2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13670 | MEDIUM | 5.4 | 0.2% | Jan 30, 2025 | The Music Sheet Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pn_msv' short... |
| CVE-2024-13664 | MEDIUM | 5.4 | 0.2% | Jan 30, 2025 | The WP Post List Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpb_post_list... |
| CVE-2024-13661 | MEDIUM | 5.4 | 0.3% | Jan 30, 2025 | The Table Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wptableeditor_vtabs... |
| CVE-2024-13652 | MEDIUM | 4.3 | 0.3% | Jan 30, 2025 | The ECPay Ecommerce for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to a missing cap... |
| CVE-2024-13646 | HIGH | 8.1 | 0.4% | Jan 30, 2025 | The Single-user-chat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial o... |
| CVE-2024-13596 | MEDIUM | 6.5 | 0.3% | Jan 30, 2025 | The WordPress Survey & Poll – Quiz, Survey and Poll Plugin for WordPress plugin for WordPress is vulnerable to SQL Injec... |
| CVE-2024-13549 | MEDIUM | 5.4 | 0.2% | Jan 30, 2025 | The All Bootstrap Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Accordion" widget in... |
| CVE-2024-13512 | MEDIUM | 5.4 | 0.1% | Jan 30, 2025 | The Wonder FontAwesome plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2024-13460 | MEDIUM | 5.4 | 0.2% | Jan 30, 2025 | The WE – Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Testimonial Author Nam... |
| CVE-2024-13400 | MEDIUM | 5.4 | 0.2% | Jan 30, 2025 | The Kona Gallery Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Kona: Instagram for Gu... |
| CVE-2024-13349 | MEDIUM | 5.4 | 0.3% | Jan 30, 2025 | The Stockdio Historical Chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stockd... |
| CVE-2024-12861 | MEDIUM | 6.5 | 0.3% | Jan 30, 2025 | The W2S – Migrate WooCommerce to Shopify plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to... |
| CVE-2024-12822 | CRITICAL | 9.8 | 0.6% | Jan 30, 2025 | The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to p... |
| CVE-2024-12821 | MEDIUM | 6.5 | 0.3% | Jan 30, 2025 | The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to p... |
| CVE-2024-12451 | MEDIUM | 5.4 | 0.3% | Jan 30, 2025 | The HTML5 chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'HTML5CHAT' shortcode ... |
| CVE-2024-12444 | MEDIUM | 5.4 | 0.3% | Jan 30, 2025 | The WP Dispensary plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpd_menu' shortcod... |
| CVE-2024-12320 | MEDIUM | 6.1 | 0.3% | Jan 30, 2025 | The Team Rosters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in all ver... |
| CVE-2024-12299 | MEDIUM | 6.1 | 0.4% | Jan 30, 2025 | The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Filename parameter in ... |
| CVE-2024-12269 | HIGH | 7.5 | 0.6% | Jan 30, 2025 | The Safe Ai Malware Protection for WP plugin for WordPress is vulnerable to unauthorized access of data due to a missing... |
| CVE-2024-12177 | MEDIUM | 6.1 | 0.4% | Jan 30, 2025 | The Ai Image Alt Text Generator for WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pag... |
| CVE-2024-12129 | HIGH | 8.8 | 0.4% | Jan 30, 2025 | The Royal Core plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escala... |
| CVE-2024-12102 | MEDIUM | 4.3 | 0.3% | Jan 30, 2025 | The Typer Core plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.6 vi... |
| CVE-2024-11600 | HIGH | 7.2 | 1.3% | Jan 30, 2025 | The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable t... |
| CVE-2024-11583 | MEDIUM | 4.3 | 0.4% | Jan 30, 2025 | The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable t... |
| CVE-2024-10847 | MEDIUM | 5.4 | 0.3% | Jan 30, 2025 | The Storely theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all version... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now