2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13795MEDIUM4.3The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ...
CVE-2024-13704MEDIUM6.1The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'st_user_title' paramet...
CVE-2024-13575MEDIUM5.4The Web Stories Enhancer – Level Up Your Web Stories plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2024-13465MEDIUM5.4The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Tabl...
CVE-2024-11895MEDIUM5.4The Online Payments – Get Paid with PayPal, Square & Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2024-11376MEDIUM6.1The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin...
CVE-2024-57964HIGH7.3Insecure Loading of Dynamic Link Libraries have been discovered in HVAC Energy Saving Program, which could allow local a...
CVE-2024-57963HIGH7.3Insecure Loading of Dynamic Link Libraries have been discovered in USB-CONVERTERCABLE DRIVER, which could allow local at...
CVE-2024-13523MEDIUM5.4The MemorialDay plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2024-45320MEDIUM6.5Out-of-bounds write vulnerability exists in DocuPrint CP225w 01.22.01 and earlier, DocuPrint CP228w 01.22.01 and earlier...
CVE-2024-13556CRITICAL9.8The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress is vulnerable to PHP Ob...
CVE-2024-13438MEDIUM4.3The SpeedSize Image & Video AI-Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...
CVE-2024-13315HIGH8.8The Shopwarden – Automated WooCommerce monitoring & testing plugin for WordPress is vulnerable to Cross-Site Request For...
CVE-2024-13852HIGH8.8The Option Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missin...
CVE-2024-13848MEDIUM4.8The Reaction Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version...
CVE-2024-13725CRITICAL9.8The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc...
CVE-2024-13687MEDIUM4.3The Team Builder – Meet the Team plugin for WordPress is vulnerable to unauthorized modification of data due to a missin...
CVE-2024-13684HIGH8.1The Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. Th...
CVE-2024-13677HIGH8.8The GetBookingsWP – Appointments Booking Calendar Plugin For WordPress plugin for WordPress is vulnerable to privilege e...
CVE-2024-13622HIGH7.5The File Uploads Addon for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi...
CVE-2024-13609MEDIUM5.9The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive In...
CVE-2024-13595MEDIUM6.5The Simple Signup Form plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'ssf' shortcode...
CVE-2024-13588MEDIUM5.4The Simplebooklet PDF Viewer and Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2024-13587MEDIUM5.4The Zigaform – Price Calculator & Cost Estimation Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2024-13582MEDIUM5.4The Simple Pricing Tables For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stor...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now