2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-55415MEDIUM5.7DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.
CVE-2024-53615MEDIUM6.5A command injection vulnerability in the video thumbnail rendering component of Karl Ward's files.gallery v0.3.0 through...
CVE-2024-8494MEDIUM6.5The Elementor Website Builder Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u...
CVE-2024-13742CRITICAL9.8The iControlWP – Multiple WordPress Site Manager plugin for WordPress is vulnerable to PHP Object Injection in all versi...
CVE-2024-13720CRITICAL9.1The WP Image Uploader plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valida...
CVE-2024-13715MEDIUM4.3The zStore Manager Basic plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability che...
CVE-2024-13707HIGH8.1The WP Image Uploader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2024-13705MEDIUM6.1The StageShow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg wi...
CVE-2024-13700MEDIUM5.4The Embed Swagger UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsgui' shortco...
CVE-2024-13671HIGH7.5The Music Sheet Viewer plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 4...
CVE-2024-13670MEDIUM5.4The Music Sheet Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pn_msv' short...
CVE-2024-13664MEDIUM5.4The WP Post List Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpb_post_list...
CVE-2024-13661MEDIUM5.4The Table Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wptableeditor_vtabs...
CVE-2024-13652MEDIUM4.3The ECPay Ecommerce for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to a missing cap...
CVE-2024-13646HIGH8.1The Single-user-chat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial o...
CVE-2024-13596MEDIUM6.5The WordPress Survey & Poll – Quiz, Survey and Poll Plugin for WordPress plugin for WordPress is vulnerable to SQL Injec...
CVE-2024-13549MEDIUM5.4The All Bootstrap Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Accordion" widget in...
CVE-2024-13512MEDIUM5.4The Wonder FontAwesome plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2024-13460MEDIUM5.4The WE – Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Testimonial Author Nam...
CVE-2024-13400MEDIUM5.4The Kona Gallery Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Kona: Instagram for Gu...
CVE-2024-13349MEDIUM5.4The Stockdio Historical Chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stockd...
CVE-2024-12861MEDIUM6.5The W2S – Migrate WooCommerce to Shopify plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to...
CVE-2024-12822CRITICAL9.8The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to p...
CVE-2024-12821MEDIUM6.5The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to p...
CVE-2024-12451MEDIUM5.4The HTML5 chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'HTML5CHAT' shortcode ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now