2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-23563MEDIUM4.4HCL Connections Docs is vulnerable to a sensitive information disclosure which could allow a user to obtain sensitive in...
CVE-2024-10322MEDIUM5.4The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads...
CVE-2024-13532HIGH7.5The Small Package Quotes – Purolator Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and '...
CVE-2024-13480HIGH7.5The LTL Freight Quotes – For Customers of FedEx Freight plugin for WordPress is vulnerable to SQL Injection via the 'edi...
CVE-2024-13477CRITICAL9.8The LTL Freight Quotes – Unishippers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' param...
CVE-2024-12386MEDIUM5.4The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2024-10960HIGH8.8The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio...
CVE-2024-32838HIGH8.8SQL Injection vulnerability in various API endpoints - offices, dashboards, etc. Apache Fineract versions 1.9 and before...
CVE-2024-13531HIGH7.5The ShipEngine Shipping Quotes plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all ve...
CVE-2024-13528HIGH7.5The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versi...
CVE-2024-13490HIGH7.5The LTL Freight Quotes – XPO Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship...
CVE-2024-13475HIGH7.5The Small Package Quotes – UPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter i...
CVE-2024-13473HIGH7.5The LTL Freight Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship...
CVE-2024-13459MEDIUM5.4The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fusedesk_newcase' short...
CVE-2024-13456MEDIUM5.4The Easy Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wqt-question' sh...
CVE-2024-13437MEDIUM4.3The Book a Room plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2...
CVE-2024-13435HIGH7.5The Ebook Downloader plugin for WordPress is vulnerable to SQL Injection via the 'download' parameter in all versions up...
CVE-2024-13365CRITICAL9.8The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin ...
CVE-2024-12296HIGH8.8The Apus Framework plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege es...
CVE-2024-12213CRITICAL9.8The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to 2.3.16. This is du...
CVE-2024-13814HIGH8.8The The Global Gallery - WordPress Responsive Gallery plugin for WordPress is vulnerable to arbitrary shortcode executio...
CVE-2024-12315HIGH7.5The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Sensitive Information Expo...
CVE-2024-13821MEDIUM5.3The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in ...
CVE-2024-13794MEDIUM5.3The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Login Page Dislcosure in all...
CVE-2024-13714HIGH8.8The All-Images.ai – IA Image Bank and Custom Image creation plugin for WordPress is vulnerable to arbitrary file uploads...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now