2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13117 | MEDIUM | 6.5 | 0.5% | Jan 27, 2025 | The Social Share Buttons for WordPress plugin through 2.7 allows an unauthenticated user to upload arbitrary images and ... |
| CVE-2024-13116 | LOW | 3.8 | 0.3% | Jan 27, 2025 | The Crelly Slider WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2024-13095 | MEDIUM | 4.8 | 0.3% | Jan 27, 2025 | The WP Triggers Lite WordPress plugin through 2.5.3 does not sanitize and escape a parameter before using it in a SQL st... |
| CVE-2024-13094 | HIGH | 7.1 | 0.6% | Jan 27, 2025 | The WP Triggers Lite WordPress plugin through 2.5.3 does not sanitise and escape a parameter before outputting it back i... |
| CVE-2024-13057 | HIGH | 7.1 | 0.2% | Jan 27, 2025 | The Dyn Business Panel WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisati... |
| CVE-2024-13056 | HIGH | 7.1 | 0.3% | Jan 27, 2025 | The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back... |
| CVE-2024-13055 | HIGH | 7.1 | 0.5% | Jan 27, 2025 | The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back... |
| CVE-2024-13052 | HIGH | 7.1 | 0.3% | Jan 27, 2025 | The Dental Optimizer Patient Generator App WordPress plugin through 1.0 does not sanitise and escape a parameter before ... |
| CVE-2024-12774 | MEDIUM | 6.5 | 0.2% | Jan 27, 2025 | The Altra Side Menu WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers t... |
| CVE-2024-12773 | HIGH | 7.2 | 0.6% | Jan 27, 2025 | The Altra Side Menu WordPress plugin through 2.0 does not sanitize and escape a parameter before using it in a SQL state... |
| CVE-2024-12436 | MEDIUM | 4.3 | 0.2% | Jan 27, 2025 | The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF checks in some places, which could allow attacker... |
| CVE-2024-12321 | HIGH | 7.1 | 0.3% | Jan 27, 2025 | The WC Affiliate WordPress plugin through 2.3.9 does not sanitise and escape a parameter before outputting it back in t... |
| CVE-2024-12280 | MEDIUM | 4.3 | 0.2% | Jan 27, 2025 | The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which coul... |
| CVE-2024-28771 | MEDIUM | 6.5 | 0.2% | Jan 27, 2025 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attr... |
| CVE-2024-28770 | MEDIUM | 6.5 | 0.2% | Jan 27, 2025 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attr... |
| CVE-2024-28766 | HIGH | 7.5 | 0.3% | Jan 27, 2025 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive inf... |
| CVE-2024-31906 | MEDIUM | 6.2 | 0.2% | Jan 26, 2025 | IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the s... |
| CVE-2024-13505 | MEDIUM | 4.8 | 0.2% | Jan 26, 2025 | The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ays_sections[5][questions][8... |
| CVE-2024-12334 | MEDIUM | 6.1 | 0.3% | Jan 26, 2025 | The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Sc... |
| CVE-2024-11936 | HIGH | 8.8 | 0.4% | Jan 26, 2025 | The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalatio... |
| CVE-2024-11641 | HIGH | 8.8 | 0.3% | Jan 26, 2025 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio... |
| CVE-2024-46881 | HIGH | 7.1 | 0.3% | Jan 26, 2025 | Develocity (formerly Gradle Enterprise) before 2024.1.8 has Incorrect Access Control. Project-level access control confi... |
| CVE-2024-11090 | HIGH | 7.5 | 0.4% | Jan 26, 2025 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all ver... |
| CVE-2024-10705 | HIGH | 8.1 | 0.3% | Jan 26, 2025 | The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio... |
| CVE-2024-10636 | MEDIUM | 6.1 | 0.3% | Jan 26, 2025 | The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now