2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11625 | MEDIUM | 5.3 | 0.3% | Jan 7, 2025 | Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affec... |
| CVE-2024-10866 | MEDIUM | 5.3 | 0.3% | Jan 7, 2025 | The Export Import Menus plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch... |
| CVE-2024-9502 | MEDIUM | 5.4 | 0.4% | Jan 7, 2025 | The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for ... |
| CVE-2024-9354 | MEDIUM | 6.1 | 0.4% | Jan 7, 2025 | The Estatik Mortgage Calculator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'color' par... |
| CVE-2024-12781 | MEDIUM | 4.3 | 0.3% | Jan 7, 2025 | The Aurum - WordPress & WooCommerce Shopping Theme theme for WordPress is vulnerable to unauthorized modification of dat... |
| CVE-2024-12624 | MEDIUM | 5.4 | 0.2% | Jan 7, 2025 | The Sina Extension for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sina... |
| CVE-2024-12499 | MEDIUM | 6.4 | 0.2% | Jan 7, 2025 | The WP jQuery DataTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_jdt' shor... |
| CVE-2024-12495 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Bootstrap Blocks for WP Editor v2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gtb-boo... |
| CVE-2024-12437 | MEDIUM | 6.4 | 0.4% | Jan 7, 2025 | The Marketplace Items plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'envato' shortc... |
| CVE-2024-11764 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Solar Wizard Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'solar_wizard' ... |
| CVE-2024-9702 | MEDIUM | 5.4 | 0.3% | Jan 7, 2025 | The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug... |
| CVE-2024-9697 | MEDIUM | 5.3 | 0.4% | Jan 7, 2025 | The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to... |
| CVE-2024-9638 | MEDIUM | 4.8 | 0.4% | Jan 7, 2025 | The Category Posts Widget WordPress plugin before 4.9.18 does not sanitise and escape some of its settings, which could ... |
| CVE-2024-8857 | MEDIUM | 4.8 | 0.3% | Jan 7, 2025 | The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could... |
| CVE-2024-7696 | MEDIUM | 6.3 | 0.2% | Jan 7, 2025 | Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for an authenticated mal... |
| CVE-2024-12464 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Chatroll Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'chatroll' sho... |
| CVE-2024-12440 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Candifly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'candifly' shortcode in ... |
| CVE-2024-12439 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Marketplace Items plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'marketplace' s... |
| CVE-2024-12438 | MEDIUM | 6.1 | 0.4% | Jan 7, 2025 | The WooCommerce Digital Content Delivery (incl. DRM) – FlickRocket plugin for WordPress is vulnerable to Reflected Cross... |
| CVE-2024-12384 | MEDIUM | 6.1 | 0.3% | Jan 7, 2025 | The Binary MLM Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page’ parameter... |
| CVE-2024-12383 | MEDIUM | 6.1 | 0.2% | Jan 7, 2025 | The Binary MLM Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2024-12261 | MEDIUM | 6.1 | 0.4% | Jan 7, 2025 | The SmartEmailing.cz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'se-lists-updated' par... |
| CVE-2024-12073 | MEDIUM | 5.4 | 0.2% | Jan 7, 2025 | The Meteor Slides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slide_url_value' parameter ... |
| CVE-2024-11887 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Geo Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'geotargetlygeoconten... |
| CVE-2024-11756 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The SweepWidget Contests, Giveaways, Photo Contests, Competitions plugin for WordPress is vulnerable to Stored Cross-Sit... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now