2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10453 | MEDIUM | 5.4 | 0.3% | Dec 21, 2024 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2024-9545 | MEDIUM | 5.4 | 0.3% | Dec 21, 2024 | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2024-12588 | MEDIUM | 5.4 | 0.2% | Dec 21, 2024 | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2024-11808 | MEDIUM | 6.1 | 0.3% | Dec 21, 2024 | The Pingmeter Uptime Monitoring plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_wpnonce' ... |
| CVE-2024-10797 | MEDIUM | 4.3 | 0.3% | Dec 21, 2024 | The Full Screen Menu for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and... |
| CVE-2024-12771 | HIGH | 8.8 | 0.3% | Dec 21, 2024 | The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in a... |
| CVE-2024-12721 | HIGH | 7.2 | 0.7% | Dec 21, 2024 | The Custom Product Tabs For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to... |
| CVE-2024-12697 | MEDIUM | 6.4 | 0.3% | Dec 21, 2024 | The real.Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1... |
| CVE-2024-12635 | MEDIUM | 6.5 | 0.4% | Dec 21, 2024 | The WP Docs plugin for WordPress is vulnerable to time-based SQL Injection via the 'dir_id' parameter in all versions up... |
| CVE-2024-12262 | MEDIUM | 6.1 | 0.4% | Dec 21, 2024 | The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'step' parameter in all ver... |
| CVE-2024-12066 | HIGH | 8.8 | 0.9% | Dec 21, 2024 | The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path ... |
| CVE-2024-11975 | MEDIUM | 6.1 | 0.4% | Dec 21, 2024 | The Reactflow Visitor Recording and Heatmaps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th... |
| CVE-2024-11938 | MEDIUM | 6.4 | 0.3% | Dec 21, 2024 | The One Click Upsell Funnel for WooCommerce – Funnel Builder for WordPress, Create WooCommerce Upsell, Post-Purchase Up... |
| CVE-2024-11682 | MEDIUM | 6.1 | 0.4% | Dec 21, 2024 | The G Web Pro Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'q' parameter i... |
| CVE-2024-11287 | MEDIUM | 6.1 | 0.3% | Dec 21, 2024 | The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg wit... |
| CVE-2024-11196 | MEDIUM | 6.4 | 0.4% | Dec 21, 2024 | The Multi-column Tag Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mctagmap sho... |
| CVE-2024-11977 | HIGH | 7.3 | 0.6% | Dec 21, 2024 | The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode e... |
| CVE-2024-11607 | MEDIUM | 6.1 | 0.2% | Dec 21, 2024 | The GTPayment Donations WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisat... |
| CVE-2024-12846 | MEDIUM | 4.8 | 0.4% | Dec 21, 2024 | A vulnerability, which was classified as problematic, has been found in Emlog Pro up to 2.4.1. Affected by this issue is... |
| CVE-2024-11349 | CRITICAL | 9.8 | 1.2% | Dec 21, 2024 | The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. Thi... |
| CVE-2024-11811 | MEDIUM | 6.1 | 0.4% | Dec 20, 2024 | The Feedify – Web Push Notifications plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'platf... |
| CVE-2024-12845 | MEDIUM | 6.1 | 0.4% | Dec 20, 2024 | A vulnerability classified as problematic was found in Emlog Pro up to 2.4.1. Affected by this vulnerability is an unkno... |
| CVE-2024-56359 | MEDIUM | 6.1 | 0.3% | Dec 20, 2024 | grist-core is a spreadsheet hosting server. A user visiting a malicious document and clicking on a link in a HyperLink c... |
| CVE-2024-56358 | MEDIUM | 6.1 | 0.3% | Dec 20, 2024 | grist-core is a spreadsheet hosting server. A user visiting a malicious document and previewing an attachment could have... |
| CVE-2024-56357 | MEDIUM | 6.1 | 0.3% | Dec 20, 2024 | grist-core is a spreadsheet hosting server. A user visiting a malicious document or submitting a malicious form could ha... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now