2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11962 | CRITICAL | 9.8 | 0.9% | Nov 28, 2024 | A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. Affected by this vulnera... |
| CVE-2024-11961 | HIGH | 7.5 | 0.9% | Nov 28, 2024 | A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms 3.7. It has been rated as problematic. This i... |
| CVE-2024-11960 | HIGH | 8.8 | 1.7% | Nov 28, 2024 | A vulnerability was found in D-Link DIR-605L 2.13B01. It has been declared as critical. This vulnerability affects the f... |
| CVE-2024-11959 | HIGH | 8.8 | 1.7% | Nov 28, 2024 | A vulnerability was found in D-Link DIR-605L 2.13B01. It has been classified as critical. This affects the function form... |
| CVE-2024-7747 | MEDIUM | 6.5 | 0.5% | Nov 28, 2024 | The Wallet for WooCommerce plugin for WordPress is vulnerable to incorrect conversion between numeric types in all versi... |
| CVE-2024-53731 | MEDIUM | 6.5 | 0.3% | Nov 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fintelligence Fint... |
| CVE-2024-8308 | MEDIUM | 6.5 | 0.6% | Nov 28, 2024 | A low privileged remote attacker can insert a SQL injection in the web application due to improper handling of HTTP requ... |
| CVE-2024-53737 | MEDIUM | 5.4 | 0.3% | Nov 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mails... |
| CVE-2024-53736 | HIGH | 7.1 | 0.2% | Nov 28, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Jason Grim Custom Shortcode Sidebars custom-shortcode-sidebars allows... |
| CVE-2024-53734 | HIGH | 7.1 | 0.2% | Nov 28, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Jamie O Idealien Category Enhancements idealien-category-enhancements... |
| CVE-2024-53733 | HIGH | 7.1 | 0.3% | Nov 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in harshtohit111 Fenc... |
| CVE-2024-53732 | HIGH | 7.1 | 0.2% | Nov 28, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in wpwox Footer Flyout Widget footer-flyout-widget allows Stored XSS.Thi... |
| CVE-2024-52501 | HIGH | 7.5 | 0.7% | Nov 28, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-52499 | HIGH | 7.5 | 0.7% | Nov 28, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-52498 | HIGH | 7.5 | 0.6% | Nov 28, 2024 | Path Traversal: '.../...//' vulnerability in softpulseinfotech SP Blog Designer sp-blog-designer allows PHP Local File I... |
| CVE-2024-52497 | HIGH | 7.5 | 0.7% | Nov 28, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-52496 | HIGH | 7.5 | 0.7% | Nov 28, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-52495 | HIGH | 8.5 | 0.4% | Nov 28, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology ... |
| CVE-2024-52490 | CRITICAL | 10 | 0.6% | Nov 28, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in pathomation Pathomation pathomation allows Upload a Web... |
| CVE-2024-52481 | HIGH | 7.5 | 0.7% | Nov 28, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Astoundify Jobify jobify... |
| CVE-2024-52475 | CRITICAL | 9.8 | 1.8% | Nov 28, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Information Technology Wawp automation-web-pla... |
| CVE-2024-52474 | CRITICAL | 9.3 | 0.5% | Nov 28, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Сервис “Экспресс П... |
| CVE-2024-11620 | HIGH | 7.2 | 0.7% | Nov 28, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math ... |
| CVE-2024-11402 | HIGH | 7.1 | 0.3% | Nov 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kubiq Block Editor... |
| CVE-2024-8672 | CRITICAL | 9.9 | 43.8% | Nov 28, 2024 | The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Remote Code Ex... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now