2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37420 | CRITICAL | 9.9 | 0.5% | Jul 9, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in WPZita Zita Elementor Site Library allows Upload a Web ... |
| CVE-2024-37419 | HIGH | 8.8 | 0.6% | Jul 9, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Codeless Cowidgets – Ele... |
| CVE-2024-37418 | CRITICAL | 9.9 | 0.5% | Jul 9, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects... |
| CVE-2024-37410 | HIGH | 7.2 | 0.6% | Jul 9, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-39487 | HIGH | 7.1 | 0.2% | Jul 9, 2024 | In the Linux kernel, the following vulnerability has been resolved: bonding: Fix out-of-bounds read in bond_option_arp_... |
| CVE-2024-37268 | HIGH | 8.8 | 0.5% | Jul 9, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in kaptinlin Striking allow... |
| CVE-2024-37266 | HIGH | 7.2 | 0.6% | Jul 9, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Tutor LMS allows... |
| CVE-2024-37253 | LOW | 2.7 | 0.3% | Jul 9, 2024 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in WpDi... |
| CVE-2024-37224 | MEDIUM | 6.5 | 0.6% | Jul 9, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in smartypants SP Project &... |
| CVE-2024-37090 | HIGH | 8.8 | 0.5% | Jul 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Mas... |
| CVE-2024-35777 | LOW | 3.5 | 0.4% | Jul 9, 2024 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Auto... |
| CVE-2024-6168 | MEDIUM | 4.3 | 0.2% | Jul 9, 2024 | The Just Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2024-6167 | MEDIUM | 4.3 | 0.3% | Jul 9, 2024 | The Just Custom Fields plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capab... |
| CVE-2024-6069 | HIGH | 8.8 | 0.6% | Jul 9, 2024 | The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & C... |
| CVE-2024-5993 | MEDIUM | 5.4 | 0.5% | Jul 9, 2024 | The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit... |
| CVE-2024-5992 | MEDIUM | 6.5 | 0.5% | Jul 9, 2024 | The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit... |
| CVE-2024-5937 | MEDIUM | 6.4 | 0.3% | Jul 9, 2024 | The Simple Alert Boxes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Alert shortcod... |
| CVE-2024-5856 | MEDIUM | 4.3 | 0.4% | Jul 9, 2024 | The Comment Images Reloaded plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability ... |
| CVE-2024-5810 | MEDIUM | 5.3 | 0.4% | Jul 9, 2024 | The WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to unauthorized access... |
| CVE-2024-5704 | MEDIUM | 4.3 | 0.4% | Jul 9, 2024 | The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin plugin for WordPress is vulnerable to unauthori... |
| CVE-2024-5669 | MEDIUM | 6.4 | 0.4% | Jul 9, 2024 | The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] plugin for WordPress is vulnerable to unauthor... |
| CVE-2024-5648 | MEDIUM | 5.4 | 0.5% | Jul 9, 2024 | The LearnDash LMS – Reports plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap... |
| CVE-2024-5600 | MEDIUM | 5.4 | 0.3% | Jul 9, 2024 | The SCSS Happy Compiler – Compile SCSS to CSS & Automatic Enqueue plugin for WordPress is vulnerable to Stored Cross-Sit... |
| CVE-2024-5479 | HIGH | 7.2 | 0.4% | Jul 9, 2024 | The Easy Pixels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all versions up... |
| CVE-2024-5457 | MEDIUM | 5.4 | 0.4% | Jul 9, 2024 | The Panda Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now