2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13657 | MEDIUM | 6.4 | 0.3% | Feb 19, 2025 | The Store Locator Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'storelocato... |
| CVE-2024-13592 | HIGH | 8.8 | 0.8% | Feb 19, 2025 | The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Local File In... |
| CVE-2024-13591 | MEDIUM | 5.4 | 0.3% | Feb 19, 2025 | The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-... |
| CVE-2024-13589 | MEDIUM | 6.4 | 0.3% | Feb 19, 2025 | The YouTube Playlists with Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yt... |
| CVE-2024-13468 | HIGH | 7.5 | 0.5% | Feb 19, 2025 | The Trash Duplicate and 301 Redirect plugin for WordPress is vulnerable to unauthorized loss of data due to a missing ca... |
| CVE-2024-13462 | MEDIUM | 6.4 | 0.4% | Feb 19, 2025 | The WP Wiki Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wiki' shortcode ... |
| CVE-2024-13405 | MEDIUM | 4.3 | 0.2% | Feb 19, 2025 | The Apptivo Business Site CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an... |
| CVE-2024-13390 | MEDIUM | 6.4 | 0.3% | Feb 19, 2025 | The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug... |
| CVE-2024-12522 | MEDIUM | 6.4 | 0.4% | Feb 19, 2025 | The Yay! Forms | Embed Custom Forms, Surveys, and Quizzes Easily plugin for WordPress is vulnerable to Stored Cross-Site... |
| CVE-2024-12339 | MEDIUM | 6.1 | 0.4% | Feb 19, 2025 | The Digihood HTML Sitemap plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘channel' paramet... |
| CVE-2024-12069 | MEDIUM | 6.1 | 0.3% | Feb 19, 2025 | The Lexicata plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg withou... |
| CVE-2024-11778 | MEDIUM | 6.4 | 0.4% | Feb 19, 2025 | The CanadaHelps Embedded Donation Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'... |
| CVE-2024-11753 | MEDIUM | 6.4 | 0.4% | Feb 19, 2025 | The UMich OIDC Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'umich_oidc_butt... |
| CVE-2024-11335 | MEDIUM | 6.4 | 0.3% | Feb 19, 2025 | The UltraEmbed – Advanced Iframe Plugin For WordPress with Gutenberg Block Included plugin for WordPress is vulnerable t... |
| CVE-2024-13799 | MEDIUM | 6.4 | 0.3% | Feb 19, 2025 | The User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress is vulnerable to S... |
| CVE-2024-12173 | LOW | 3.5 | 0.3% | Feb 19, 2025 | The Master Slider WordPress plugin before 3.10.5 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2024-13443 | MEDIUM | 6.4 | 0.2% | Feb 19, 2025 | The Easypromos Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Easypromos shor... |
| CVE-2024-11582 | HIGH | 7.2 | 0.3% | Feb 19, 2025 | The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2024-57262 | HIGH | 7.1 | 0.3% | Feb 19, 2025 | In barebox before 2025.01.0, ext4fs_read_symlink has an integer overflow for zalloc (adding one to an le32 variable) via... |
| CVE-2024-57261 | HIGH | 7.1 | 0.3% | Feb 19, 2025 | In barebox before 2025.01.0, request2size in common/dlmalloc.c has an integer overflow, a related issue to CVE-2024-5725... |
| CVE-2024-13508 | MEDIUM | 6.1 | 0.3% | Feb 19, 2025 | The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the locale parameter in all... |
| CVE-2024-57259 | MEDIUM | 6.8 | 0.4% | Feb 18, 2025 | sqfs_search_dir in Das U-Boot before 2025.01-rc1 exhibits an off-by-one error and resultant heap memory corruption for s... |
| CVE-2024-57258 | HIGH | 7.8 | 0.2% | Feb 18, 2025 | Integer overflows in memory allocation in Das U-Boot before 2025.01-rc1 occur for a crafted squashfs filesystem via sbrk... |
| CVE-2024-57257 | LOW | 2.4 | 0.3% | Feb 18, 2025 | A stack consumption issue in sqfs_size in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with de... |
| CVE-2024-57256 | MEDIUM | 6.8 | 0.4% | Feb 18, 2025 | An integer overflow in ext4fs_read_symlink in Das U-Boot before 2025.01-rc1 occurs for zalloc (adding one to an le32 var... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now