2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13501MEDIUM5.4The WP-FormAssembly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'formassembly' sh...
CVE-2024-13464MEDIUM5.4The Library Bookshelves plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bookshelf' s...
CVE-2024-12813MEDIUM5.4The Open Hours – Easy Opening Hours plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
CVE-2024-12525MEDIUM5.4The Easy MLS Listings Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasa...
CVE-2024-12314HIGH7.2The Rapid Cache plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 1.2.3. This ...
CVE-2024-13740MEDIUM4.3The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Ref...
CVE-2024-13741MEDIUM5.4The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Reques...
CVE-2024-25066MEDIUM4.3RSA Authentication Manager before 8.7 SP2 Patch 1 allows XML External Entity (XXE) attacks via a license file, resulting...
CVE-2024-13837Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2024-13879MEDIUM5.5The Stream plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.2...
CVE-2024-47935MEDIUM6.7Improper Validation of Integrity Check Value vulnerability in TXOne Networks StellarProtect (Legacy Mode), StellarEnforc...
CVE-2024-13726HIGH8.6The Coder WordPress plugin through 1.3.4 does not properly sanitise and escape a parameter before using it in a SQL st...
CVE-2024-13627MEDIUM4.7The OWL Carousel Slider WordPress plugin through 2.2 does not sanitise and escape a parameter before outputting it back ...
CVE-2024-13626HIGH7.1The VR-Frases (collect & share quotes) WordPress plugin through 3.0.1 does not sanitise and escape a parameter before ou...
CVE-2024-13625HIGH7.1The Tube Video Ads Lite WordPress plugin through 1.5.7 does not sanitise and escape a parameter before outputting it bac...
CVE-2024-13608MEDIUM4.7The Track Logins WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statemen...
CVE-2024-13603MEDIUM6.1The Wise Forms WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow unaut...
CVE-2024-44044HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandexponents Osh...
CVE-2024-57971CRITICAL9.1DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:...
CVE-2024-57970MEDIUM4libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c v...
CVE-2024-13834MEDIUM5.4The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme plugin for WordP...
CVE-2024-13500MEDIUM6.5The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for Wo...
CVE-2024-13488HIGH7.5The LTL Freight Quotes – Estes Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' an...
CVE-2024-13439MEDIUM4.3The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capab...
CVE-2024-10581MEDIUM4.3The DirectoryPress Frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now