2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12435 | MEDIUM | 6.1 | 0.4% | Jan 7, 2025 | The Compare Products for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s_fea... |
| CVE-2024-12332 | MEDIUM | 6.5 | 0.4% | Jan 7, 2025 | The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter... |
| CVE-2024-12327 | MEDIUM | 4.3 | 0.3% | Jan 7, 2025 | The LazyLoad Background Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ... |
| CVE-2024-12324 | MEDIUM | 6.1 | 0.3% | Jan 7, 2025 | The Unilevel MLM Plan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in a... |
| CVE-2024-12322 | HIGH | 8.8 | 0.3% | Jan 7, 2025 | The ThePerfectWedding.nl Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, ... |
| CVE-2024-12313 | HIGH | 8.1 | 0.8% | Jan 7, 2025 | The Compare Products for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, a... |
| CVE-2024-12291 | MEDIUM | 6.1 | 0.2% | Jan 7, 2025 | The ViewMedica 9 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2024-12290 | MEDIUM | 6.1 | 0.4% | Jan 7, 2025 | The Infility Global plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘set_type’ parameter in... |
| CVE-2024-12288 | MEDIUM | 6.1 | 0.2% | Jan 7, 2025 | The Simple add pages or posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an... |
| CVE-2024-12264 | CRITICAL | 9.8 | 0.7% | Jan 7, 2025 | The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ... |
| CVE-2024-12256 | MEDIUM | 6.1 | 0.3% | Jan 7, 2025 | The Simple Video Management System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'analyti... |
| CVE-2024-12252 | CRITICAL | 9.8 | 3.1% | Jan 7, 2025 | The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing capability check on the remo... |
| CVE-2024-12214 | MEDIUM | 6.1 | 0.3% | Jan 7, 2025 | The WooCommerce HSS Extension for Streaming Video plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v... |
| CVE-2024-12208 | — | — | — | Jan 7, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-43269. Reason: This candidate is a ... |
| CVE-2024-12207 | MEDIUM | 4.4 | 0.3% | Jan 7, 2025 | The Toggles Shortcode and Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ par... |
| CVE-2024-12176 | MEDIUM | 5.3 | 0.3% | Jan 7, 2025 | The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to unauthorized access due to a missing capabi... |
| CVE-2024-12170 | MEDIUM | 5.4 | 0.2% | Jan 7, 2025 | The ViewMedica 9 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2024-12159 | MEDIUM | 5.3 | 0.4% | Jan 7, 2025 | The Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords plugin for WordPress is vulnerable to Inform... |
| CVE-2024-12158 | MEDIUM | 5.3 | 0.3% | Jan 7, 2025 | The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to unauthorized l... |
| CVE-2024-12157 | HIGH | 7.5 | 1.0% | Jan 7, 2025 | The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to SQL Injection ... |
| CVE-2024-12153 | MEDIUM | 6.1 | 0.4% | Jan 7, 2025 | The GDY Modular Content plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query... |
| CVE-2024-12140 | MEDIUM | 4.3 | 0.4% | Jan 7, 2025 | The Elementor Addons AI Addons – 70 Widgets, Premium Templates, Ultimate Elements plugin for WordPress is vulnerable to ... |
| CVE-2024-12126 | MEDIUM | 6.1 | 0.3% | Jan 7, 2025 | The SEO Keywords plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘google_error’ parameter i... |
| CVE-2024-12124 | — | — | — | Jan 7, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-54290. Reason: This candidate is a ... |
| CVE-2024-12049 | MEDIUM | 6.1 | 0.4% | Jan 7, 2025 | The Woo Ukrposhta plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order', 'post', and 'idd... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now