2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-52451HIGH8.2Cross-Site Request Forgery (CSRF) vulnerability in aaronrobbins Post Ideas post-ideas allows SQL Injection.This issue af...
CVE-2024-52450HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-52449HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Navneil Naicer Bootscrap...
CVE-2024-52448HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in webcodingplace Ultimate ...
CVE-2024-52447HIGH8.6Path Traversal: '.../...//' vulnerability in corporatezen222 Contact Page With Google Map contact-page-with-google-map a...
CVE-2024-52446HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Buying Buddy Buying Buddy IDX CRM buying-buddy-idx-crm allows Object ...
CVE-2024-52445HIGH8.8Deserialization of Untrusted Data vulnerability in ModelTheme QRMenu Restaurant QR Menu Lite qrmenu-lite allows Object I...
CVE-2024-52444HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpopal Opal Woo Custom P...
CVE-2024-52443CRITICAL9.8Deserialization of Untrusted Data vulnerability in masikonis Geolocator geolocator allows Object Injection.This issue af...
CVE-2024-52442CRITICAL9.8Incorrect Privilege Assignment vulnerability in userplus UserPlus userplus allows Privilege Escalation.This issue affect...
CVE-2024-52441CRITICAL9.8Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Rajesh Thanoc...
CVE-2024-52440CRITICAL9.8Deserialization of Untrusted Data vulnerability in xpresslane Xpresslane Fast Checkout xpresslane-integration-for-woocom...
CVE-2024-52439CRITICAL9.8Deserialization of Untrusted Data vulnerability in Mark O'Donnell Team Rosters team-rosters allows Object Injection.This...
CVE-2024-52438HIGH8.8Missing Authentication for Critical Function vulnerability in deco.agency de:branding debranding allows Privilege Escala...
CVE-2024-52437HIGH8.8Missing Authentication for Critical Function vulnerability in Saul Morales Pacheco Banner System banner-system allows Pr...
CVE-2024-11406MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS ...
CVE-2024-11404MEDIUM5.5Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Script-Related HTML Tags in a Web Page (Basi...
CVE-2024-10520MEDIUM5.3The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili...
CVE-2024-48899MEDIUM4.3A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course ba...
CVE-2024-45691MEDIUM5.4A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be byp...
CVE-2024-45690HIGH7.5A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts...
CVE-2024-45689MEDIUM6.5A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability...
CVE-2024-10872MEDIUM5.4The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `template-post-c...
CVE-2024-10382HIGH7.5There exists a code execution vulnerability in the Car App Android Jetpack Library. CarAppService uses deserialization l...
CVE-2024-11494HIGH7.5**UNSUPPORTED WHEN ASSIGNED** The improper authentication vulnerability in the Zyxel P-6101C ADSL modem firmware version...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now