2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-45673MEDIUM5.5IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 thro...
CVE-2024-10222MEDIUM5.4The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions u...
CVE-2024-9150HIGH8.7Report generation functionality in Wyn Enterprise allows for code inclusion, but not sufficiently limits what code might...
CVE-2024-13900HIGH7.2The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and...
CVE-2024-13846MEDIUM4.9The Indeed Ultimate Learning Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘post_id’ parame...
CVE-2024-13713MEDIUM6.5The WPExperts Square For GiveWP plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all vers...
CVE-2024-13455MEDIUM5.4The igumbi Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'igumbi_cal...
CVE-2024-13648MEDIUM5.4The Maps for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MapOnePoint' shortco...
CVE-2024-13461MEDIUM5.4The Autoship Cloud for WooCommerce Subscription Products plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2024-13353HIGH8.8The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulne...
CVE-2024-12452MEDIUM5.4The Ziggeo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ziggeo_event' shortcode i...
CVE-2024-12276MEDIUM6.5The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2024-13585LOW3.5The Ajax Search Lite WordPress plugin before 4.12.5 does not sanitise and escape some of its settings, which could allo...
CVE-2024-13314LOW3.5The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.7.4 does not sanitise and escape some of its set...
CVE-2024-11260HIGH7.5The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injecti...
CVE-2024-13883MEDIUM4.3The WPUpper Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2024-13818HIGH7.5The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & C...
CVE-2024-13751MEDIUM5.4The 3D Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'des[]' parameter in all ...
CVE-2024-13672MEDIUM5.4The Mini Course Generator | Embed mini-courses and interactive content plugin for WordPress is vulnerable to Stored Cros...
CVE-2024-13537MEDIUM5.3The C9 Blocks plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.7.7. Th...
CVE-2024-13388MEDIUM5.4The TCBD Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbdtooltip_text' s...
CVE-2024-13379MEDIUM5.4The C9 Admin Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver...
CVE-2024-13235MEDIUM6.5The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'l...
CVE-2024-38657MEDIUM4.9External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version...
CVE-2024-7131Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now