2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-49322CRITICAL9.8Incorrect Privilege Assignment vulnerability in CodePassenger Job Board Manager for WordPress jemployee allows Privilege...
CVE-2024-49318CRITICAL9.8Deserialization of Untrusted Data vulnerability in Scott My Reading Library my-reading-library allows Object Injection.T...
CVE-2024-49314CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in jiangqie JiangQie Free Mini Program jiangqie-free-mini-...
CVE-2024-49305CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Email Ve...
CVE-2024-49291CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Gora Tech LLC Cooked Pro.This issue affects Cooked Pro:...
CVE-2024-49246CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in anand23 Ajax Ratin...
CVE-2024-49217CRITICAL9.8Incorrect Privilege Assignment vulnerability in madiriaashish Adding drop down roles in registration user-drop-down-role...
CVE-2024-49397CRITICAL9.2The affected product is vulnerable to a cross-site scripting attack which may allow an attacker to bypass authentication...
CVE-2024-48920CRITICAL9.1PutongOJ is online judging software. Prior to version 2.1.0-beta.1, unprivileged users can escalate privileges by constr...
CVE-2024-10025CRITICAL9.1A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By e...
CVE-2024-9263CRITICAL9.8The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable...
CVE-2024-9863CRITICAL9.8The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation in versions up ...
CVE-2024-9862CRITICAL9.8The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in ve...
CVE-2024-48180CRITICAL9.8ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uplo...
CVE-2024-9893CRITICAL9.8The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and incl...
CVE-2024-49260CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Limbcode WordPress Gallery Plugin – Limb Image Gallery ...
CVE-2024-49254CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in sunjianle ajax-extend ajax-extend allows Code...
CVE-2024-49242CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Shafiq Digital Lottery digital-lottery allows Upload a ...
CVE-2024-49227CRITICAL9.8Deserialization of Untrusted Data vulnerability in foter Free Stock Photos Foter free-stock-photos-foter allows Object I...
CVE-2024-49218CRITICAL9.8Deserialization of Untrusted Data vulnerability in Al Imran Akash Recently recently-viewed-most-viewed-and-sold-products...
CVE-2024-49216CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in jclay06 Feed Comments Number feed-comments-number allow...
CVE-2024-48035CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in takayukii ACF Images Search And Insert acf-images-searc...
CVE-2024-48034CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in fliperrr Creates 3D Flipbook, PDF Flipbook create-flipb...
CVE-2024-48030CRITICAL9.8Deserialization of Untrusted Data vulnerability in Webextends Telecash Ricaricaweb telecash-ricaricaweb allows Object In...
CVE-2024-48028CRITICAL9.8Deserialization of Untrusted Data vulnerability in Boyan Raichev IP Loc8 ip-loc8 allows Object Injection.This issue affe...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now