2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13910 | HIGH | 7.2 | 0.9% | Mar 1, 2025 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to arbitrary file ... |
| CVE-2024-13697 | MEDIUM | 6.5 | 0.3% | Mar 1, 2025 | The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vu... |
| CVE-2024-13611 | HIGH | 7.5 | 0.5% | Mar 1, 2025 | The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vu... |
| CVE-2024-13911 | HIGH | 7.2 | 0.5% | Mar 1, 2025 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Sensitive Infor... |
| CVE-2024-13806 | MEDIUM | 6.5 | 0.3% | Mar 1, 2025 | The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and incl... |
| CVE-2024-12544 | HIGH | 8.8 | 0.7% | Mar 1, 2025 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for ... |
| CVE-2024-13373 | HIGH | 8.1 | 0.4% | Mar 1, 2025 | The Exertio Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up... |
| CVE-2024-12824 | CRITICAL | 9.8 | 2.2% | Mar 1, 2025 | The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in ... |
| CVE-2024-13901 | MEDIUM | 4.8 | 0.3% | Mar 1, 2025 | The Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site plugin for WordPress is vulnerable to... |
| CVE-2024-9217 | MEDIUM | 6.1 | 0.3% | Mar 1, 2025 | The Currency Switcher for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the us... |
| CVE-2024-9212 | MEDIUM | 6.1 | 0.3% | Mar 1, 2025 | The SKU Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of... |
| CVE-2024-13750 | MEDIUM | 6.5 | 0.4% | Mar 1, 2025 | The Multilevel Referral Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'or... |
| CVE-2024-13746 | MEDIUM | 6.5 | 0.3% | Mar 1, 2025 | The Booking Calendar and Notification plugin for WordPress is vulnerable to unauthorized access, modification, and loss ... |
| CVE-2024-13568 | HIGH | 7.5 | 0.4% | Mar 1, 2025 | The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Sensitive Informati... |
| CVE-2024-13559 | MEDIUM | 6.4 | 0.2% | Mar 1, 2025 | The TemplatesNext ToolKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tx_woo_wis... |
| CVE-2024-13518 | MEDIUM | 4.3 | 0.2% | Mar 1, 2025 | The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2024-13358 | MEDIUM | 4.3 | 0.2% | Mar 1, 2025 | The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to... |
| CVE-2024-1509 | CRITICAL | 9.1 | 0.3% | Feb 28, 2025 | Brocade ASCG before 3.2.0 Web Interface is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional response h... |
| CVE-2024-54175 | MEDIUM | 5.5 | 0.1% | Feb 28, 2025 | IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow a local user to cause a denial of service due to an improper c... |
| CVE-2024-44754 | MEDIUM | 6.8 | 0.2% | Feb 28, 2025 | Cryptographic key extraction from internal flash in Minut M2 with firmware version #15142 allows physically proximate at... |
| CVE-2024-10860 | MEDIUM | 4.3 | 0.2% | Feb 28, 2025 | The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized submission of data... |
| CVE-2024-9195 | HIGH | 8.8 | 0.4% | Feb 28, 2025 | The WHMPress - WHMCS Client Area plugin for WordPress is vulnerable to unauthorized modification of data that can lead t... |
| CVE-2024-9193 | CRITICAL | 9.8 | 3.1% | Feb 28, 2025 | The WHMpress - WHMCS WordPress Integration Plugin plugin for WordPress is vulnerable to Local File Inclusion in all vers... |
| CVE-2024-9019 | MEDIUM | 5.4 | 0.2% | Feb 28, 2025 | The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2024-8425 | CRITICAL | 9.8 | 3.9% | Feb 28, 2025 | The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now