2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-11749MEDIUM6.4The App Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'appizy' shortcode in a...
CVE-2024-11606MEDIUM5.3The Tabs Shortcode WordPress plugin through 2.0.2 does not validate and escape some of its shortcode attributes before o...
CVE-2024-11369MEDIUM6.1The Store credit / Gift cards for woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t...
CVE-2024-10536MEDIUM4.3The FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor plugin for Word...
CVE-2024-9208MEDIUM6.1The Enable Accessibility plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_quer...
CVE-2024-12462MEDIUM6.4The YOGO Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yogo-calendar' shor...
CVE-2024-12457MEDIUM6.4The Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode plugin for WordPress is ...
CVE-2024-12453MEDIUM6.4The Uptodown APK Download Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'utd...
CVE-2024-12445MEDIUM6.4The RightMessage WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rm_area' shortco...
CVE-2024-12435MEDIUM6.1The Compare Products for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s_fea...
CVE-2024-12332MEDIUM6.5The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter...
CVE-2024-12327MEDIUM4.3The LazyLoad Background Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ...
CVE-2024-12324MEDIUM6.1The Unilevel MLM Plan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in a...
CVE-2024-12291MEDIUM6.1The ViewMedica 9 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2024-12290MEDIUM6.1The Infility Global plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘set_type’ parameter in...
CVE-2024-12288MEDIUM6.1The Simple add pages or posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an...
CVE-2024-12256MEDIUM6.1The Simple Video Management System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'analyti...
CVE-2024-12214MEDIUM6.1The WooCommerce HSS Extension for Streaming Video plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v...
CVE-2024-12207MEDIUM4.4The Toggles Shortcode and Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ par...
CVE-2024-12176MEDIUM5.3The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to unauthorized access due to a missing capabi...
CVE-2024-12170MEDIUM5.4The ViewMedica 9 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2024-12159MEDIUM5.3The Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords plugin for WordPress is vulnerable to Inform...
CVE-2024-12158MEDIUM5.3The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to unauthorized l...
CVE-2024-12153MEDIUM6.1The GDY Modular Content plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query...
CVE-2024-12140MEDIUM4.3The Elementor Addons AI Addons – 70 Widgets, Premium Templates, Ultimate Elements plugin for WordPress is vulnerable to ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now