2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12435MEDIUM6.1The Compare Products for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s_fea...
CVE-2024-12332MEDIUM6.5The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter...
CVE-2024-12327MEDIUM4.3The LazyLoad Background Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ...
CVE-2024-12324MEDIUM6.1The Unilevel MLM Plan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in a...
CVE-2024-12322HIGH8.8The ThePerfectWedding.nl Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, ...
CVE-2024-12313HIGH8.1The Compare Products for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, a...
CVE-2024-12291MEDIUM6.1The ViewMedica 9 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2024-12290MEDIUM6.1The Infility Global plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘set_type’ parameter in...
CVE-2024-12288MEDIUM6.1The Simple add pages or posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an...
CVE-2024-12264CRITICAL9.8The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ...
CVE-2024-12256MEDIUM6.1The Simple Video Management System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'analyti...
CVE-2024-12252CRITICAL9.8The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing capability check on the remo...
CVE-2024-12214MEDIUM6.1The WooCommerce HSS Extension for Streaming Video plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v...
CVE-2024-12208——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-43269. Reason: This candidate is a ...
CVE-2024-12207MEDIUM4.4The Toggles Shortcode and Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ par...
CVE-2024-12176MEDIUM5.3The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to unauthorized access due to a missing capabi...
CVE-2024-12170MEDIUM5.4The ViewMedica 9 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2024-12159MEDIUM5.3The Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords plugin for WordPress is vulnerable to Inform...
CVE-2024-12158MEDIUM5.3The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to unauthorized l...
CVE-2024-12157HIGH7.5The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to SQL Injection ...
CVE-2024-12153MEDIUM6.1The GDY Modular Content plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query...
CVE-2024-12140MEDIUM4.3The Elementor Addons AI Addons – 70 Widgets, Premium Templates, Ultimate Elements plugin for WordPress is vulnerable to ...
CVE-2024-12126MEDIUM6.1The SEO Keywords plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘google_error’ parameter i...
CVE-2024-12124——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-54290. Reason: This candidate is a ...
CVE-2024-12049MEDIUM6.1The Woo Ukrposhta plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order', 'post', and 'idd...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now