2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52871 | HIGH | 7.5 | 0.4% | Nov 17, 2024 | In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting. |
| CVE-2024-52867 | HIGH | 8.1 | 0.2% | Nov 17, 2024 | guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users b... |
| CVE-2024-52397 | CRITICAL | 9.1 | 0.5% | Nov 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Davor Zeljkovic Convert Docx2post convert-docx2post all... |
| CVE-2024-52416 | CRITICAL | 10 | 0.4% | Nov 16, 2024 | Missing Authorization vulnerability in Eugen Bobrowski Debug Tool debug-tool allows Upload a Web Shell to a Web Server.T... |
| CVE-2024-52415 | HIGH | 8.8 | 0.2% | Nov 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in skipstorm SK WP Settings Backup sk-wp-settings-backup allows Object I... |
| CVE-2024-52414 | CRITICAL | 9.8 | 0.5% | Nov 16, 2024 | Deserialization of Untrusted Data vulnerability in Anthony Carbon WDES Responsive Mobile Menu wdes-responsive-mobile-men... |
| CVE-2024-52413 | CRITICAL | 9.8 | 0.7% | Nov 16, 2024 | Deserialization of Untrusted Data vulnerability in dmcwebzone Airin Blog airin-blog allows Object Injection.This issue a... |
| CVE-2024-52412 | CRITICAL | 9.8 | 0.5% | Nov 16, 2024 | Deserialization of Untrusted Data vulnerability in Stephen Cui Xin allows Object Injection.This issue affects Xin: from ... |
| CVE-2024-52411 | CRITICAL | 9.8 | 0.5% | Nov 16, 2024 | Deserialization of Untrusted Data vulnerability in flowcraft Advanced Personalization personalization-by-flowcraft allow... |
| CVE-2024-52410 | CRITICAL | 9.8 | 0.5% | Nov 16, 2024 | Deserialization of Untrusted Data vulnerability in Phoenixheart Referrer Detector referrer-detector allows Object Inject... |
| CVE-2024-52409 | CRITICAL | 9.8 | 0.5% | Nov 16, 2024 | Deserialization of Untrusted Data vulnerability in Phoenixheart AJAX Random Posts ajax-random-posts allows Object Inject... |
| CVE-2024-52408 | CRITICAL | 9.9 | 0.5% | Nov 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in pushassist Push Notifications for WordPress by PushAssi... |
| CVE-2024-52407 | CRITICAL | 9.9 | 0.5% | Nov 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in BasePress BasePress Migration Tools basepress-migration... |
| CVE-2024-52406 | CRITICAL | 9.9 | 0.5% | Nov 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in wibergsweb CSV to html csv-to-html allows Upload a Web ... |
| CVE-2024-52405 | CRITICAL | 9.9 | 0.5% | Nov 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in bikramjoshii B-Banner Slider b-banner-slider allows Upl... |
| CVE-2024-52404 | CRITICAL | 9.9 | 0.5% | Nov 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in bigfiveagency CF7 Reply Manager cf7-reply-manager.This ... |
| CVE-2024-52403 | CRITICAL | 9.9 | 0.5% | Nov 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Saad Iqbal User Management user-management allows Uploa... |
| CVE-2024-52400 | CRITICAL | 9.9 | 0.5% | Nov 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Subhasis Laha Gallerio gallerio allows Upload a Web She... |
| CVE-2024-52399 | CRITICAL | 9.9 | 0.5% | Nov 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Clarisse K. Writer Helper writer-helper allows Upload a... |
| CVE-2024-52398 | CRITICAL | 9.1 | 0.5% | Nov 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Halyra CDI collect-and-deliver-interface-for-woocommerc... |
| CVE-2024-52386 | MEDIUM | 5.3 | 0.5% | Nov 16, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-9887 | HIGH | 7.2 | 0.5% | Nov 16, 2024 | The Login using WordPress Users ( WP as SAML IDP ) plugin for WordPress is vulnerable to time-based SQL Injection via th... |
| CVE-2024-11094 | MEDIUM | 5.3 | 0.4% | Nov 16, 2024 | The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi... |
| CVE-2024-10592 | MEDIUM | 6.4 | 0.8% | Nov 16, 2024 | The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup class parameter in a... |
| CVE-2024-10645 | HIGH | 7.5 | 0.5% | Nov 16, 2024 | The Blogger 301 Redirect plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘br’ parameter in ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now