2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-11052MEDIUM6.1The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2024-10637MEDIUM5.4The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.54 does not validate and escape some of its bloc...
CVE-2024-10568MEDIUM4.7The Ajax Search Lite WordPress plugin before 4.12.4 does not sanitise and escape some of its settings, which could allo...
CVE-2024-10518MEDIUM4.8The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl...
CVE-2024-10517MEDIUM4.8The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl...
CVE-2024-10010MEDIUM4.8The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-12526MEDIUM4.3The Arena.IM – Live Blogging for real-time events plugin for WordPress is vulnerable to Cross-Site Request Forgery in al...
CVE-2024-12463MEDIUM5.4The Arena.IM – Live Blogging for real-time events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2024-12441MEDIUM6.1The BP Email Assign Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parame...
CVE-2024-12406MEDIUM6.5The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via t...
CVE-2024-12162MEDIUM6.1The Video & Photo Gallery for Ultimate Member plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t...
CVE-2024-12156MEDIUM6.1The AI Content Writer, RSS Feed to Post, Autoblogging SEO Help plugin for WordPress is vulnerable to Reflected Cross-Sit...
CVE-2024-11891MEDIUM6.4The Perfect Font Awesome Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
CVE-2024-11875MEDIUM6.4The Add infos to the events calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
CVE-2024-11804MEDIUM6.1The Planaday API plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all ver...
CVE-2024-11750MEDIUM6.4The ONLYOFFICE DocSpace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'onlyoffice-d...
CVE-2024-11723MEDIUM6.1The kvCORE IDX plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via any parameter on pages with the ...
CVE-2024-11709MEDIUM4.3The AI Post Generator | AutoWriter plugin for WordPress is vulnerable to unauthorized modification of data due to a miss...
CVE-2024-11459MEDIUM6.1The Country Blocker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ip' parameter in all v...
CVE-2024-11410MEDIUM6.4The Top and footer bars for announcements, notifications, advertisements, promotions – YooBar plugin for WordPress is vu...
CVE-2024-11384MEDIUM5.4The Arena.IM – Live Blogging for real-time events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2024-10182MEDIUM6.4The Cognito Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all versio...
CVE-2024-12461MEDIUM6.4The WP-Revive Adserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprevive_asyn...
CVE-2024-12341MEDIUM4.3The Custom Skins Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...
CVE-2024-12338MEDIUM6.1The Website Toolbox Community plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘websitetoolb...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now