2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-37420CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in WPZita Zita Elementor Site Library allows Upload a Web ...
CVE-2024-37419HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Codeless Cowidgets – Ele...
CVE-2024-37418CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects...
CVE-2024-37410HIGH7.2Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-39487HIGH7.1In the Linux kernel, the following vulnerability has been resolved: bonding: Fix out-of-bounds read in bond_option_arp_...
CVE-2024-37268HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in kaptinlin Striking allow...
CVE-2024-37266HIGH7.2Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Tutor LMS allows...
CVE-2024-37253LOW2.7Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in WpDi...
CVE-2024-37224MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in smartypants SP Project &...
CVE-2024-37090HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Mas...
CVE-2024-35777LOW3.5Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Auto...
CVE-2024-6168MEDIUM4.3The Just Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2024-6167MEDIUM4.3The Just Custom Fields plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capab...
CVE-2024-6069HIGH8.8The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & C...
CVE-2024-5993MEDIUM5.4The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2024-5992MEDIUM6.5The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2024-5937MEDIUM6.4The Simple Alert Boxes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Alert shortcod...
CVE-2024-5856MEDIUM4.3The Comment Images Reloaded plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability ...
CVE-2024-5810MEDIUM5.3The WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to unauthorized access...
CVE-2024-5704MEDIUM4.3The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin plugin for WordPress is vulnerable to unauthori...
CVE-2024-5669MEDIUM6.4The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] plugin for WordPress is vulnerable to unauthor...
CVE-2024-5648MEDIUM5.4The LearnDash LMS – Reports plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap...
CVE-2024-5600MEDIUM5.4The SCSS Happy Compiler – Compile SCSS to CSS & Automatic Enqueue plugin for WordPress is vulnerable to Stored Cross-Sit...
CVE-2024-5479HIGH7.2The Easy Pixels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all versions up...
CVE-2024-5457MEDIUM5.4The Panda Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now