2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10591HIGH8.8The MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics plugin for Word...
CVE-2024-13466MEDIUM6.4The Automatically Hierarchic Categories in Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2024-13380MEDIUM6.4The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2024-13706MEDIUM6.1The WP Image Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'file' parameter in a...
CVE-2024-13453HIGH7.3The The Contact Form & SMTP Plugin for WordPress by PirateForms plugin for WordPress is vulnerable to arbitrary shortcod...
CVE-2024-12524MEDIUM6.4The Clinked Client Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'clinked-lo...
CVE-2024-12409MEDIUM6.1The Simple:Press Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all...
CVE-2024-13758MEDIUM6.5The CP Contact Form with PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, ...
CVE-2024-13732MEDIUM5.4The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
CVE-2024-13694HIGH7.5The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is...
CVE-2024-13470MEDIUM5.4The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2024-13642MEDIUM5.4The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image...
CVE-2024-13457MEDIUM5.3The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version...
CVE-2024-12921MEDIUM6.4The EthereumICO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ethereum-ico shortcod...
CVE-2024-12709MEDIUM4.3The Bulk Me Now! WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to m...
CVE-2024-12708HIGH7.1The Bulk Me Now! WordPress plugin through 2.0 does not validate and escape some of its shortcode attributes before outpu...
CVE-2024-12638HIGH7.1The Bulk Me Now! WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the ...
CVE-2024-12400HIGH7.1The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leadin...
CVE-2024-12163MEDIUM6.5The goodlayers-core WordPress plugin before 2.1.3 allows users with a subscriber role and above to upload SVGs containin...
CVE-2024-10309MEDIUM5.9The Tracking Code Manager WordPress plugin before 2.4.0 does not sanitise and escape some of its metabox settings when o...
CVE-2024-57665CRITICAL9.8JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java. The cause of the vulnerability...
CVE-2024-57513MEDIUM6.5A floating-point exception (FPE) vulnerability exists in the AP4_TfraAtom::AP4_TfraAtom function in Bento4.
CVE-2024-57510HIGH7.8Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to ex...
CVE-2024-57509HIGH7.8Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to ex...
CVE-2024-57395CRITICAL9.8Password Vulnerability in Safety production process management system v1.0 allows a remote attacker to escalate privileg...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now