2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54391 | HIGH | 7.1 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in mattwalters WordPress Filter wordpress-filter allows Stored XSS.This ... |
| CVE-2024-54390 | HIGH | 7.1 | 0.4% | Dec 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bouzid Nazim Zitou... |
| CVE-2024-54389 | HIGH | 7.1 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Eduardo addWeather myweather allows Cross Site Request Forgery.This i... |
| CVE-2024-54388 | HIGH | 7.1 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Phuc Pham Multiple Admin Emails multiple-admin-emails allows Cross Si... |
| CVE-2024-54387 | HIGH | 7.1 | 0.4% | Dec 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jaytesh Barange Po... |
| CVE-2024-54386 | HIGH | 7.1 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in pushmonkey Push Monkey Pro – Web Push Notifications and WooCommerce A... |
| CVE-2024-54385 | HIGH | 7.2 | 5.1% | Dec 16, 2024 | Server-Side Request Forgery (SSRF) vulnerability in princeahmed Radio Player radio-player allows Server Side Request For... |
| CVE-2024-54384 | MEDIUM | 4.3 | 0.4% | Dec 16, 2024 | Missing Authorization vulnerability in Anh Tran Falcon – WordPress Optimizations & Tweaks falcon allows Exploiting Incor... |
| CVE-2024-54382 | MEDIUM | 4.9 | 2.2% | Dec 16, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in boldthemes Bold Page Bui... |
| CVE-2024-54380 | HIGH | 7.5 | 0.7% | Dec 16, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Filippo Bodei WP Cookies... |
| CVE-2024-54379 | HIGH | 8.8 | 0.8% | Dec 16, 2024 | Missing Authorization vulnerability in blokhauswp Minterpress minterpress allows Privilege Escalation.This issue affects... |
| CVE-2024-54378 | HIGH | 8.8 | 0.8% | Dec 16, 2024 | Missing Authorization vulnerability in Quietly Quietly Insights quietly-insights allows Privilege Escalation.This issue ... |
| CVE-2024-54375 | HIGH | 7.5 | 0.7% | Dec 16, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sabri Woolook woolook al... |
| CVE-2024-54374 | HIGH | 7.5 | 1.2% | Dec 16, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sabri Sogrid sogrid allo... |
| CVE-2024-54373 | HIGH | 7.5 | 0.7% | Dec 16, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chris Gardenberg EduAdmi... |
| CVE-2024-54372 | CRITICAL | 9.6 | 0.3% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Sourov Amin Insertify insertify allows Code Injection.This issue affe... |
| CVE-2024-54370 | CRITICAL | 9.9 | 0.6% | Dec 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member ... |
| CVE-2024-54369 | CRITICAL | 9.1 | 1.5% | Dec 16, 2024 | Missing Authorization vulnerability in ThemeHunk Zita Site Builder ai-site-builder allows Accessing Functionality Not Pr... |
| CVE-2024-54368 | CRITICAL | 9.6 | 0.3% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in rubengarzajr GitSync git-sync allows Code Injection.This issue affect... |
| CVE-2024-54367 | CRITICAL | 9.8 | 0.7% | Dec 16, 2024 | Deserialization of Untrusted Data vulnerability in Ultimate Member ForumWP forumwp allows Object Injection.This issue af... |
| CVE-2024-54366 | MEDIUM | 5.3 | 0.6% | Dec 16, 2024 | Generation of Error Message Containing Sensitive Information vulnerability in videogallery Vimeography vimeography allow... |
| CVE-2024-54365 | HIGH | 8.8 | 0.5% | Dec 16, 2024 | Incorrect Privilege Assignment vulnerability in Knowhalim KH Easy User Settings kh-easy-user-settings allows Privilege E... |
| CVE-2024-54364 | HIGH | 7.1 | 0.4% | Dec 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spartac Feedpress ... |
| CVE-2024-54363 | CRITICAL | 9.8 | 1.8% | Dec 16, 2024 | Incorrect Privilege Assignment vulnerability in saiful.total Wp NssUser Register wp-nssuser-register allows Privilege Es... |
| CVE-2024-54361 | CRITICAL | 9.3 | 0.5% | Dec 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tenteeglobal Insta... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now