2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51715 | HIGH | 8.5 | 0.4% | Jan 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickWhale ClickWh... |
| CVE-2024-51700 | HIGH | 7.1 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eutrue NAVER Analy... |
| CVE-2024-49644 | HIGH | 8.8 | 0.4% | Jan 7, 2025 | Incorrect Privilege Assignment vulnerability in AllAccessible Accessibility by AllAccessible allaccessible allows Privil... |
| CVE-2024-49249 | HIGH | 8.6 | 0.5% | Jan 7, 2025 | Path Traversal: '.../...//' vulnerability in SMSA Express SMSA Shipping smsa-shipping-official allows Path Traversal.Thi... |
| CVE-2024-12152 | HIGH | 7.5 | 1.0% | Jan 7, 2025 | The MIPL WC Multisite Sync plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includin... |
| CVE-2024-47398 | HIGH | 8.8 | 0.2% | Jan 7, 2025 | in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the device is unable to boot up through out-of-bou... |
| CVE-2024-12202 | HIGH | 8.8 | 0.5% | Jan 7, 2025 | The Croma Music plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escal... |
| CVE-2024-11627 | HIGH | 8.1 | 0.3% | Jan 7, 2025 | : Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Site... |
| CVE-2024-11725 | HIGH | 8.8 | 0.5% | Jan 7, 2025 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data ... |
| CVE-2024-11282 | HIGH | 7.5 | 0.4% | Jan 7, 2025 | The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure i... |
| CVE-2024-12849 | HIGH | 7.5 | 47.1% | Jan 7, 2025 | The Error Log Viewer By WP Guru plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and inc... |
| CVE-2024-12633 | HIGH | 7.1 | 0.3% | Jan 7, 2025 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Reflected Cross... |
| CVE-2024-12535 | HIGH | 8.6 | 0.6% | Jan 7, 2025 | The Host PHP Info plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check wh... |
| CVE-2024-12471 | HIGH | 8.8 | 1.5% | Jan 7, 2025 | The Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator plugin for WordPress is... |
| CVE-2024-12322 | HIGH | 8.8 | 0.3% | Jan 7, 2025 | The ThePerfectWedding.nl Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, ... |
| CVE-2024-12313 | HIGH | 8.1 | 0.8% | Jan 7, 2025 | The Compare Products for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, a... |
| CVE-2024-12157 | HIGH | 7.5 | 1.0% | Jan 7, 2025 | The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to SQL Injection ... |
| CVE-2024-11465 | HIGH | 7.2 | 1.0% | Jan 7, 2025 | The Custom Product Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to... |
| CVE-2024-12416 | HIGH | 7.5 | 0.4% | Jan 7, 2025 | The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to SQL Injection via the 'woom... |
| CVE-2024-55553 | HIGH | 7.5 | 0.8% | Jan 6, 2025 | In FRRouting (FRR) before 10.3 from 6.0 onward, all routes are re-validated if the total size of an update received via ... |
| CVE-2024-54767 | HIGH | 7.5 | 1.8% | Jan 6, 2025 | An access control issue in the component /juis_boxinfo.xml of AVM FRITZ!Box 7530 AX v7.59 allows attackers to obtain sen... |
| CVE-2024-53934 | HIGH | 7.7 | 0.2% | Jan 6, 2025 | The com.windymob.callscreen.ringtone.callcolor.colorphone (aka Color Phone Call Screen Themes) application through 1.1.2... |
| CVE-2024-48457 | HIGH | 7.5 | 3.0% | Jan 6, 2025 | An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi ... |
| CVE-2024-48456 | HIGH | 7.5 | 17.3% | Jan 6, 2025 | An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi ... |
| CVE-2024-55076 | HIGH | 8.1 | 0.3% | Jan 6, 2025 | Grocy through 4.3.0 has no CSRF protection, as demonstrated by changing the Administrator's password. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now