2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13910HIGH7.2The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to arbitrary file ...
CVE-2024-13697MEDIUM6.5The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vu...
CVE-2024-13611HIGH7.5The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vu...
CVE-2024-13911HIGH7.2The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Sensitive Infor...
CVE-2024-13806MEDIUM6.5The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and incl...
CVE-2024-12544HIGH8.8The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for ...
CVE-2024-13373HIGH8.1The Exertio Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up...
CVE-2024-12824CRITICAL9.8The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in ...
CVE-2024-13901MEDIUM4.8The Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site plugin for WordPress is vulnerable to...
CVE-2024-9217MEDIUM6.1The Currency Switcher for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the us...
CVE-2024-9212MEDIUM6.1The SKU Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of...
CVE-2024-13750MEDIUM6.5The Multilevel Referral Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'or...
CVE-2024-13746MEDIUM6.5The Booking Calendar and Notification plugin for WordPress is vulnerable to unauthorized access, modification, and loss ...
CVE-2024-13568HIGH7.5The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Sensitive Informati...
CVE-2024-13559MEDIUM6.4The TemplatesNext ToolKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tx_woo_wis...
CVE-2024-13518MEDIUM4.3The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2024-13358MEDIUM4.3The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to...
CVE-2024-1509CRITICAL9.1Brocade ASCG before 3.2.0 Web Interface is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional response h...
CVE-2024-54175MEDIUM5.5IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow a local user to cause a denial of service due to an improper c...
CVE-2024-44754MEDIUM6.8Cryptographic key extraction from internal flash in Minut M2 with firmware version #15142 allows physically proximate at...
CVE-2024-10860MEDIUM4.3The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized submission of data...
CVE-2024-9195HIGH8.8The WHMPress - WHMCS Client Area plugin for WordPress is vulnerable to unauthorized modification of data that can lead t...
CVE-2024-9193CRITICAL9.8The WHMpress - WHMCS WordPress Integration Plugin plugin for WordPress is vulnerable to Local File Inclusion in all vers...
CVE-2024-9019MEDIUM5.4The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2024-8425CRITICAL9.8The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now