2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13657MEDIUM6.4The Store Locator Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'storelocato...
CVE-2024-13592HIGH8.8The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Local File In...
CVE-2024-13591MEDIUM5.4The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-...
CVE-2024-13589MEDIUM6.4The YouTube Playlists with Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yt...
CVE-2024-13468HIGH7.5The Trash Duplicate and 301 Redirect plugin for WordPress is vulnerable to unauthorized loss of data due to a missing ca...
CVE-2024-13462MEDIUM6.4The WP Wiki Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wiki' shortcode ...
CVE-2024-13405MEDIUM4.3The Apptivo Business Site CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an...
CVE-2024-13390MEDIUM6.4The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2024-12522MEDIUM6.4The Yay! Forms | Embed Custom Forms, Surveys, and Quizzes Easily plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2024-12339MEDIUM6.1The Digihood HTML Sitemap plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘channel' paramet...
CVE-2024-12069MEDIUM6.1The Lexicata plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg withou...
CVE-2024-11778MEDIUM6.4The CanadaHelps Embedded Donation Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'...
CVE-2024-11753MEDIUM6.4The UMich OIDC Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'umich_oidc_butt...
CVE-2024-11335MEDIUM6.4The UltraEmbed – Advanced Iframe Plugin For WordPress with Gutenberg Block Included plugin for WordPress is vulnerable t...
CVE-2024-13799MEDIUM6.4The User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress is vulnerable to S...
CVE-2024-12173LOW3.5The Master Slider WordPress plugin before 3.10.5 does not sanitise and escape some of its settings, which could allow h...
CVE-2024-13443MEDIUM6.4The Easypromos Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Easypromos shor...
CVE-2024-11582HIGH7.2The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2024-57262HIGH7.1In barebox before 2025.01.0, ext4fs_read_symlink has an integer overflow for zalloc (adding one to an le32 variable) via...
CVE-2024-57261HIGH7.1In barebox before 2025.01.0, request2size in common/dlmalloc.c has an integer overflow, a related issue to CVE-2024-5725...
CVE-2024-13508MEDIUM6.1The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the locale parameter in all...
CVE-2024-57259MEDIUM6.8sqfs_search_dir in Das U-Boot before 2025.01-rc1 exhibits an off-by-one error and resultant heap memory corruption for s...
CVE-2024-57258HIGH7.8Integer overflows in memory allocation in Das U-Boot before 2025.01-rc1 occur for a crafted squashfs filesystem via sbrk...
CVE-2024-57257LOW2.4A stack consumption issue in sqfs_size in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with de...
CVE-2024-57256MEDIUM6.8An integer overflow in ext4fs_read_symlink in Das U-Boot before 2025.01-rc1 occurs for zalloc (adding one to an le32 var...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now