2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-11447MEDIUM6.1The Community by PeepSo – Download from PeepSo.com plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ...
CVE-2024-11440MEDIUM6.4The Grey Owl Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gol_button' sh...
CVE-2024-11438MEDIUM6.4The StreamWeasels Online Status Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '...
CVE-2024-11435MEDIUM6.1The salavat counter Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter...
CVE-2024-11432MEDIUM6.4The SuevaFree Essential Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'counter'...
CVE-2024-11428MEDIUM6.4The Lazy load videos and sticky control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2024-11424MEDIUM6.4The Slick Sitemap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slick-sitemap' sho...
CVE-2024-11416MEDIUM6.1The WIP Incoming Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2024-11414MEDIUM6.4The RecipePress Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipe Ingredients in all...
CVE-2024-11412MEDIUM6.4The Shine PDF Embeder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shinepdf' shor...
CVE-2024-11388MEDIUM5.4The Dino Game – Embed Google Chrome Dinosaur Game in WordPress plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2024-11385MEDIUM5.4The Pure CSS Circle Progress bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cir...
CVE-2024-11371MEDIUM6.1The Theater for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_que...
CVE-2024-11370MEDIUM6.1The Subaccounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of a...
CVE-2024-11365MEDIUM6.1The Crypto and DeFi Widgets – Web3 Cryptocurrency Shortcodes plugin for WordPress is vulnerable to Reflected Cross-Site ...
CVE-2024-11360MEDIUM6.1The Page Parts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg w...
CVE-2024-11354MEDIUM4.3The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized modification of...
CVE-2024-11334MEDIUM5.3The My Contador lesr plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check...
CVE-2024-11197MEDIUM4.2The Lock User Account plugin for WordPress is vulnerable to user lock bypass in all versions up to, and including, 1.0.5...
CVE-2024-10890MEDIUM6.1The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o...
CVE-2024-10796MEDIUM4.3The If-So Dynamic Content Personalization plugin for WordPress is vulnerable to Information Exposure in all versions up ...
CVE-2024-10792MEDIUM6.1The Easiest Funnel Builder For WordPress & WooCommerce by WPFunnels plugin for WordPress is vulnerable to Reflected Cros...
CVE-2024-10785MEDIUM5.4The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si...
CVE-2024-10782MEDIUM4.3The Theme Builder For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and in...
CVE-2024-10726MEDIUM6.1The Friendly Functions for Welcart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now