2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11888MEDIUM6.4The IDer Login for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ider_lo...
CVE-2024-11884MEDIUM6.4The Wp photo text slider 50 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-photo...
CVE-2024-11883MEDIUM6.4The Connatix Video Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cnx_script_...
CVE-2024-11879Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-53752. Reason: This candidate is a ...
CVE-2024-11877MEDIUM6.4The Cricket Live Score plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cricket_score...
CVE-2024-11876MEDIUM6.4The Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site plugin for WordPress is vulnerable t...
CVE-2024-11873MEDIUM6.4The glomex oEmbed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'glomex_integration...
CVE-2024-11869MEDIUM6.4The Buk for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buk' shortcode...
CVE-2024-11867MEDIUM6.4The Companion Portfolio – Responsive Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2024-11865MEDIUM6.4The Tabs Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 d...
CVE-2024-11855MEDIUM6.4The Koalendar – Events & Appointments Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2024-11770MEDIUM6.4The Post Carousel & Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'post-cs' ...
CVE-2024-11763MEDIUM6.4The Plezi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'plezi' shortcode in all ve...
CVE-2024-11759MEDIUM6.4The Bukza plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bukza' shortcode in all ve...
CVE-2024-11755MEDIUM6.4The IMS Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown post settings in a...
CVE-2024-11751MEDIUM6.4The TCBD Popover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbd-popover-image ...
CVE-2024-11462MEDIUM6.1The Filestack Official plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'fstab' and 'filesta...
CVE-2024-11095MEDIUM6.4The Visualmodo Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads ...
CVE-2024-12553MEDIUM6.5GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote atta...
CVE-2024-12552HIGH7.8Wacom Center WTabletServicePro Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local ...
CVE-2024-55956CRITICAL9.8In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can impo...
CVE-2024-55946HIGH8.7Playloom Engine is an open-source, high-performance game development engine. Engine Beta v0.0.1 has a security vulnerabi...
CVE-2024-12632Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-55956. Reason: This candidate is a duplicate of ...
CVE-2024-55890MEDIUM6.9D-Tale is a visualizer for pandas data structures. Prior to version 3.16.1, users hosting D-Tale publicly can be vulnera...
CVE-2024-47892HIGH7.8Software installed and run as a non-privileged user may conduct GPU system calls to read and write freed physical memory...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now