2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-10802MEDIUM5.3The Hash Elements plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on...
CVE-2024-10794MEDIUM4.3The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to Information Exposure in all versi...
CVE-2024-11143MEDIUM4.3The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up ...
CVE-2024-10882MEDIUM6.1The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting du...
CVE-2024-10684MEDIUM6.1The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dir' p...
CVE-2024-10593MEDIUM4.3The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vu...
CVE-2024-10531MEDIUM4.3The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2024-10530MEDIUM4.3The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2024-10529MEDIUM5.3The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2024-9614MEDIUM6.1The Constant Contact Forms by MailMunch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the ...
CVE-2024-9578MEDIUM5.3The Hide Links plugin for WordPress is vulnerable to unauthorized shortcode execution due to do_shortcode being hooked t...
CVE-2024-9426MEDIUM6.4The Aqua SVG Sprite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio...
CVE-2024-8985MEDIUM6.4The Social Proof (Testimonial) Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
CVE-2024-8874MEDIUM6.1The AJAX Login and Registration modal popup + inline form plugin for WordPress is vulnerable to Reflected Cross-Site Scr...
CVE-2024-38654MEDIUM4.4Improper bounds checking in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker with...
CVE-2024-29211MEDIUM4.7A race condition in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to modify se...
CVE-2024-10887MEDIUM6.4The NiceJob plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes (ni...
CVE-2024-10854MEDIUM4.3The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c...
CVE-2024-10853MEDIUM4.3The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c...
CVE-2024-10852MEDIUM4.3The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil...
CVE-2024-10851MEDIUM6.1The Razorpay Payment Button Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o...
CVE-2024-10850MEDIUM6.1The Razorpay Payment Button Elementor Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to...
CVE-2024-10778MEDIUM4.3The BuddyPress Builder for Elementor – BuddyBuilder plugin for WordPress is vulnerable to Information Exposure in all ve...
CVE-2024-10717MEDIUM6.5The Styler for Ninja Forms plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a de...
CVE-2024-10577MEDIUM6.1The 胖鼠采集(Fat Rat Collect) 微信知乎简书腾讯新闻列表分页采集, 还有自动采集、自动发布、自动标签、等多项功能。开源插件 plugin for WordPress is vulnerable to Reflected ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now