2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-37268HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in kaptinlin Striking allow...
CVE-2024-37266HIGH7.2Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Tutor LMS allows...
CVE-2024-37090HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Mas...
CVE-2024-6069HIGH8.8The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & C...
CVE-2024-5479HIGH7.2The Easy Pixels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all versions up...
CVE-2024-5456HIGH8.8The Panda Video plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.0 v...
CVE-2024-3604HIGH8.8The OSM – OpenStreetMap plugin for WordPress is vulnerable to SQL Injection via the 'tagged_filter' attribute of the 'os...
CVE-2024-37502HIGH7.5Deserialization of Untrusted Data vulnerability in wpweb WooCommerce Social Login woo-social-login.This issue affects Wo...
CVE-2024-37494HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in KaineLabs Youzify....
CVE-2024-37486HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships P...
CVE-2024-37256HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS....
CVE-2024-37225HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho Marketing Aut...
CVE-2024-6321HIGH8.8The ScrollTo Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in version...
CVE-2024-6320HIGH8.8The ScrollTo Top plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions u...
CVE-2024-6317HIGH8.8The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File...
CVE-2024-6316HIGH8.8The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File...
CVE-2024-6310HIGH8.8The Advanced AJAX Page Loader plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload ...
CVE-2024-6309HIGH8.8The Attachment File Icons (AF Icons) plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File ...
CVE-2024-6180HIGH7.2The EventON plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on...
CVE-2024-6161HIGH8.8The Default Thumbnail Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat...
CVE-2024-6123HIGH7.2The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ic...
CVE-2024-28750HIGH7.2A remote attacker with high privileges may use a deleting file function to inject OS commands.
CVE-2024-28749HIGH7.2A remote attacker with high privileges may use a writing file function to inject OS commands.
CVE-2024-28748HIGH7.2A remote attacker with high privileges may use a reading file function to inject OS commands.
CVE-2024-22062HIGH8.8There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permis...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now