2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10591 | HIGH | 8.8 | 0.4% | Jan 30, 2025 | The MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics plugin for Word... |
| CVE-2024-13466 | MEDIUM | 6.4 | 0.3% | Jan 30, 2025 | The Automatically Hierarchic Categories in Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th... |
| CVE-2024-13380 | MEDIUM | 6.4 | 0.3% | Jan 30, 2025 | The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th... |
| CVE-2024-13706 | MEDIUM | 6.1 | 0.3% | Jan 30, 2025 | The WP Image Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'file' parameter in a... |
| CVE-2024-13453 | HIGH | 7.3 | 0.5% | Jan 30, 2025 | The The Contact Form & SMTP Plugin for WordPress by PirateForms plugin for WordPress is vulnerable to arbitrary shortcod... |
| CVE-2024-12524 | MEDIUM | 6.4 | 0.3% | Jan 30, 2025 | The Clinked Client Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'clinked-lo... |
| CVE-2024-12409 | MEDIUM | 6.1 | 0.3% | Jan 30, 2025 | The Simple:Press Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all... |
| CVE-2024-13758 | MEDIUM | 6.5 | 0.3% | Jan 30, 2025 | The CP Contact Form with PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, ... |
| CVE-2024-13732 | MEDIUM | 5.4 | 0.4% | Jan 30, 2025 | The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... |
| CVE-2024-13694 | HIGH | 7.5 | 0.6% | Jan 30, 2025 | The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is... |
| CVE-2024-13470 | MEDIUM | 5.4 | 0.3% | Jan 30, 2025 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2024-13642 | MEDIUM | 5.4 | 0.2% | Jan 30, 2025 | The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image... |
| CVE-2024-13457 | MEDIUM | 5.3 | 0.3% | Jan 30, 2025 | The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version... |
| CVE-2024-12921 | MEDIUM | 6.4 | 0.2% | Jan 30, 2025 | The EthereumICO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ethereum-ico shortcod... |
| CVE-2024-12709 | MEDIUM | 4.3 | 0.2% | Jan 30, 2025 | The Bulk Me Now! WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to m... |
| CVE-2024-12708 | HIGH | 7.1 | 0.3% | Jan 30, 2025 | The Bulk Me Now! WordPress plugin through 2.0 does not validate and escape some of its shortcode attributes before outpu... |
| CVE-2024-12638 | HIGH | 7.1 | 0.5% | Jan 30, 2025 | The Bulk Me Now! WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the ... |
| CVE-2024-12400 | HIGH | 7.1 | 0.3% | Jan 30, 2025 | The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leadin... |
| CVE-2024-12163 | MEDIUM | 6.5 | 0.3% | Jan 30, 2025 | The goodlayers-core WordPress plugin before 2.1.3 allows users with a subscriber role and above to upload SVGs containin... |
| CVE-2024-10309 | MEDIUM | 5.9 | 0.3% | Jan 30, 2025 | The Tracking Code Manager WordPress plugin before 2.4.0 does not sanitise and escape some of its metabox settings when o... |
| CVE-2024-57665 | CRITICAL | 9.8 | 0.5% | Jan 29, 2025 | JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java. The cause of the vulnerability... |
| CVE-2024-57513 | MEDIUM | 6.5 | 0.3% | Jan 29, 2025 | A floating-point exception (FPE) vulnerability exists in the AP4_TfraAtom::AP4_TfraAtom function in Bento4. |
| CVE-2024-57510 | HIGH | 7.8 | 0.2% | Jan 29, 2025 | Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to ex... |
| CVE-2024-57509 | HIGH | 7.8 | 0.2% | Jan 29, 2025 | Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to ex... |
| CVE-2024-57395 | CRITICAL | 9.8 | 0.7% | Jan 29, 2025 | Password Vulnerability in Safety production process management system v1.0 allows a remote attacker to escalate privileg... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now