2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12214 | MEDIUM | 6.1 | 0.3% | Jan 7, 2025 | The WooCommerce HSS Extension for Streaming Video plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v... |
| CVE-2024-12207 | MEDIUM | 4.4 | 0.3% | Jan 7, 2025 | The Toggles Shortcode and Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ par... |
| CVE-2024-12176 | MEDIUM | 5.3 | 0.3% | Jan 7, 2025 | The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to unauthorized access due to a missing capabi... |
| CVE-2024-12170 | MEDIUM | 5.4 | 0.2% | Jan 7, 2025 | The ViewMedica 9 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2024-12159 | MEDIUM | 5.3 | 0.4% | Jan 7, 2025 | The Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords plugin for WordPress is vulnerable to Inform... |
| CVE-2024-12158 | MEDIUM | 5.3 | 0.3% | Jan 7, 2025 | The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to unauthorized l... |
| CVE-2024-12153 | MEDIUM | 6.1 | 0.4% | Jan 7, 2025 | The GDY Modular Content plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query... |
| CVE-2024-12140 | MEDIUM | 4.3 | 0.4% | Jan 7, 2025 | The Elementor Addons AI Addons – 70 Widgets, Premium Templates, Ultimate Elements plugin for WordPress is vulnerable to ... |
| CVE-2024-12126 | MEDIUM | 6.1 | 0.3% | Jan 7, 2025 | The SEO Keywords plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘google_error’ parameter i... |
| CVE-2024-12049 | MEDIUM | 6.1 | 0.4% | Jan 7, 2025 | The Woo Ukrposhta plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order', 'post', and 'idd... |
| CVE-2024-11810 | MEDIUM | 6.1 | 0.4% | Jan 7, 2025 | The PayGreen Payment Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message_id' p... |
| CVE-2024-11690 | MEDIUM | 6.1 | 0.3% | Jan 7, 2025 | The Financial Stocks & Crypto Market Data Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi... |
| CVE-2024-11496 | MEDIUM | 6.5 | 0.3% | Jan 7, 2025 | The Infility Global plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ... |
| CVE-2024-11445 | MEDIUM | 6.4 | 0.4% | Jan 7, 2025 | The Image Magnify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'image_magnify' sho... |
| CVE-2024-11434 | MEDIUM | 6.1 | 0.3% | Jan 7, 2025 | The WP – Bulk SMS – by SMS.to plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parame... |
| CVE-2024-11383 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The CC Canadian Mortgage Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '... |
| CVE-2024-11382 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Common Ninja: Fully Customizable & Perfectly Responsive Free Widgets for WordPress Websites plugin for WordPress is ... |
| CVE-2024-11378 | MEDIUM | 6.1 | 0.3% | Jan 7, 2025 | The Bizapp for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'error' paramete... |
| CVE-2024-11377 | MEDIUM | 6.1 | 0.5% | Jan 7, 2025 | The Automate Hub Free by Sperse.IO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' par... |
| CVE-2024-11375 | MEDIUM | 6.1 | 0.3% | Jan 7, 2025 | The WC1C plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without ap... |
| CVE-2024-11363 | MEDIUM | 6.1 | 0.3% | Jan 7, 2025 | The Same but Different – Related Posts by Taxonomy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ... |
| CVE-2024-11338 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The PIXNET Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gtm' and 'venue' parameters... |
| CVE-2024-11337 | MEDIUM | 6.4 | 0.4% | Jan 7, 2025 | The Horoscope And Tarot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'divine_horos... |
| CVE-2024-11290 | MEDIUM | 5.3 | 0.4% | Jan 7, 2025 | The Member Access plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ... |
| CVE-2024-12592 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Sellsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'testSellsy' shortcode in ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now