2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-53007MEDIUM6.4Bentley Systems ProjectWise Integration Server before 10.00.03.288 allows unintended SQL query execution by an authentic...
CVE-2024-52875HIGH8.8An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertE...
CVE-2024-13530MEDIUM4.3The Custom Login Page Styler – Limit Login Attempts – Restrict Content With Login – Redirect After Login – Change Login ...
CVE-2024-13623MEDIUM5.9The Order Export for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up...
CVE-2024-13717MEDIUM4.3The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to unauthorized modification of data du...
CVE-2024-13504HIGH7.2The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Si...
CVE-2024-13424MEDIUM4.3The Ni Sales Commission For WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capab...
CVE-2024-13415MEDIUM4.3The Food Menu – Restaurant Menu & Online Ordering for WooCommerce plugin for WordPress is vulnerable to unauthorized acc...
CVE-2024-13226MEDIUM6.1The A5 Custom Login Page WordPress plugin through 2.8.1 does not sanitise and escape a parameter before outputting it ba...
CVE-2024-13225MEDIUM6.1The ECT Home Page Products WordPress plugin through 1.9 does not sanitise and escape a parameter before outputting it ba...
CVE-2024-13224MEDIUM6.1The SlideDeck 1 Lite Content Slider WordPress plugin through 1.4.8 does not sanitise and escape a parameter before outpu...
CVE-2024-13223MEDIUM6.1The Tabulate WordPress plugin through 2.10.3 does not sanitise and escape some parameters before outputting them back in...
CVE-2024-13222MEDIUM6.1The User Messages WordPress plugin through 1.2.4 does not sanitise and escape a parameter before outputting it back in t...
CVE-2024-13221MEDIUM6.1The Fantastic ElasticSearch WordPress plugin through 4.1.0 does not sanitise and escape a parameter before outputting it...
CVE-2024-13220MEDIUM6.1The WordPress Google Map Professional (Map In Your Language) WordPress plugin through 1.0 does not sanitise and escape a...
CVE-2024-13219MEDIUM6.1The Privacy Policy Genius WordPress plugin through 2.0.4 does not sanitise and escape a parameter before outputting it b...
CVE-2024-13218MEDIUM6.1The Fast Tube WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2024-13216MEDIUM4.3The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information ...
CVE-2024-13112MEDIUM6.1The WP MediaTagger WordPress plugin through 4.1.1 does not sanitise and escape a parameter before outputting it back in ...
CVE-2024-13101MEDIUM5.4The WP MediaTagger WordPress plugin through 4.1.1 does not validate and escape some of its shortcode attributes before o...
CVE-2024-13100MEDIUM6.1The OPSI Israel Domestic Shipments WordPress plugin through 2.6.3 does not sanitise and escape a parameter before output...
CVE-2024-12872MEDIUM4.8The Zalomení WordPress plugin through 1.5 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2024-12772MEDIUM5.4The Ninja Tables WordPress plugin before 5.0.17 does not sanitize and escape a parameter before outputting it back in t...
CVE-2024-12275MEDIUM6.1The Canvasflow for WordPress plugin through 1.5.5 does not sanitise and escape a parameter before outputting it back in ...
CVE-2024-11886MEDIUM6.4The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now