2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45673 | MEDIUM | 5.5 | 0.1% | Feb 21, 2025 | IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 thro... |
| CVE-2024-10222 | MEDIUM | 5.4 | 0.4% | Feb 21, 2025 | The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions u... |
| CVE-2024-9150 | HIGH | 8.7 | 0.4% | Feb 21, 2025 | Report generation functionality in Wyn Enterprise allows for code inclusion, but not sufficiently limits what code might... |
| CVE-2024-13900 | HIGH | 7.2 | 0.4% | Feb 21, 2025 | The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and... |
| CVE-2024-13846 | MEDIUM | 4.9 | 0.4% | Feb 21, 2025 | The Indeed Ultimate Learning Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘post_id’ parame... |
| CVE-2024-13713 | MEDIUM | 6.5 | 0.4% | Feb 21, 2025 | The WPExperts Square For GiveWP plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all vers... |
| CVE-2024-13455 | MEDIUM | 5.4 | 0.2% | Feb 21, 2025 | The igumbi Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'igumbi_cal... |
| CVE-2024-13648 | MEDIUM | 5.4 | 0.3% | Feb 21, 2025 | The Maps for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MapOnePoint' shortco... |
| CVE-2024-13461 | MEDIUM | 5.4 | 0.2% | Feb 21, 2025 | The Autoship Cloud for WooCommerce Subscription Products plugin for WordPress is vulnerable to Stored Cross-Site Scripti... |
| CVE-2024-13353 | HIGH | 8.8 | 0.7% | Feb 21, 2025 | The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulne... |
| CVE-2024-12452 | MEDIUM | 5.4 | 0.3% | Feb 21, 2025 | The Ziggeo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ziggeo_event' shortcode i... |
| CVE-2024-12276 | MEDIUM | 6.5 | 0.3% | Feb 21, 2025 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi... |
| CVE-2024-13585 | LOW | 3.5 | 0.4% | Feb 21, 2025 | The Ajax Search Lite WordPress plugin before 4.12.5 does not sanitise and escape some of its settings, which could allo... |
| CVE-2024-13314 | LOW | 3.5 | 0.4% | Feb 21, 2025 | The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.7.4 does not sanitise and escape some of its set... |
| CVE-2024-11260 | HIGH | 7.5 | 0.6% | Feb 21, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injecti... |
| CVE-2024-13883 | MEDIUM | 4.3 | 0.2% | Feb 21, 2025 | The WPUpper Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2024-13818 | HIGH | 7.5 | 0.5% | Feb 21, 2025 | The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & C... |
| CVE-2024-13751 | MEDIUM | 5.4 | 0.2% | Feb 21, 2025 | The 3D Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'des[]' parameter in all ... |
| CVE-2024-13672 | MEDIUM | 5.4 | 0.3% | Feb 21, 2025 | The Mini Course Generator | Embed mini-courses and interactive content plugin for WordPress is vulnerable to Stored Cros... |
| CVE-2024-13537 | MEDIUM | 5.3 | 0.3% | Feb 21, 2025 | The C9 Blocks plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.7.7. Th... |
| CVE-2024-13388 | MEDIUM | 5.4 | 0.2% | Feb 21, 2025 | The TCBD Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbdtooltip_text' s... |
| CVE-2024-13379 | MEDIUM | 5.4 | 0.3% | Feb 21, 2025 | The C9 Admin Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver... |
| CVE-2024-13235 | MEDIUM | 6.5 | 0.4% | Feb 21, 2025 | The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'l... |
| CVE-2024-38657 | MEDIUM | 4.9 | 1.3% | Feb 21, 2025 | External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version... |
| CVE-2024-7131 | — | — | — | Feb 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now