2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5769 | MEDIUM | 4.3 | 0.4% | Jan 9, 2025 | The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2024-12848 | HIGH | 8.8 | 0.9% | Jan 9, 2025 | The SKT Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on t... |
| CVE-2024-12819 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The Searchie plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sio_embed_media' shortc... |
| CVE-2024-12621 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The Yumpu E-Paper publishing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'YUMPU' ... |
| CVE-2024-12618 | MEDIUM | 4.3 | 0.3% | Jan 9, 2025 | The Newsletter2Go plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch... |
| CVE-2024-12616 | MEDIUM | 4.3 | 0.3% | Jan 9, 2025 | The Bitly's WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2024-12605 | MEDIUM | 4.3 | 0.2% | Jan 9, 2025 | The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin Ch... |
| CVE-2024-12542 | HIGH | 8.6 | 1.3% | Jan 9, 2025 | The linkID plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when incl... |
| CVE-2024-12515 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The Muslim Prayer Time-Salah/Iqamah plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Masjid ID ... |
| CVE-2024-12514 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The 3DVieweronline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '3Dvo-model' short... |
| CVE-2024-12496 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The Linear plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linear_block_buy_commissi... |
| CVE-2024-12493 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The Files Download Delay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fddwrap' sh... |
| CVE-2024-12491 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The SimplyRETS Real Estate IDX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sr_se... |
| CVE-2024-12394 | MEDIUM | 6.1 | 0.3% | Jan 9, 2025 | The Action Network plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all ... |
| CVE-2024-12330 | HIGH | 7.5 | 0.5% | Jan 9, 2025 | The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to Sensit... |
| CVE-2024-12285 | MEDIUM | 6.1 | 0.4% | Jan 9, 2025 | The SEMA API plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘catid’ parameter in all versi... |
| CVE-2024-12249 | MEDIUM | 4.3 | 0.3% | Jan 9, 2025 | The GS Insever Portfolio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi... |
| CVE-2024-12222 | MEDIUM | 6.1 | 0.4% | Jan 9, 2025 | The Deliver via Shipos for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dvs... |
| CVE-2024-12218 | MEDIUM | 6.1 | 0.2% | Jan 9, 2025 | The Woocommerce check pincode/zipcode for shipping plugin for WordPress is vulnerable to Cross-Site Request Forgery in a... |
| CVE-2024-12206 | MEDIUM | 4.3 | 0.2% | Jan 9, 2025 | The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers... |
| CVE-2024-12122 | MEDIUM | 6.1 | 0.3% | Jan 9, 2025 | The ResAds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions ... |
| CVE-2024-12067 | MEDIUM | 6.5 | 0.5% | Jan 9, 2025 | The WP Travel – Ultimate Travel Booking System, Tour Management Engine plugin for WordPress is vulnerable to SQL Injecti... |
| CVE-2024-11929 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The Responsive FlipBook Plugin Wordpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the rfbwp... |
| CVE-2024-11907 | MEDIUM | 6.4 | 0.4% | Jan 9, 2025 | The Skyword API Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skyword_ifram... |
| CVE-2024-11815 | MEDIUM | 6.1 | 0.4% | Jan 9, 2025 | The Pósturinn\'s Shipping with WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now