2024 CVE Vulnerabilities

39,224 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12519MEDIUM6.4The TCBD Auto Refresher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbd_auto_re...
CVE-2024-12412MEDIUM6.1The Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | WordPress plugin p...
CVE-2024-12407MEDIUM6.1The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t...
CVE-2024-12116MEDIUM4.3The Unlimited Theme Addon For Elementor and WooCommerce plugin for WordPress is vulnerable to Information Exposure in al...
CVE-2024-11915MEDIUM4.3The RRAddons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and includi...
CVE-2024-11892MEDIUM6.4The Accordion Slider Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'accordion_...
CVE-2024-11874MEDIUM6.4The Grid Accordion Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'grid_accordi...
CVE-2024-11758MEDIUM6.4The WP SPID Italia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all v...
CVE-2024-11386MEDIUM6.4The GatorMail SmartForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gatormailsm...
CVE-2024-42174LOW3.7HCL MyXalytics is affected by username enumeration vulnerability. This allows a malicious user to perform enumeration o...
CVE-2024-42173MEDIUM4.8HCL MyXalytics is affected by an improper password policy implementation vulnerability. Weak passwords and lack of acco...
CVE-2024-42172CRITICAL9.8HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tok...
CVE-2024-42171MEDIUM6.4HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URL...
CVE-2024-42170MEDIUM6.8HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URL...
CVE-2024-12587MEDIUM6.1The Contact Form Master WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it ba...
CVE-2024-12304MEDIUM5.4The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si...
CVE-2024-42169HIGH8.1HCL MyXalytics is affected by insecure direct object references. It occurs due to missing access control checks, which ...
CVE-2024-42168CRITICAL9.4HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can deploy a web server that ...
CVE-2024-12627HIGH7.5The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulne...
CVE-2024-12505MEDIUM6.4The Trackserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tsmap' shortcode in ...
CVE-2024-12472MEDIUM4.3The Post Duplicator plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.3...
CVE-2024-12404HIGH7.5The CF Internal Link Shortcode plugin for WordPress is vulnerable to SQL Injection via the 'post_title' parameter in all...
CVE-2024-12204MEDIUM5.4The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulne...
CVE-2024-11327MEDIUM6.1The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is...
CVE-2024-9188HIGH8.8Specially constructed queries cause cross platform scripting leaking administrator tokens

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now