2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-52871HIGH7.5In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting.
CVE-2024-52867HIGH8.1guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users b...
CVE-2024-52397CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Davor Zeljkovic Convert Docx2post convert-docx2post all...
CVE-2024-52416CRITICAL10Missing Authorization vulnerability in Eugen Bobrowski Debug Tool debug-tool allows Upload a Web Shell to a Web Server.T...
CVE-2024-52415HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in skipstorm SK WP Settings Backup sk-wp-settings-backup allows Object I...
CVE-2024-52414CRITICAL9.8Deserialization of Untrusted Data vulnerability in Anthony Carbon WDES Responsive Mobile Menu wdes-responsive-mobile-men...
CVE-2024-52413CRITICAL9.8Deserialization of Untrusted Data vulnerability in dmcwebzone Airin Blog airin-blog allows Object Injection.This issue a...
CVE-2024-52412CRITICAL9.8Deserialization of Untrusted Data vulnerability in Stephen Cui Xin allows Object Injection.This issue affects Xin: from ...
CVE-2024-52411CRITICAL9.8Deserialization of Untrusted Data vulnerability in flowcraft Advanced Personalization personalization-by-flowcraft allow...
CVE-2024-52410CRITICAL9.8Deserialization of Untrusted Data vulnerability in Phoenixheart Referrer Detector referrer-detector allows Object Inject...
CVE-2024-52409CRITICAL9.8Deserialization of Untrusted Data vulnerability in Phoenixheart AJAX Random Posts ajax-random-posts allows Object Inject...
CVE-2024-52408CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in pushassist Push Notifications for WordPress by PushAssi...
CVE-2024-52407CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in BasePress BasePress Migration Tools basepress-migration...
CVE-2024-52406CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in wibergsweb CSV to html csv-to-html allows Upload a Web ...
CVE-2024-52405CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in bikramjoshii B-Banner Slider b-banner-slider allows Upl...
CVE-2024-52404CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in bigfiveagency CF7 Reply Manager cf7-reply-manager.This ...
CVE-2024-52403CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Saad Iqbal User Management user-management allows Uploa...
CVE-2024-52400CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Subhasis Laha Gallerio gallerio allows Upload a Web She...
CVE-2024-52399CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Clarisse K. Writer Helper writer-helper allows Upload a...
CVE-2024-52398CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Halyra CDI collect-and-deliver-interface-for-woocommerc...
CVE-2024-52386MEDIUM5.3Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-9887HIGH7.2The Login using WordPress Users ( WP as SAML IDP ) plugin for WordPress is vulnerable to time-based SQL Injection via th...
CVE-2024-11094MEDIUM5.3The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi...
CVE-2024-10592MEDIUM6.4The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup class parameter in a...
CVE-2024-10645HIGH7.5The Blogger 301 Redirect plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘br’ parameter in ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now