2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-52902HIGH8.8IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded databas...
CVE-2024-13534HIGH7.5The Small Package Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_i...
CVE-2024-13533HIGH7.5The Small Package Quotes – USPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter ...
CVE-2024-13491HIGH7.5The Small Package Quotes – For Customers of FedEx plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' ...
CVE-2024-13485HIGH7.5The LTL Freight Quotes – ABF Freight Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and '...
CVE-2024-13483HIGH7.5The LTL Freight Quotes – SAIA Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropshi...
CVE-2024-13481HIGH7.5The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and ...
CVE-2024-13479HIGH7.5The LTL Freight Quotes – SEFL Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and...
CVE-2024-13478HIGH7.5The LTL Freight Quotes – TForce Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' a...
CVE-2024-13489HIGH7.5The LTL Freight Quotes – Old Dominion Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and ...
CVE-2024-13364MEDIUM5.3The Raptive Ads plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the site_...
CVE-2024-13363MEDIUM6.1The Raptive Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'poc' parameter in all vers...
CVE-2024-13339MEDIUM5.4The DeBounce Email Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and...
CVE-2024-13336MEDIUM4.3The Disable Auto Updates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2024-13231MEDIUM5.3The WordPress Portfolio Builder – Portfolio Gallery plugin for WordPress is vulnerable to unauthorized modification of d...
CVE-2024-13854MEDIUM4.3The Education Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions...
CVE-2024-13736MEDIUM6.1The Pure Chat – Live Chat & More! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘purechatWid...
CVE-2024-13719MEDIUM5.3The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up ...
CVE-2024-13712MEDIUM4.9The Pollin plugin for WordPress is vulnerable to SQL Injection via the 'question' parameter in all versions up to, and i...
CVE-2024-13711MEDIUM6.1The Pollin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'question' parameter in all vers...
CVE-2024-13679MEDIUM5.4The Widget BUY.BOX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buybox-widget' sh...
CVE-2024-13676MEDIUM6.5The Categorized Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' attribute of the 'ima...
CVE-2024-13674MEDIUM6.4The Cosmic Blocks (40+) Content Editor Blocks Collection plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2024-13663MEDIUM6.4The Coaching Staffs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mstw-cs-table' s...
CVE-2024-13660MEDIUM6.4The Responsive Flickr Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fsho...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now