2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13795 | MEDIUM | 4.3 | 0.2% | Feb 18, 2025 | The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ... |
| CVE-2024-13704 | MEDIUM | 6.1 | 0.3% | Feb 18, 2025 | The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'st_user_title' paramet... |
| CVE-2024-13575 | MEDIUM | 5.4 | 0.4% | Feb 18, 2025 | The Web Stories Enhancer – Level Up Your Web Stories plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2024-13465 | MEDIUM | 5.4 | 0.3% | Feb 18, 2025 | The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Tabl... |
| CVE-2024-11895 | MEDIUM | 5.4 | 0.4% | Feb 18, 2025 | The Online Payments – Get Paid with PayPal, Square & Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2024-11376 | MEDIUM | 6.1 | 0.4% | Feb 18, 2025 | The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin... |
| CVE-2024-57964 | HIGH | 7.3 | 0.2% | Feb 18, 2025 | Insecure Loading of Dynamic Link Libraries have been discovered in HVAC Energy Saving Program, which could allow local a... |
| CVE-2024-57963 | HIGH | 7.3 | 0.2% | Feb 18, 2025 | Insecure Loading of Dynamic Link Libraries have been discovered in USB-CONVERTERCABLE DRIVER, which could allow local at... |
| CVE-2024-13523 | MEDIUM | 5.4 | 0.2% | Feb 18, 2025 | The MemorialDay plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1... |
| CVE-2024-45320 | MEDIUM | 6.5 | 0.2% | Feb 18, 2025 | Out-of-bounds write vulnerability exists in DocuPrint CP225w 01.22.01 and earlier, DocuPrint CP228w 01.22.01 and earlier... |
| CVE-2024-13556 | CRITICAL | 9.8 | 0.5% | Feb 18, 2025 | The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress is vulnerable to PHP Ob... |
| CVE-2024-13438 | MEDIUM | 4.3 | 0.2% | Feb 18, 2025 | The SpeedSize Image & Video AI-Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version... |
| CVE-2024-13315 | HIGH | 8.8 | 0.2% | Feb 18, 2025 | The Shopwarden – Automated WooCommerce monitoring & testing plugin for WordPress is vulnerable to Cross-Site Request For... |
| CVE-2024-13852 | HIGH | 8.8 | 0.3% | Feb 18, 2025 | The Option Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missin... |
| CVE-2024-13848 | MEDIUM | 4.8 | 0.2% | Feb 18, 2025 | The Reaction Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version... |
| CVE-2024-13725 | CRITICAL | 9.8 | 1.3% | Feb 18, 2025 | The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc... |
| CVE-2024-13687 | MEDIUM | 4.3 | 0.2% | Feb 18, 2025 | The Team Builder – Meet the Team plugin for WordPress is vulnerable to unauthorized modification of data due to a missin... |
| CVE-2024-13684 | HIGH | 8.1 | 0.2% | Feb 18, 2025 | The Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. Th... |
| CVE-2024-13677 | HIGH | 8.8 | 0.5% | Feb 18, 2025 | The GetBookingsWP – Appointments Booking Calendar Plugin For WordPress plugin for WordPress is vulnerable to privilege e... |
| CVE-2024-13622 | HIGH | 7.5 | 0.5% | Feb 18, 2025 | The File Uploads Addon for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi... |
| CVE-2024-13609 | MEDIUM | 5.9 | 1.6% | Feb 18, 2025 | The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive In... |
| CVE-2024-13595 | MEDIUM | 6.5 | 0.4% | Feb 18, 2025 | The Simple Signup Form plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'ssf' shortcode... |
| CVE-2024-13588 | MEDIUM | 5.4 | 0.2% | Feb 18, 2025 | The Simplebooklet PDF Viewer and Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug... |
| CVE-2024-13587 | MEDIUM | 5.4 | 0.2% | Feb 18, 2025 | The Zigaform – Price Calculator & Cost Estimation Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2024-13582 | MEDIUM | 5.4 | 0.2% | Feb 18, 2025 | The Simple Pricing Tables For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stor... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now