2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13221MEDIUM6.1The Fantastic ElasticSearch WordPress plugin through 4.1.0 does not sanitise and escape a parameter before outputting it...
CVE-2024-13220MEDIUM6.1The WordPress Google Map Professional (Map In Your Language) WordPress plugin through 1.0 does not sanitise and escape a...
CVE-2024-13219MEDIUM6.1The Privacy Policy Genius WordPress plugin through 2.0.4 does not sanitise and escape a parameter before outputting it b...
CVE-2024-13218MEDIUM6.1The Fast Tube WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2024-13216MEDIUM4.3The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information ...
CVE-2024-13112MEDIUM6.1The WP MediaTagger WordPress plugin through 4.1.1 does not sanitise and escape a parameter before outputting it back in ...
CVE-2024-13101MEDIUM5.4The WP MediaTagger WordPress plugin through 4.1.1 does not validate and escape some of its shortcode attributes before o...
CVE-2024-13100MEDIUM6.1The OPSI Israel Domestic Shipments WordPress plugin through 2.6.3 does not sanitise and escape a parameter before output...
CVE-2024-12872MEDIUM4.8The Zalomení WordPress plugin through 1.5 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2024-12772MEDIUM5.4The Ninja Tables WordPress plugin before 5.0.17 does not sanitize and escape a parameter before outputting it back in t...
CVE-2024-12275MEDIUM6.1The Canvasflow for WordPress plugin through 1.5.5 does not sanitise and escape a parameter before outputting it back in ...
CVE-2024-11886MEDIUM6.4The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
CVE-2024-10867MEDIUM5.4The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable t...
CVE-2024-47900HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to access OOB kernel memory.
CVE-2024-47899HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern...
CVE-2024-47898HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern...
CVE-2024-47891HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern...
CVE-2024-13463MEDIUM6.4The SeatReg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'seatreg' shortcode in al...
CVE-2024-46974HIGH7.8Software installed and run as a non-privileged user may conduct improper read/write operations on imported/exported DMA ...
CVE-2024-13817——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2024-13767HIGH8.1The Live2DWebCanvas plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validati...
CVE-2024-13399MEDIUM6.4The Gosign – Posts Slider Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'posts-slider-...
CVE-2024-13397MEDIUM6.4The WPRadio – WordPress Radio Streaming Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-13396MEDIUM6.4The Frictionless plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'frictionless_form' ...
CVE-2024-23929HIGH7.3This vulnerability allows network-adjacent attackers to create arbitrary files on affected installations of Pioneer DMH-...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now