2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13771MEDIUM5.9The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass...
CVE-2024-12810HIGH8.1The JobCareer | Job Board Responsive WordPress Theme theme for WordPress is vulnerable to unauthorized access, modificat...
CVE-2024-26006MEDIUM6.1An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below...
CVE-2024-8176HIGH7.5A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XM...
CVE-2024-13407MEDIUM6.5The Omnipress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.4 via...
CVE-2024-13321CRITICAL9.8The AnalyticsWP plugin for WordPress is vulnerable to SQL Injection via the 'custom_sql' parameter in all versions up to...
CVE-2024-13824CRITICAL9.8The CiyaShop - Multipurpose WooCommerce Theme theme for WordPress is vulnerable to PHP Object Injection in all versions ...
CVE-2024-13913HIGH8.8The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2024-13376HIGH8.8The Industrial theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalat...
CVE-2024-11286CRITICAL9.8The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. Th...
CVE-2024-11285CRITICAL9.8The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an...
CVE-2024-11284CRITICAL9.8The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an...
CVE-2024-11283HIGH7.5The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. Th...
CVE-2024-55549HIGH7.8xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exclusion of result prefixes.
CVE-2024-55060MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component index.php of Rafed CMS Website v1.44 allows attackers to exe...
CVE-2024-30143MEDIUM4.3HCL AppScan Traffic Recorder fails to adequately neutralize special characters within the filename, potentially allowing...
CVE-2024-9042MEDIUM5.9This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the aff...
CVE-2024-53406HIGH8.8Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection p...
CVE-2024-12858——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. *** Duplicate of CVE-2025-2...
CVE-2024-57062MEDIUM6.7An issue in SoundCloud IOS application v.7.65.2 allows a local attacker to escalate privileges and obtain sensitive info...
CVE-2024-55198MEDIUM5.3User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery funct...
CVE-2024-57348MEDIUM6.1Cross Site Scripting vulnerability in PecanProject pecan through v.1.8.0 allows a remote attacker to execute arbitrary c...
CVE-2024-28803MEDIUM6.1Cross-site scripting (XSS) vulnerability in Italtel S.p.A. i-MCS NFV v.12.1.0-20211215 allows unauthenticated remote att...
CVE-2024-22880MEDIUM4.7Cross Site Scripting vulnerability in Zadarma Zadarma extension v.1.0.11 allows a remote attacker to execute a arbitrary...
CVE-2024-10942HIGH7.5The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to,...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now