2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11382 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Common Ninja: Fully Customizable & Perfectly Responsive Free Widgets for WordPress Websites plugin for WordPress is ... |
| CVE-2024-11378 | MEDIUM | 6.1 | 0.3% | Jan 7, 2025 | The Bizapp for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'error' paramete... |
| CVE-2024-11377 | MEDIUM | 6.1 | 0.5% | Jan 7, 2025 | The Automate Hub Free by Sperse.IO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' par... |
| CVE-2024-11375 | MEDIUM | 6.1 | 0.3% | Jan 7, 2025 | The WC1C plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without ap... |
| CVE-2024-11363 | MEDIUM | 6.1 | 0.3% | Jan 7, 2025 | The Same but Different – Related Posts by Taxonomy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ... |
| CVE-2024-11338 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The PIXNET Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gtm' and 'venue' parameters... |
| CVE-2024-11337 | MEDIUM | 6.4 | 0.4% | Jan 7, 2025 | The Horoscope And Tarot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'divine_horos... |
| CVE-2024-11290 | MEDIUM | 5.3 | 0.4% | Jan 7, 2025 | The Member Access plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ... |
| CVE-2024-10527 | LOW | 3.1 | 0.3% | Jan 7, 2025 | The Spacer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the mo... |
| CVE-2024-12592 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Sellsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'testSellsy' shortcode in ... |
| CVE-2024-12590 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The WP Youtube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all v... |
| CVE-2024-12559 | MEDIUM | 5.3 | 0.4% | Jan 7, 2025 | The ClickDesigns plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che... |
| CVE-2024-12557 | MEDIUM | 6.1 | 0.2% | Jan 7, 2025 | The Transporters.io plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2024-12541 | MEDIUM | 5.4 | 0.2% | Jan 7, 2025 | The Chative Live chat and Chatbot plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to... |
| CVE-2024-12540 | — | — | — | Jan 7, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-54288. Reason: This candidate is a ... |
| CVE-2024-12538 | MEDIUM | 4.3 | 0.3% | Jan 7, 2025 | The Duplicate Post, Page and Any Custom Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all... |
| CVE-2024-12528 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The WordPress Survey & Poll – Quiz, Survey and Poll Plugin for WordPress plugin for WordPress is vulnerable to Stored Cr... |
| CVE-2024-12419 | MEDIUM | 6.5 | 0.4% | Jan 7, 2025 | The The Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler plugin for WordPress is vulnerable to arbitrar... |
| CVE-2024-12416 | HIGH | 7.5 | 0.4% | Jan 7, 2025 | The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to SQL Injection via the 'woom... |
| CVE-2024-12402 | CRITICAL | 9.8 | 0.6% | Jan 7, 2025 | The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is vulnerable to privilege e... |
| CVE-2024-12098 | MEDIUM | 6.1 | 0.3% | Jan 7, 2025 | The ARS Affiliate Page Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'utm_keyword'... |
| CVE-2024-12022 | — | — | — | Jan 7, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-52485. Reason: This candidate is a ... |
| CVE-2024-11934 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cr... |
| CVE-2024-11899 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Slider Pro Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sliderpro' short... |
| CVE-2024-11777 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Sell Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sell_media_search_for... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now