2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13336 | MEDIUM | 4.3 | 0.2% | Feb 19, 2025 | The Disable Auto Updates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2024-13231 | MEDIUM | 5.3 | 0.4% | Feb 19, 2025 | The WordPress Portfolio Builder – Portfolio Gallery plugin for WordPress is vulnerable to unauthorized modification of d... |
| CVE-2024-13854 | MEDIUM | 4.3 | 0.3% | Feb 19, 2025 | The Education Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions... |
| CVE-2024-13736 | MEDIUM | 6.1 | 0.4% | Feb 19, 2025 | The Pure Chat – Live Chat & More! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘purechatWid... |
| CVE-2024-13719 | MEDIUM | 5.3 | 0.4% | Feb 19, 2025 | The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up ... |
| CVE-2024-13712 | MEDIUM | 4.9 | 0.5% | Feb 19, 2025 | The Pollin plugin for WordPress is vulnerable to SQL Injection via the 'question' parameter in all versions up to, and i... |
| CVE-2024-13711 | MEDIUM | 6.1 | 0.3% | Feb 19, 2025 | The Pollin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'question' parameter in all vers... |
| CVE-2024-13679 | MEDIUM | 5.4 | 0.3% | Feb 19, 2025 | The Widget BUY.BOX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buybox-widget' sh... |
| CVE-2024-13676 | MEDIUM | 6.5 | 0.4% | Feb 19, 2025 | The Categorized Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' attribute of the 'ima... |
| CVE-2024-13674 | MEDIUM | 6.4 | 0.3% | Feb 19, 2025 | The Cosmic Blocks (40+) Content Editor Blocks Collection plugin for WordPress is vulnerable to Stored Cross-Site Scripti... |
| CVE-2024-13663 | MEDIUM | 6.4 | 0.3% | Feb 19, 2025 | The Coaching Staffs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mstw-cs-table' s... |
| CVE-2024-13660 | MEDIUM | 6.4 | 0.4% | Feb 19, 2025 | The Responsive Flickr Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fsho... |
| CVE-2024-13657 | MEDIUM | 6.4 | 0.3% | Feb 19, 2025 | The Store Locator Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'storelocato... |
| CVE-2024-13592 | HIGH | 8.8 | 0.8% | Feb 19, 2025 | The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Local File In... |
| CVE-2024-13591 | MEDIUM | 5.4 | 0.3% | Feb 19, 2025 | The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-... |
| CVE-2024-13589 | MEDIUM | 6.4 | 0.3% | Feb 19, 2025 | The YouTube Playlists with Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yt... |
| CVE-2024-13468 | HIGH | 7.5 | 0.5% | Feb 19, 2025 | The Trash Duplicate and 301 Redirect plugin for WordPress is vulnerable to unauthorized loss of data due to a missing ca... |
| CVE-2024-13462 | MEDIUM | 6.4 | 0.4% | Feb 19, 2025 | The WP Wiki Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wiki' shortcode ... |
| CVE-2024-13405 | MEDIUM | 4.3 | 0.2% | Feb 19, 2025 | The Apptivo Business Site CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an... |
| CVE-2024-13390 | MEDIUM | 6.4 | 0.3% | Feb 19, 2025 | The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug... |
| CVE-2024-12522 | MEDIUM | 6.4 | 0.4% | Feb 19, 2025 | The Yay! Forms | Embed Custom Forms, Surveys, and Quizzes Easily plugin for WordPress is vulnerable to Stored Cross-Site... |
| CVE-2024-12339 | MEDIUM | 6.1 | 0.4% | Feb 19, 2025 | The Digihood HTML Sitemap plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘channel' paramet... |
| CVE-2024-12069 | MEDIUM | 6.1 | 0.3% | Feb 19, 2025 | The Lexicata plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg withou... |
| CVE-2024-11778 | MEDIUM | 6.4 | 0.4% | Feb 19, 2025 | The CanadaHelps Embedded Donation Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'... |
| CVE-2024-11753 | MEDIUM | 6.4 | 0.4% | Feb 19, 2025 | The UMich OIDC Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'umich_oidc_butt... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now