2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10453MEDIUM5.4The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2024-9545MEDIUM5.4The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2024-12588MEDIUM5.4The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2024-11808MEDIUM6.1The Pingmeter Uptime Monitoring plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_wpnonce' ...
CVE-2024-10797MEDIUM4.3The Full Screen Menu for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and...
CVE-2024-12771HIGH8.8The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in a...
CVE-2024-12721HIGH7.2The Custom Product Tabs For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to...
CVE-2024-12697MEDIUM6.4The real.Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1...
CVE-2024-12635MEDIUM6.5The WP Docs plugin for WordPress is vulnerable to time-based SQL Injection via the 'dir_id' parameter in all versions up...
CVE-2024-12262MEDIUM6.1The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'step' parameter in all ver...
CVE-2024-12066HIGH8.8The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path ...
CVE-2024-11975MEDIUM6.1The Reactflow Visitor Recording and Heatmaps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th...
CVE-2024-11938MEDIUM6.4The One Click Upsell Funnel for WooCommerce – Funnel Builder for WordPress, Create WooCommerce Upsell, Post-Purchase Up...
CVE-2024-11682MEDIUM6.1The G Web Pro Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'q' parameter i...
CVE-2024-11287MEDIUM6.1The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg wit...
CVE-2024-11196MEDIUM6.4The Multi-column Tag Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mctagmap sho...
CVE-2024-11977HIGH7.3The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode e...
CVE-2024-11607MEDIUM6.1The GTPayment Donations WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisat...
CVE-2024-12846MEDIUM4.8A vulnerability, which was classified as problematic, has been found in Emlog Pro up to 2.4.1. Affected by this issue is...
CVE-2024-11349CRITICAL9.8The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. Thi...
CVE-2024-11811MEDIUM6.1The Feedify – Web Push Notifications plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'platf...
CVE-2024-12845MEDIUM6.1A vulnerability classified as problematic was found in Emlog Pro up to 2.4.1. Affected by this vulnerability is an unkno...
CVE-2024-56359MEDIUM6.1grist-core is a spreadsheet hosting server. A user visiting a malicious document and clicking on a link in a HyperLink c...
CVE-2024-56358MEDIUM6.1grist-core is a spreadsheet hosting server. A user visiting a malicious document and previewing an attachment could have...
CVE-2024-56357MEDIUM6.1grist-core is a spreadsheet hosting server. A user visiting a malicious document or submitting a malicious form could ha...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now