2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-11625MEDIUM5.3Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affec...
CVE-2024-10866MEDIUM5.3The Export Import Menus plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch...
CVE-2024-9502MEDIUM5.4The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for ...
CVE-2024-9354MEDIUM6.1The Estatik Mortgage Calculator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'color' par...
CVE-2024-12781MEDIUM4.3The Aurum - WordPress & WooCommerce Shopping Theme theme for WordPress is vulnerable to unauthorized modification of dat...
CVE-2024-12624MEDIUM5.4The Sina Extension for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sina...
CVE-2024-12499MEDIUM6.4The WP jQuery DataTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_jdt' shor...
CVE-2024-12495MEDIUM6.4The Bootstrap Blocks for WP Editor v2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gtb-boo...
CVE-2024-12437MEDIUM6.4The Marketplace Items plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'envato' shortc...
CVE-2024-11764MEDIUM6.4The Solar Wizard Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'solar_wizard' ...
CVE-2024-9702MEDIUM5.4The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2024-9697MEDIUM5.3The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to...
CVE-2024-9638MEDIUM4.8The Category Posts Widget WordPress plugin before 4.9.18 does not sanitise and escape some of its settings, which could ...
CVE-2024-8857MEDIUM4.8The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could...
CVE-2024-7696MEDIUM6.3Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for an authenticated mal...
CVE-2024-12464MEDIUM6.4The Chatroll Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'chatroll' sho...
CVE-2024-12440MEDIUM6.4The Candifly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'candifly' shortcode in ...
CVE-2024-12439MEDIUM6.4The Marketplace Items plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'marketplace' s...
CVE-2024-12438MEDIUM6.1The WooCommerce Digital Content Delivery (incl. DRM) – FlickRocket plugin for WordPress is vulnerable to Reflected Cross...
CVE-2024-12384MEDIUM6.1The Binary MLM Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page’ parameter...
CVE-2024-12383MEDIUM6.1The Binary MLM Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2024-12261MEDIUM6.1The SmartEmailing.cz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'se-lists-updated' par...
CVE-2024-12073MEDIUM5.4The Meteor Slides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slide_url_value' parameter ...
CVE-2024-11887MEDIUM6.4The Geo Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'geotargetlygeoconten...
CVE-2024-11756MEDIUM6.4The SweepWidget Contests, Giveaways, Photo Contests, Competitions plugin for WordPress is vulnerable to Stored Cross-Sit...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now