2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-51715HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickWhale ClickWh...
CVE-2024-51700HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eutrue NAVER Analy...
CVE-2024-49644HIGH8.8Incorrect Privilege Assignment vulnerability in AllAccessible Accessibility by AllAccessible allaccessible allows Privil...
CVE-2024-49249HIGH8.6Path Traversal: '.../...//' vulnerability in SMSA Express SMSA Shipping smsa-shipping-official allows Path Traversal.Thi...
CVE-2024-12152HIGH7.5The MIPL WC Multisite Sync plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includin...
CVE-2024-47398HIGH8.8in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the device is unable to boot up through out-of-bou...
CVE-2024-12202HIGH8.8The Croma Music plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escal...
CVE-2024-11627HIGH8.1: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Site...
CVE-2024-11725HIGH8.8The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data ...
CVE-2024-11282HIGH7.5The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure i...
CVE-2024-12849HIGH7.5The Error Log Viewer By WP Guru plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and inc...
CVE-2024-12633HIGH7.1The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Reflected Cross...
CVE-2024-12535HIGH8.6The Host PHP Info plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check wh...
CVE-2024-12471HIGH8.8The Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator plugin for WordPress is...
CVE-2024-12322HIGH8.8The ThePerfectWedding.nl Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, ...
CVE-2024-12313HIGH8.1The Compare Products for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, a...
CVE-2024-12157HIGH7.5The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to SQL Injection ...
CVE-2024-11465HIGH7.2The Custom Product Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to...
CVE-2024-12416HIGH7.5The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to SQL Injection via the 'woom...
CVE-2024-55553HIGH7.5In FRRouting (FRR) before 10.3 from 6.0 onward, all routes are re-validated if the total size of an update received via ...
CVE-2024-54767HIGH7.5An access control issue in the component /juis_boxinfo.xml of AVM FRITZ!Box 7530 AX v7.59 allows attackers to obtain sen...
CVE-2024-53934HIGH7.7The com.windymob.callscreen.ringtone.callcolor.colorphone (aka Color Phone Call Screen Themes) application through 1.1.2...
CVE-2024-48457HIGH7.5An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi ...
CVE-2024-48456HIGH7.5An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi ...
CVE-2024-55076HIGH8.1Grocy through 4.3.0 has no CSRF protection, as demonstrated by changing the Administrator's password.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now