2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12406 | MEDIUM | 6.5 | 0.4% | Dec 12, 2024 | The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via t... |
| CVE-2024-12162 | MEDIUM | 6.1 | 0.4% | Dec 12, 2024 | The Video & Photo Gallery for Ultimate Member plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t... |
| CVE-2024-12156 | MEDIUM | 6.1 | 0.4% | Dec 12, 2024 | The AI Content Writer, RSS Feed to Post, Autoblogging SEO Help plugin for WordPress is vulnerable to Reflected Cross-Sit... |
| CVE-2024-11891 | MEDIUM | 6.4 | 0.4% | Dec 12, 2024 | The Perfect Font Awesome Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ... |
| CVE-2024-11875 | MEDIUM | 6.4 | 0.3% | Dec 12, 2024 | The Add infos to the events calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ... |
| CVE-2024-11804 | MEDIUM | 6.1 | 0.3% | Dec 12, 2024 | The Planaday API plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all ver... |
| CVE-2024-11750 | MEDIUM | 6.4 | 0.3% | Dec 12, 2024 | The ONLYOFFICE DocSpace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'onlyoffice-d... |
| CVE-2024-11723 | MEDIUM | 6.1 | 0.3% | Dec 12, 2024 | The kvCORE IDX plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via any parameter on pages with the ... |
| CVE-2024-11709 | MEDIUM | 4.3 | 0.3% | Dec 12, 2024 | The AI Post Generator | AutoWriter plugin for WordPress is vulnerable to unauthorized modification of data due to a miss... |
| CVE-2024-11459 | MEDIUM | 6.1 | 0.4% | Dec 12, 2024 | The Country Blocker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ip' parameter in all v... |
| CVE-2024-11410 | MEDIUM | 6.4 | 0.3% | Dec 12, 2024 | The Top and footer bars for announcements, notifications, advertisements, promotions – YooBar plugin for WordPress is vu... |
| CVE-2024-11384 | MEDIUM | 5.4 | 0.2% | Dec 12, 2024 | The Arena.IM – Live Blogging for real-time events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2024-10910 | HIGH | 7.3 | 0.6% | Dec 12, 2024 | The The Grid Plus – Unlimited grid layout plugin for WordPress is vulnerable to arbitrary shortcode execution via grid_p... |
| CVE-2024-10590 | HIGH | 8.8 | 0.8% | Dec 12, 2024 | The Opt-In Downloads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in... |
| CVE-2024-10182 | MEDIUM | 6.4 | 0.4% | Dec 12, 2024 | The Cognito Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all versio... |
| CVE-2024-12461 | MEDIUM | 6.4 | 0.5% | Dec 12, 2024 | The WP-Revive Adserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprevive_asyn... |
| CVE-2024-12341 | MEDIUM | 4.3 | 0.3% | Dec 12, 2024 | The Custom Skins Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing... |
| CVE-2024-12338 | MEDIUM | 6.1 | 0.4% | Dec 12, 2024 | The Website Toolbox Community plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘websitetoolb... |
| CVE-2024-12260 | MEDIUM | 6.1 | 0.4% | Dec 12, 2024 | The Ultimate Endpoints With Rest Api plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page'... |
| CVE-2024-12258 | MEDIUM | 6.1 | 0.4% | Dec 12, 2024 | The WP Service Payment Form With Authorize.net plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ... |
| CVE-2024-11914 | MEDIUM | 6.4 | 0.4% | Dec 12, 2024 | The Gutenberg Blocks and Page Layouts – Attire Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2024-11901 | MEDIUM | 6.4 | 0.5% | Dec 12, 2024 | The PowerBI Embed Reports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MO_API_POW... |
| CVE-2024-11689 | HIGH | 8.8 | 0.4% | Dec 12, 2024 | The HQ Rental Software plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2024-11683 | MEDIUM | 6.1 | 0.4% | Dec 12, 2024 | The Newsletter Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'token_type' p... |
| CVE-2024-11443 | HIGH | 8.8 | 0.5% | Dec 12, 2024 | The de:branding plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escal... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now