2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11730 | MEDIUM | 6.5 | 0.4% | Dec 6, 2024 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'sor... |
| CVE-2024-11729 | MEDIUM | 6.5 | 0.6% | Dec 6, 2024 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'ser... |
| CVE-2024-10909 | MEDIUM | 6.3 | 0.4% | Dec 6, 2024 | The The Pojo Forms plugin for WordPress is vulnerable to arbitrary shortcode execution via form_preview_shortcode AJAX a... |
| CVE-2024-10681 | MEDIUM | 6.3 | 0.4% | Dec 6, 2024 | The The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPres... |
| CVE-2024-9872 | MEDIUM | 5.4 | 0.2% | Dec 6, 2024 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modif... |
| CVE-2024-9866 | MEDIUM | 5.4 | 0.3% | Dec 6, 2024 | The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' p... |
| CVE-2024-9706 | MEDIUM | 5.3 | 0.4% | Dec 6, 2024 | The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a ... |
| CVE-2024-9705 | MEDIUM | 4.3 | 0.3% | Dec 6, 2024 | The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a ... |
| CVE-2024-12110 | MEDIUM | 4.3 | 0.3% | Dec 6, 2024 | The Gold Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c... |
| CVE-2024-12060 | MEDIUM | 6.1 | 0.3% | Dec 6, 2024 | The WP Media Optimizer (.webp) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wpmowebp-cs... |
| CVE-2024-12028 | MEDIUM | 5.3 | 0.4% | Dec 6, 2024 | The Friends plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST ... |
| CVE-2024-12027 | MEDIUM | 4.3 | 0.3% | Dec 6, 2024 | The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a m... |
| CVE-2024-12003 | MEDIUM | 6.1 | 0.2% | Dec 6, 2024 | The WP System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1... |
| CVE-2024-11823 | MEDIUM | 6.1 | 0.3% | Dec 6, 2024 | The Folder Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'foldergallery' sh... |
| CVE-2024-11687 | MEDIUM | 6.1 | 0.3% | Dec 6, 2024 | The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th... |
| CVE-2024-11450 | MEDIUM | 6.4 | 0.2% | Dec 6, 2024 | The ONLYOFFICE Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'onlyoffice' shor... |
| CVE-2024-11444 | MEDIUM | 4.3 | 0.2% | Dec 6, 2024 | The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up ... |
| CVE-2024-11368 | MEDIUM | 6.1 | 0.4% | Dec 6, 2024 | The Splash Sync plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg wit... |
| CVE-2024-11352 | MEDIUM | 6.4 | 0.3% | Dec 6, 2024 | The TwentyTwenty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'twentytwenty' short... |
| CVE-2024-11339 | MEDIUM | 6.4 | 0.2% | Dec 6, 2024 | The Smart PopUp Blaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spb-button'... |
| CVE-2024-11336 | MEDIUM | 6.1 | 0.1% | Dec 6, 2024 | The Clickbank WordPress Plugin (Storefront) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers... |
| CVE-2024-11292 | MEDIUM | 5.3 | 0.4% | Dec 6, 2024 | The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ... |
| CVE-2024-11276 | MEDIUM | 6.1 | 0.3% | Dec 6, 2024 | The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to Reflected ... |
| CVE-2024-11204 | MEDIUM | 6.1 | 0.3% | Dec 6, 2024 | The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url... |
| CVE-2024-10879 | MEDIUM | 6.1 | 0.4% | Dec 6, 2024 | The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the u... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now