2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13564MEDIUM5.4The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2024-13798MEDIUM5.3The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in al...
CVE-2024-13474HIGH7.5The LTL Freight Quotes – Purolator Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id...
CVE-2024-12467MEDIUM6.1The Pago por Redsys plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'Ds_MerchantParameters'...
CVE-2024-12038MEDIUM5.4The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) p...
CVE-2024-13899HIGH7.2The Mambo Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 ...
CVE-2024-13873MEDIUM4.3The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to...
CVE-2024-22341HIGH7.5IBM Watson Query on Cloud Pak for Data 4.0.0 through 4.0.9, 4.5.0 through 4.5.3, 4.6.0 through 4.6.6, 4.7.0 through 4.7....
CVE-2024-45674LOW3.3IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 thro...
CVE-2024-57176HIGH7.6An issue in the shiroFilter function of White-Jotter project v0.2.2 allows attackers to execute a directory traversal an...
CVE-2024-55159MEDIUM4.2GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the SortName parameter at /system/l...
CVE-2024-55156MEDIUM5.5An XML External Entity (XXE) vulnerability in the deserializeArgs() method of Java SDK for CloudEvents v4.0.1 allows att...
CVE-2024-45673MEDIUM5.5IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 thro...
CVE-2024-10222MEDIUM5.4The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions u...
CVE-2024-9150HIGH8.7Report generation functionality in Wyn Enterprise allows for code inclusion, but not sufficiently limits what code might...
CVE-2024-13900HIGH7.2The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and...
CVE-2024-13846MEDIUM4.9The Indeed Ultimate Learning Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘post_id’ parame...
CVE-2024-13713MEDIUM6.5The WPExperts Square For GiveWP plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all vers...
CVE-2024-13455MEDIUM5.4The igumbi Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'igumbi_cal...
CVE-2024-13648MEDIUM5.4The Maps for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MapOnePoint' shortco...
CVE-2024-13461MEDIUM5.4The Autoship Cloud for WooCommerce Subscription Products plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2024-13353HIGH8.8The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulne...
CVE-2024-12452MEDIUM5.4The Ziggeo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ziggeo_event' shortcode i...
CVE-2024-12276MEDIUM6.5The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2024-13585LOW3.5The Ajax Search Lite WordPress plugin before 4.12.5 does not sanitise and escape some of its settings, which could allo...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now