2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13581MEDIUM5.4The Simple Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'simple_chart' shor...
CVE-2024-13579MEDIUM5.4The WP-Asambleas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'polls_popup' shortc...
CVE-2024-13578MEDIUM5.4The WP-BibTeX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'WpBibTeX' shortcode in...
CVE-2024-13577MEDIUM5.4The CATS Job Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catsone' short...
CVE-2024-13576MEDIUM5.4The Gumlet Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gumlet' shortcode i...
CVE-2024-13573MEDIUM5.4The Zigaform – Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zgf...
CVE-2024-13565MEDIUM5.4The Simple Map No Api plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all...
CVE-2024-13555MEDIUM4.3The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Cross-Site R...
CVE-2024-13540MEDIUM5.3The WooODT Lite – Delivery & pickup date time location for WooCommerce plugin for WordPress is vulnerable to Full Path D...
CVE-2024-13538MEDIUM5.3The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all vers...
CVE-2024-13535MEDIUM5.3The Actionwear products sync plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and inclu...
CVE-2024-13522MEDIUM5.4The magayo Lottery Results plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2024-13501MEDIUM5.4The WP-FormAssembly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'formassembly' sh...
CVE-2024-13464MEDIUM5.4The Library Bookshelves plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bookshelf' s...
CVE-2024-12813MEDIUM5.4The Open Hours – Easy Opening Hours plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
CVE-2024-12525MEDIUM5.4The Easy MLS Listings Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasa...
CVE-2024-12314HIGH7.2The Rapid Cache plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 1.2.3. This ...
CVE-2024-13740MEDIUM4.3The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Ref...
CVE-2024-13741MEDIUM5.4The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Reques...
CVE-2024-25066MEDIUM4.3RSA Authentication Manager before 8.7 SP2 Patch 1 allows XML External Entity (XXE) attacks via a license file, resulting...
CVE-2024-13837——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2024-13879MEDIUM5.5The Stream plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.2...
CVE-2024-47935MEDIUM6.7Improper Validation of Integrity Check Value vulnerability in TXOne Networks StellarProtect (Legacy Mode), StellarEnforc...
CVE-2024-13726HIGH8.6The Coder WordPress plugin through 1.3.4 does not properly sanitise and escape a parameter before using it in a SQL st...
CVE-2024-13627MEDIUM4.7The OWL Carousel Slider WordPress plugin through 2.2 does not sanitise and escape a parameter before outputting it back ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now