2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13117MEDIUM6.5The Social Share Buttons for WordPress plugin through 2.7 allows an unauthenticated user to upload arbitrary images and ...
CVE-2024-13116LOW3.8The Crelly Slider WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-13095MEDIUM4.8The WP Triggers Lite WordPress plugin through 2.5.3 does not sanitize and escape a parameter before using it in a SQL st...
CVE-2024-13094HIGH7.1The WP Triggers Lite WordPress plugin through 2.5.3 does not sanitise and escape a parameter before outputting it back i...
CVE-2024-13057HIGH7.1The Dyn Business Panel WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisati...
CVE-2024-13056HIGH7.1The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back...
CVE-2024-13055HIGH7.1The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back...
CVE-2024-13052HIGH7.1The Dental Optimizer Patient Generator App WordPress plugin through 1.0 does not sanitise and escape a parameter before ...
CVE-2024-12774MEDIUM6.5The Altra Side Menu WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers t...
CVE-2024-12773HIGH7.2The Altra Side Menu WordPress plugin through 2.0 does not sanitize and escape a parameter before using it in a SQL state...
CVE-2024-12436MEDIUM4.3The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF checks in some places, which could allow attacker...
CVE-2024-12321HIGH7.1The WC Affiliate WordPress plugin through 2.3.9 does not sanitise and escape a parameter before outputting it back in t...
CVE-2024-12280MEDIUM4.3The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which coul...
CVE-2024-28771MEDIUM6.5IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attr...
CVE-2024-28770MEDIUM6.5IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attr...
CVE-2024-28766HIGH7.5IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive inf...
CVE-2024-31906MEDIUM6.2IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the s...
CVE-2024-13505MEDIUM4.8The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ays_sections[5][questions][8...
CVE-2024-12334MEDIUM6.1The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Sc...
CVE-2024-11936HIGH8.8The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalatio...
CVE-2024-11641HIGH8.8The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio...
CVE-2024-46881HIGH7.1Develocity (formerly Gradle Enterprise) before 2024.1.8 has Incorrect Access Control. Project-level access control confi...
CVE-2024-11090HIGH7.5The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all ver...
CVE-2024-10705HIGH8.1The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio...
CVE-2024-10636MEDIUM6.1The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now