2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37268 | HIGH | 8.8 | 0.5% | Jul 9, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in kaptinlin Striking allow... |
| CVE-2024-37266 | HIGH | 7.2 | 0.6% | Jul 9, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Tutor LMS allows... |
| CVE-2024-37090 | HIGH | 8.8 | 0.5% | Jul 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Mas... |
| CVE-2024-6069 | HIGH | 8.8 | 0.6% | Jul 9, 2024 | The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & C... |
| CVE-2024-5479 | HIGH | 7.2 | 0.4% | Jul 9, 2024 | The Easy Pixels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all versions up... |
| CVE-2024-5456 | HIGH | 8.8 | 0.9% | Jul 9, 2024 | The Panda Video plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.0 v... |
| CVE-2024-3604 | HIGH | 8.8 | 0.5% | Jul 9, 2024 | The OSM – OpenStreetMap plugin for WordPress is vulnerable to SQL Injection via the 'tagged_filter' attribute of the 'os... |
| CVE-2024-37502 | HIGH | 7.5 | 0.3% | Jul 9, 2024 | Deserialization of Untrusted Data vulnerability in wpweb WooCommerce Social Login woo-social-login.This issue affects Wo... |
| CVE-2024-37494 | HIGH | 8.8 | 0.5% | Jul 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in KaineLabs Youzify.... |
| CVE-2024-37486 | HIGH | 7.2 | 0.7% | Jul 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships P... |
| CVE-2024-37256 | HIGH | 7.2 | 0.6% | Jul 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS.... |
| CVE-2024-37225 | HIGH | 8.8 | 0.5% | Jul 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho Marketing Aut... |
| CVE-2024-6321 | HIGH | 8.8 | 0.4% | Jul 9, 2024 | The ScrollTo Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in version... |
| CVE-2024-6320 | HIGH | 8.8 | 0.4% | Jul 9, 2024 | The ScrollTo Top plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions u... |
| CVE-2024-6317 | HIGH | 8.8 | 0.6% | Jul 9, 2024 | The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File... |
| CVE-2024-6316 | HIGH | 8.8 | 0.5% | Jul 9, 2024 | The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File... |
| CVE-2024-6310 | HIGH | 8.8 | 0.5% | Jul 9, 2024 | The Advanced AJAX Page Loader plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload ... |
| CVE-2024-6309 | HIGH | 8.8 | 0.4% | Jul 9, 2024 | The Attachment File Icons (AF Icons) plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File ... |
| CVE-2024-6180 | HIGH | 7.2 | 0.5% | Jul 9, 2024 | The EventON plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on... |
| CVE-2024-6161 | HIGH | 8.8 | 0.8% | Jul 9, 2024 | The Default Thumbnail Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat... |
| CVE-2024-6123 | HIGH | 7.2 | 1.0% | Jul 9, 2024 | The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ic... |
| CVE-2024-28750 | HIGH | 7.2 | 0.8% | Jul 9, 2024 | A remote attacker with high privileges may use a deleting file function to inject OS commands. |
| CVE-2024-28749 | HIGH | 7.2 | 0.8% | Jul 9, 2024 | A remote attacker with high privileges may use a writing file function to inject OS commands. |
| CVE-2024-28748 | HIGH | 7.2 | 0.8% | Jul 9, 2024 | A remote attacker with high privileges may use a reading file function to inject OS commands. |
| CVE-2024-22062 | HIGH | 8.8 | 0.2% | Jul 9, 2024 | There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permis... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now