2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13473 | HIGH | 7.5 | 0.5% | Feb 12, 2025 | The LTL Freight Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship... |
| CVE-2024-13459 | MEDIUM | 5.4 | 0.3% | Feb 12, 2025 | The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fusedesk_newcase' short... |
| CVE-2024-13456 | MEDIUM | 5.4 | 0.2% | Feb 12, 2025 | The Easy Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wqt-question' sh... |
| CVE-2024-13437 | MEDIUM | 4.3 | 0.2% | Feb 12, 2025 | The Book a Room plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2... |
| CVE-2024-13435 | HIGH | 7.5 | 0.4% | Feb 12, 2025 | The Ebook Downloader plugin for WordPress is vulnerable to SQL Injection via the 'download' parameter in all versions up... |
| CVE-2024-13365 | CRITICAL | 9.8 | 1.5% | Feb 12, 2025 | The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin ... |
| CVE-2024-12296 | HIGH | 8.8 | 0.5% | Feb 12, 2025 | The Apus Framework plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege es... |
| CVE-2024-12213 | CRITICAL | 9.8 | 0.6% | Feb 12, 2025 | The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to 2.3.16. This is du... |
| CVE-2024-13814 | HIGH | 8.8 | 0.5% | Feb 12, 2025 | The The Global Gallery - WordPress Responsive Gallery plugin for WordPress is vulnerable to arbitrary shortcode executio... |
| CVE-2024-12315 | HIGH | 7.5 | 0.5% | Feb 12, 2025 | The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Sensitive Information Expo... |
| CVE-2024-13821 | MEDIUM | 5.3 | 0.4% | Feb 12, 2025 | The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in ... |
| CVE-2024-13794 | MEDIUM | 5.3 | 0.4% | Feb 12, 2025 | The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Login Page Dislcosure in all... |
| CVE-2024-13714 | HIGH | 8.8 | 0.9% | Feb 12, 2025 | The All-Images.ai – IA Image Bank and Custom Image creation plugin for WordPress is vulnerable to arbitrary file uploads... |
| CVE-2024-13601 | MEDIUM | 4.3 | 0.3% | Feb 12, 2025 | The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Insecu... |
| CVE-2024-13600 | HIGH | 7.5 | 0.5% | Feb 12, 2025 | The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Sensit... |
| CVE-2024-13374 | MEDIUM | 6.5 | 0.3% | Feb 12, 2025 | The WP Table Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on thew... |
| CVE-2024-13800 | HIGH | 8.1 | 0.4% | Feb 12, 2025 | The ConvertPlus plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of ser... |
| CVE-2024-13769 | MEDIUM | 5.4 | 0.3% | Feb 12, 2025 | The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to Stored Cross-Si... |
| CVE-2024-13665 | MEDIUM | 5.4 | 0.3% | Feb 12, 2025 | The Admire Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'space' shortcode in... |
| CVE-2024-13658 | MEDIUM | 5.4 | 0.3% | Feb 12, 2025 | The NGG Smart Image Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hr_SIS_ne... |
| CVE-2024-13656 | HIGH | 8.1 | 0.4% | Feb 12, 2025 | The Click Mag - Viral WordPress News Magazine/Blog Theme theme for WordPress is vulnerable to unauthorized modification ... |
| CVE-2024-13654 | HIGH | 8.1 | 0.4% | Feb 12, 2025 | The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of dat... |
| CVE-2024-13653 | HIGH | 8.8 | 0.5% | Feb 12, 2025 | The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of dat... |
| CVE-2024-13421 | CRITICAL | 9.8 | 0.7% | Feb 12, 2025 | The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and includi... |
| CVE-2024-12164 | MEDIUM | 4.3 | 0.4% | Feb 12, 2025 | The WPSyncSheets Lite For WPForms – WPForms Google Spreadsheet Addon plugin for WordPress is vulnerable to unauthorized ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now