2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-45847HIGH8.8An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one ...
CVE-2024-45846HIGH8.8An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the ...
CVE-2024-3306HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in Utarit Information SoliClub allows Exploiting Incorrec...
CVE-2024-3305HIGH7.5Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Utarit Information SoliClub all...
CVE-2024-27321HIGH7.8An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of ...
CVE-2024-27320HIGH7.8An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of ...
CVE-2024-8750MEDIUM6.1Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve sess...
CVE-2024-8749HIGH7.5SQL injection vulnerability in idoit pro version 28. This vulnerability could allow an attacker to send a specially craf...
CVE-2024-8622MEDIUM6.1The amCharts: Charts and Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'amcharts_jav...
CVE-2024-8529HIGH7.5The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter o...
CVE-2024-8522HIGH7.5The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parame...
CVE-2024-2010MEDIUM6.1Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in TE Informatics V5 allows ...
CVE-2024-8056MEDIUM6.1The MM-Breaking News WordPress plugin through 0.7.9 does not escape the $_SERVER['REQUEST_URI'] parameter before outputt...
CVE-2024-8054MEDIUM6.1The MM-Breaking News WordPress plugin through 0.7.9 does not have CSRF check in some places, and is missing sanitisation...
CVE-2024-7862MEDIUM6.5The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in place when updating its...
CVE-2024-7861MEDIUM6.1The Misiek Paypal WordPress plugin through 1.1.20090324 does not have CSRF check in some places, and is missing sanitisa...
CVE-2024-7860MEDIUM6.1The Simple Headline Rotator WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitis...
CVE-2024-7859MEDIUM6.5The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could...
CVE-2024-7822MEDIUM6.1The Quick Code WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well...
CVE-2024-7820MEDIUM6.5The ILC Thickbox WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could ...
CVE-2024-7818MEDIUM6.1The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF check in some places, and is missing sanitisati...
CVE-2024-7817MEDIUM6.5The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places, which could allow attack...
CVE-2024-7816MEDIUM6.1The Gixaw Chat WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well...
CVE-2024-7766HIGH7.2The Adicon Server WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL stateme...
CVE-2024-6887MEDIUM4.8The Giveaways and Contests by RafflePress WordPress plugin before 1.12.16 does not sanitise and escape some of its Give...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now