2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-12420MEDIUM6.5The The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to arbitrary shortcode exec...
CVE-2024-12417MEDIUM6.5The The Simple Link Directory plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to,...
CVE-2024-12414MEDIUM4.3The Themify Store Locator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2024-12309MEDIUM5.3The Rate My Post – Star Rating Plugin by FeedbackWP plugin for WordPress is vulnerable to Insecure Direct Object Referen...
CVE-2024-12042MEDIUM5.4The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2024-11911MEDIUM4.3The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability c...
CVE-2024-11910MEDIUM5.4The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp-crowdfunding/search blo...
CVE-2024-11832MEDIUM5.4The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the cu...
CVE-2024-11754MEDIUM6.4The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'trafftbook...
CVE-2024-11275MEDIUM4.3The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable...
CVE-2024-55918MEDIUM5.3An issue was discovered in the Graphics::ColorNames package before 3.2.0 for Perl. There is an ambiguity between modules...
CVE-2024-12581MEDIUM4.8The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si...
CVE-2024-10939MEDIUM4.8The Image Widget WordPress plugin before 4.4.11 does not sanitise and escape some of its Image Widget settings, which co...
CVE-2024-10678MEDIUM5.4The Ultimate Blocks WordPress plugin before 3.2.4 does not validate and escape some of its block options before outputt...
CVE-2024-12579MEDIUM5.3The Minify HTML plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to...
CVE-2024-12574MEDIUM5.4The SVG Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions...
CVE-2024-11809MEDIUM6.1The Primer MyData for Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'img_src'...
CVE-2024-11767MEDIUM6.4The NewsmanApp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'newsman_subscribe_wid...
CVE-2024-12572MEDIUM6.1The Hello In All Languages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2024-12289MEDIUM5.9Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initializati...
CVE-2024-55886MEDIUM6.9OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms, enriches, and routes...
CVE-2024-55878MEDIUM6.8SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in version 1.0.12 and prior to ve...
CVE-2024-55876MEDIUM5.4XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0,...
CVE-2024-49071MEDIUM6.5Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender al...
CVE-2024-47238MEDIUM6.7Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A hi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now