2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-45070MEDIUM5.5in OpenHarmony v4.1.2 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
CVE-2024-12516MEDIUM6.4The Coupon Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Coupon Code' parameter in a...
CVE-2024-12202HIGH8.8The Croma Music plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escal...
CVE-2024-12077MEDIUM6.1The Booking Calendar and Booking Calendar Pro plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via...
CVE-2024-11627HIGH8.1: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Site...
CVE-2024-11626MEDIUM4.8Improper Neutralization of Input During CMS Backend (adminstrative section) Web Page Generation (XSS or 'Cross-site Scri...
CVE-2024-11625MEDIUM5.3Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affec...
CVE-2024-10866MEDIUM5.3The Export Import Menus plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch...
CVE-2024-9502MEDIUM5.4The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for ...
CVE-2024-9354MEDIUM6.1The Estatik Mortgage Calculator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'color' par...
CVE-2024-12781MEDIUM4.3The Aurum - WordPress & WooCommerce Shopping Theme theme for WordPress is vulnerable to unauthorized modification of dat...
CVE-2024-12624MEDIUM5.4The Sina Extension for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sina...
CVE-2024-12499MEDIUM6.4The WP jQuery DataTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_jdt' shor...
CVE-2024-12495MEDIUM6.4The Bootstrap Blocks for WP Editor v2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gtb-boo...
CVE-2024-12437MEDIUM6.4The Marketplace Items plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'envato' shortc...
CVE-2024-11764MEDIUM6.4The Solar Wizard Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'solar_wizard' ...
CVE-2024-11725HIGH8.8The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data ...
CVE-2024-11282HIGH7.5The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure i...
CVE-2024-9702MEDIUM5.4The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2024-9697MEDIUM5.3The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to...
CVE-2024-9638MEDIUM4.8The Category Posts Widget WordPress plugin before 4.9.18 does not sanitise and escape some of its settings, which could ...
CVE-2024-8857MEDIUM4.8The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could...
CVE-2024-8855CRITICAL9.8The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a parameter before using it in a ...
CVE-2024-7696MEDIUM6.3Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for an authenticated mal...
CVE-2024-12849HIGH7.5The Error Log Viewer By WP Guru plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and inc...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now