2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-49605MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in Stefan Nour AVChat Video Chat avchat-3 allows Stored XSS.This issue a...
CVE-2024-49335MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in sh4d0w28 GoogleDrive folder list googledrive-folder-list allows Store...
CVE-2024-47325HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle MPG mult...
CVE-2024-44061MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory EU/UK VA...
CVE-2024-49625CRITICAL9.8Deserialization of Untrusted Data vulnerability in sphoid SiteBuilder Dynamic Components sitebuilder-dynamic-components ...
CVE-2024-49624CRITICAL9.8Deserialization of Untrusted Data vulnerability in smartdevth Advanced Advertising System advanced-advertising-system al...
CVE-2024-49623HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hasan movahed Dupl...
CVE-2024-49622HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in aatmaadhikari Apa Banner Slider apa-banner-slider allows SQL Injectio...
CVE-2024-49621HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in aatmaadhikari APA Register Newsletter Form apa-register-newsletter-fo...
CVE-2024-49610CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in photokiteditor photokit photokit allows Upload a Web Sh...
CVE-2024-49608HIGH8.8Incorrect Privilege Assignment vulnerability in gerryworks GERRYWORKS Post by Mail gerryworks-post-by-mail allows Privil...
CVE-2024-49607CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in redhopit WP Dropbox Dropins wp-dropbox-dropins allows U...
CVE-2024-49332CRITICAL9.8Deserialization of Untrusted Data vulnerability in giveawayboost Giveaway Boost giveaway-boost allows Object Injection.T...
CVE-2024-49331HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Property Lot Management System plms al...
CVE-2024-49330CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in brx8r Nice Backgrounds nicebackgrounds allows Upload a ...
CVE-2024-49329CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns allows Uplo...
CVE-2024-49327CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in bepitulaz Woostagram Connect woostagram-connect allows ...
CVE-2024-49326CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Vasileios Kerasiotis Affiliator affiliator-lite allows ...
CVE-2024-49324CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in sovratecdev Sovratec Case Management sovratec-case-mana...
CVE-2024-10195CRITICAL9.8A vulnerability was found in Tecno 4G Portable WiFi TR118 V008-20220830. It has been declared as critical. Affected by t...
CVE-2024-49631MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Md Abdul Kader Eas...
CVE-2024-49630MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DevItems WP Educat...
CVE-2024-49626CRITICAL9.8Deserialization of Untrusted Data vulnerability in Piyush Patel Shipyaari Shipping Management shipyaari-shipping-managme...
CVE-2024-49611CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in paxmanpwnz Product Website Showcase product-websites-sh...
CVE-2024-49606MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DotsquaresLtd Goog...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now