2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12633 | HIGH | 7.1 | 0.3% | Jan 7, 2025 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Reflected Cross... |
| CVE-2024-12535 | HIGH | 8.6 | 0.6% | Jan 7, 2025 | The Host PHP Info plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check wh... |
| CVE-2024-12471 | HIGH | 8.8 | 1.5% | Jan 7, 2025 | The Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator plugin for WordPress is... |
| CVE-2024-12464 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Chatroll Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'chatroll' sho... |
| CVE-2024-12440 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Candifly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'candifly' shortcode in ... |
| CVE-2024-12439 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Marketplace Items plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'marketplace' s... |
| CVE-2024-12438 | MEDIUM | 6.1 | 0.4% | Jan 7, 2025 | The WooCommerce Digital Content Delivery (incl. DRM) – FlickRocket plugin for WordPress is vulnerable to Reflected Cross... |
| CVE-2024-12384 | MEDIUM | 6.1 | 0.3% | Jan 7, 2025 | The Binary MLM Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page’ parameter... |
| CVE-2024-12383 | MEDIUM | 6.1 | 0.2% | Jan 7, 2025 | The Binary MLM Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2024-12261 | MEDIUM | 6.1 | 0.4% | Jan 7, 2025 | The SmartEmailing.cz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'se-lists-updated' par... |
| CVE-2024-12073 | MEDIUM | 5.4 | 0.2% | Jan 7, 2025 | The Meteor Slides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slide_url_value' parameter ... |
| CVE-2024-11887 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Geo Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'geotargetlygeoconten... |
| CVE-2024-11756 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The SweepWidget Contests, Giveaways, Photo Contests, Competitions plugin for WordPress is vulnerable to Stored Cross-Sit... |
| CVE-2024-11749 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The App Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'appizy' shortcode in a... |
| CVE-2024-11606 | MEDIUM | 5.3 | 0.5% | Jan 7, 2025 | The Tabs Shortcode WordPress plugin through 2.0.2 does not validate and escape some of its shortcode attributes before o... |
| CVE-2024-11369 | MEDIUM | 6.1 | 0.4% | Jan 7, 2025 | The Store credit / Gift cards for woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t... |
| CVE-2024-10562 | LOW | 2.7 | 0.4% | Jan 7, 2025 | The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its settings, which could ... |
| CVE-2024-10536 | MEDIUM | 4.3 | 0.3% | Jan 7, 2025 | The FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor plugin for Word... |
| CVE-2024-10102 | LOW | 2.7 | 0.5% | Jan 7, 2025 | The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some ... |
| CVE-2024-9208 | MEDIUM | 6.1 | 0.3% | Jan 7, 2025 | The Enable Accessibility plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_quer... |
| CVE-2024-12470 | CRITICAL | 9.8 | 0.6% | Jan 7, 2025 | The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege escalation in all versions up to... |
| CVE-2024-12462 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The YOGO Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yogo-calendar' shor... |
| CVE-2024-12457 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode plugin for WordPress is ... |
| CVE-2024-12453 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Uptodown APK Download Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'utd... |
| CVE-2024-12445 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The RightMessage WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rm_area' shortco... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now