |
| CVE-2024-54367 | CRITICAL | 9.8 | 0.7% | Dec 16, 2024 | Deserialization of Untrusted Data vulnerability in Ultimate Member ForumWP forumwp allows Object Injection.This issue af... |
| CVE-2024-54366 | MEDIUM | 5.3 | 0.6% | Dec 16, 2024 | Generation of Error Message Containing Sensitive Information vulnerability in videogallery Vimeography vimeography allow... |
| CVE-2024-54365 | HIGH | 8.8 | 0.5% | Dec 16, 2024 | Incorrect Privilege Assignment vulnerability in Knowhalim KH Easy User Settings kh-easy-user-settings allows Privilege E... |
| CVE-2024-54364 | HIGH | 7.1 | 0.4% | Dec 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spartac Feedpress ... |
| CVE-2024-54363 | CRITICAL | 9.8 | 1.8% | Dec 16, 2024 | Incorrect Privilege Assignment vulnerability in saiful.total Wp NssUser Register wp-nssuser-register allows Privilege Es... |
| CVE-2024-54361 | CRITICAL | 9.3 | 0.5% | Dec 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tenteeglobal Insta... |
| CVE-2024-54360 | MEDIUM | 6.5 | 0.4% | Dec 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in premila Gutensee g... |
| CVE-2024-54359 | HIGH | 8.2 | 0.6% | Dec 16, 2024 | Missing Authorization vulnerability in Saul Morales Pacheco Banner System banner-system allows Exploiting Incorrectly Co... |
| CVE-2024-54358 | HIGH | 7.1 | 0.4% | Dec 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Enrico Cantori 3D ... |
| CVE-2024-54356 | MEDIUM | 5.4 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita mee... |
| CVE-2024-54355 | HIGH | 8.8 | 0.3% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in brandtoss WP Mailster wp-mailster allows Cross Site Request Forgery.T... |
| CVE-2024-54354 | MEDIUM | 6.5 | 0.3% | Dec 16, 2024 | Missing Authorization vulnerability in beat.k Termin-Kalender termin-kalender allows Stored XSS.This issue affects Termi... |
| CVE-2024-54353 | HIGH | 7.1 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in wpgear Hack-Info hack-info allows Stored XSS.This issue affects Hack-... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now