2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-35113MEDIUM6.5IBM Control Center 6.2.1 and 6.3.1 could allow an authenticated user to obtain sensitive information exposed through...
CVE-2024-35112MEDIUM4.3IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed techn...
CVE-2024-35111MEDIUM4.3IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technic...
CVE-2024-13562HIGH7.5The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Informa...
CVE-2024-13450MEDIUM6.5The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil...
CVE-2024-13449MEDIUM4.3The Boom Fest plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ...
CVE-2024-13599MEDIUM5.4The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions ...
CVE-2024-13586MEDIUM5.4The Masy Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'justified-gallery' ...
CVE-2024-13551MEDIUM5.4The ABC Notation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'abcjs' shortcode in...
CVE-2024-13550MEDIUM6.5The ABC Notation plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.1.3 via th...
CVE-2024-13548MEDIUM5.4The Power Ups for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'magic-bu...
CVE-2024-13467MEDIUM6.1The WP Contact Form7 Email Spam Blocker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'po...
CVE-2024-13458MEDIUM5.4The WordPress SEO Friendly Accordion FAQ with AI assisted content generation plugin for WordPress is vulnerable to Store...
CVE-2024-13441MEDIUM5.4The Bilingual Linker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bl_otherlang_link_1 param...
CVE-2024-13370MEDIUM6.5The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress ...
CVE-2024-13368MEDIUM4.3The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress ...
CVE-2024-12885MEDIUM6.5The Connections Business Directory plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficien...
CVE-2024-12826MEDIUM4.3The GoHero Store Customizer for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due ...
CVE-2024-12817MEDIUM6.4The Etsy Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'product_link' shor...
CVE-2024-12816MEDIUM6.4The NOTICE BOARD BY TOWKIR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'notice-bo...
CVE-2024-12529MEDIUM6.4The brodos.net Onlineshop Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Bro...
CVE-2024-12512MEDIUM6.4The Ask Me Anything (Anonymously) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'as...
CVE-2024-12113MEDIUM4.3The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress ...
CVE-2024-12076MEDIUM6.1The Target Video Easy Publish plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an...
CVE-2024-11825MEDIUM6.4The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘zone’ parameter in all versio...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now