2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12697MEDIUM6.4The real.Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1...
CVE-2024-12635MEDIUM6.5The WP Docs plugin for WordPress is vulnerable to time-based SQL Injection via the 'dir_id' parameter in all versions up...
CVE-2024-12262MEDIUM6.1The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'step' parameter in all ver...
CVE-2024-12066HIGH8.8The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path ...
CVE-2024-11975MEDIUM6.1The Reactflow Visitor Recording and Heatmaps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th...
CVE-2024-11938MEDIUM6.4The One Click Upsell Funnel for WooCommerce – Funnel Builder for WordPress, Create WooCommerce Upsell, Post-Purchase Up...
CVE-2024-11682MEDIUM6.1The G Web Pro Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'q' parameter i...
CVE-2024-11287MEDIUM6.1The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg wit...
CVE-2024-11196MEDIUM6.4The Multi-column Tag Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mctagmap sho...
CVE-2024-11977HIGH7.3The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode e...
CVE-2024-11607MEDIUM6.1The GTPayment Donations WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisat...
CVE-2024-12846MEDIUM4.8A vulnerability, which was classified as problematic, has been found in Emlog Pro up to 2.4.1. Affected by this issue is...
CVE-2024-11349CRITICAL9.8The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. Thi...
CVE-2024-11811MEDIUM6.1The Feedify – Web Push Notifications plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'platf...
CVE-2024-12845MEDIUM6.1A vulnerability classified as problematic was found in Emlog Pro up to 2.4.1. Affected by this vulnerability is an unkno...
CVE-2024-56359MEDIUM6.1grist-core is a spreadsheet hosting server. A user visiting a malicious document and clicking on a link in a HyperLink c...
CVE-2024-56358MEDIUM6.1grist-core is a spreadsheet hosting server. A user visiting a malicious document and previewing an attachment could have...
CVE-2024-56357MEDIUM6.1grist-core is a spreadsheet hosting server. A user visiting a malicious document or submitting a malicious form could ha...
CVE-2024-56335HIGH7.5vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected ve...
CVE-2024-56334HIGH7.8systeminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when ...
CVE-2024-55509CRITICAL9.8SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary...
CVE-2024-40875MEDIUM5.9There is a cross-site scripting vulnerability in the management console of Absolute Secure Access prior to version 13.52...
CVE-2024-12844MEDIUM6.1A vulnerability classified as problematic has been found in Emlog Pro up to 2.4.1. Affected is an unknown function of th...
CVE-2024-12843MEDIUM6.1A vulnerability was found in Emlog Pro up to 2.4.1. It has been rated as problematic. This issue affects some unknown pr...
CVE-2024-56333CRITICAL9.4Onyxia is a web app that aims at being the glue between multiple open source backend technologies to provide a state of ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now