2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6123HIGH7.2The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ic...
CVE-2024-5881MEDIUM6.4The Webico Slider Flatsome Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wbc...
CVE-2024-37923MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in cliengo Cliengo – Chatbot cliengo allows Cross Site Request Forgery.T...
CVE-2024-37555CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in ZealousWeb Generate PDF using Contact Form 7 generate-p...
CVE-2024-28751CRITICAL9.1An high privileged remote attacker can enable telnet access that accepts hardcoded credentials.
CVE-2024-28750HIGH7.2A remote attacker with high privileges may use a deleting file function to inject OS commands.
CVE-2024-28749HIGH7.2A remote attacker with high privileges may use a writing file function to inject OS commands.
CVE-2024-28748HIGH7.2A remote attacker with high privileges may use a reading file function to inject OS commands.
CVE-2024-28747CRITICAL9.8An unauthenticated remote attacker can use the hard-coded credentials to access the SmartSPS devices with high privilege...
CVE-2024-22062HIGH8.8There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permis...
CVE-2024-6334MEDIUM6.1The Easy Table of Contents WordPress plugin before 2.0.67.1 does not sanitise and escape some of its settings, which cou...
CVE-2024-5802MEDIUM4.8The URL Shortener by Myhop WordPress plugin through 1.0.17 does not sanitise and escape some of its settings, which coul...
CVE-2024-5488CRITICAL9.8The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with ano...
CVE-2024-5441HIGH8.8The Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat...
CVE-2024-3410MEDIUM4.3The DN Footer Contacts WordPress plugin before 1.6.3 does not sanitise and escape some of its settings, which could allo...
CVE-2024-6171MEDIUM5.3The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to IP Address ...
CVE-2024-6170MEDIUM5.4The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cros...
CVE-2024-6169MEDIUM5.4The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cros...
CVE-2024-6166HIGH8.8The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based ...
CVE-2024-4667MEDIUM5.4The Blog, Posts and Category Filter for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2024-39600MEDIUM4.2Under certain conditions, the memory of SAP GUI for Windows contains the password used to log on to an SAP system, which...
CVE-2024-39599MEDIUM4.7Due to a Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform, a developer can by...
CVE-2024-39596MEDIUM4.3Due to missing authorization checks, SAP Enable Now allows an author to escalate privileges to access information which ...
CVE-2024-39595MEDIUM5.4SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user-controlled input...
CVE-2024-39594MEDIUM6.1SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user controlled input...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now