2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-3523HIGH8.8A vulnerability classified as critical was found in Campcodes Online Event Management System 1.0. This vulnerability aff...
CVE-2024-3522HIGH8.8A vulnerability classified as critical has been found in Campcodes Online Event Management System 1.0. This affects an u...
CVE-2024-3313HIGH8.6SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Server 2021 and Subs...
CVE-2024-3446HIGH8.2A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the m...
CVE-2024-3213HIGH8.2The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missin...
CVE-2024-2871HIGH7.7The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all ver...
CVE-2024-2693HIGH8.8The Link Whisper Free plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0...
CVE-2024-2501HIGH7.5The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to PHP Object Injection in al...
CVE-2024-2344HIGH7.2The Avada theme for WordPress is vulnerable to SQL Injection via the 'entry' parameter in all versions up to, and includ...
CVE-2024-2342HIGH8.8The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL...
CVE-2024-2125HIGH8.8The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
CVE-2024-2112HIGH7.5The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensiti...
CVE-2024-2018HIGH8.8The WP Activity Log Premium plugin for WordPress is vulnerable to SQL Injection via the entry->roles parameter in all ve...
CVE-2024-24245HIGH7.8An issue in Canimaan Software LTD ClamXAV v3.1.2 through v3.6.1 and fixed in v.3.6.2 allows a local attacker to escalate...
CVE-2024-1991HIGH8.8The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu...
CVE-2024-1990HIGH8.8The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu...
CVE-2024-1934HIGH7.5The WP Compress – Image Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2024-1893HIGH8.8The Easy Property Listings plugin for WordPress is vulnerable to time-based SQL Injection via the ‘property_status’ shor...
CVE-2024-1812HIGH7.2The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including...
CVE-2024-1792HIGH7.5The CMB2 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.10.1 via des...
CVE-2024-1774HIGH7.2The Customily Product Personalizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user cookies in...
CVE-2024-1315HIGH8.8The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Cross-Site Req...
CVE-2024-1308HIGH7.5The WooCommerce Cloak Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a m...
CVE-2024-0952HIGH7.2The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is...
CVE-2024-31507HIGH8.6Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the "request" parameter in admin/fe...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now