2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-11841MEDIUM5.4The Tithe.ly Giving Button WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes be...
CVE-2024-8650MEDIUM5.3An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6...
CVE-2024-8116MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17....
CVE-2024-8798MEDIUM6.5No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client....
CVE-2024-56074MEDIUM5.5gitingest before 9996a06 mishandles symbolic links that point outside of the base directory.
CVE-2024-11720MEDIUM6.1The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via submission forms ...
CVE-2024-12628MEDIUM4.4The bodi0`s Easy cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cache-folder' paramete...
CVE-2024-12446MEDIUM6.4The Post to Pdf plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gmptp_single_post' s...
CVE-2024-11714MEDIUM4.9The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to...
CVE-2024-11713MEDIUM4.9The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to...
CVE-2024-11712MEDIUM5.3The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to...
CVE-2024-11710MEDIUM4.9The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to...
CVE-2024-12501MEDIUM6.4The Simple Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all ...
CVE-2024-12474MEDIUM6.4The GeoDataSource Country Region DropDown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2024-12459MEDIUM6.4The Ganohrs Toggle Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'toggle'...
CVE-2024-12422MEDIUM6.1The Import Eventbrite Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' paramet...
CVE-2024-11752MEDIUM6.4The Eveeno plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'eveeno' shortcode in all ...
CVE-2024-10690MEDIUM4.3The Shortcodes for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inclu...
CVE-2024-10646MEDIUM6.1The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner...
CVE-2024-12578MEDIUM5.3The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Information Exposure in all versions up to...
CVE-2024-12555MEDIUM6.1The SIP Calculator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2024-12523MEDIUM6.4The States Map US plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'states_map' shortc...
CVE-2024-12517MEDIUM6.4The WooCommerce Cart Count Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
CVE-2024-12502MEDIUM6.4The My IDX Home Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasap-idx-...
CVE-2024-12458MEDIUM6.4The Smart PopUp Blaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spb-button' ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now