2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9290CRITICAL9.8The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to mis...
CVE-2024-52057CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RTI Connext Profes...
CVE-2024-11012MEDIUM6.3The The Notibar – Notification Bar for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via...
CVE-2024-10783HIGH8.1The MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites plugin for WordPress is vulnerable...
CVE-2024-12465MEDIUM6.4The Property Hive Stamp Duty Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2024-12421MEDIUM6.5The The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode e...
CVE-2024-12420MEDIUM6.5The The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to arbitrary shortcode exec...
CVE-2024-12417MEDIUM6.5The The Simple Link Directory plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to,...
CVE-2024-12414MEDIUM4.3The Themify Store Locator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2024-12309MEDIUM5.3The Rate My Post – Star Rating Plugin by FeedbackWP plugin for WordPress is vulnerable to Insecure Direct Object Referen...
CVE-2024-12042MEDIUM5.4The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2024-11911MEDIUM4.3The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability c...
CVE-2024-11910MEDIUM5.4The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp-crowdfunding/search blo...
CVE-2024-11832MEDIUM5.4The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the cu...
CVE-2024-11754MEDIUM6.4The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'trafftbook...
CVE-2024-11275MEDIUM4.3The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable...
CVE-2024-55918MEDIUM5.3An issue was discovered in the Graphics::ColorNames package before 3.2.0 for Perl. There is an ambiguity between modules...
CVE-2024-12581MEDIUM4.8The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si...
CVE-2024-11839HIGH7.5Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitra...
CVE-2024-11838CRITICAL9.8External Control of File Name or Path vulnerability in PlexTrac allows Local Code Inclusion through use of an undocument...
CVE-2024-11837CRITICAL9.8Improper Neutralization of Special Elements used in an N1QL Command ('N1QL Injection') vulnerability in PlexTrac  allows...
CVE-2024-11836HIGH7.5Server-Side Request Forgery (SSRF) vulnerability in PlexTrac allowing requests to internal system resources.This issue a...
CVE-2024-11835HIGH7.5Uncontrolled Resource Consumption vulnerability in PlexTrac allows WebSocket DoS.This issue affects PlexTrac: from 1.61....
CVE-2024-11834CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PlexTrac allows arbitrar...
CVE-2024-11833CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PlexTrac allows arbitrar...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now