2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-8678MEDIUM5.3The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2024-3866MEDIUM6.1The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Re...
CVE-2024-8658MEDIUM5.3The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, Woo...
CVE-2024-7892MEDIUM4.3The adstxt Plugin WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which cou...
CVE-2024-7878MEDIUM4.8The WP ULike WordPress plugin before 4.7.4 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2024-6845MEDIUM5.3The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, a...
CVE-2024-8668MEDIUM5.4The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) pl...
CVE-2024-8516MEDIUM4.3The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, an...
CVE-2024-8515MEDIUM5.4The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget...
CVE-2024-9073MEDIUM5.4The GutenGeek Free Gutenberg Blocks for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2024-9069MEDIUM5.4The Graphicsly – The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WPBa...
CVE-2024-9068MEDIUM5.4The OneElements – Best Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File u...
CVE-2024-9028MEDIUM5.4The WP GPX Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sgpx' shortcode in a...
CVE-2024-9027MEDIUM5.4The WPZOOM Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode...
CVE-2024-9024MEDIUM5.4The Material Design Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mdi-icon sh...
CVE-2024-8741MEDIUM6.1The Beam me up Scotty – Back to Top Button plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to t...
CVE-2024-8713MEDIUM6.1The Kodex Posts likes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_a...
CVE-2024-8621MEDIUM6.5The Daily Prayer Time plugin for WordPress is vulnerable to SQL Injection via the 'max_word' attribute of the 'quran_ver...
CVE-2024-8549MEDIUM6.1The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to...
CVE-2024-8483MEDIUM6.5The MAS Static Content plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, ...
CVE-2024-8476MEDIUM4.3The Easy PayPal Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2024-8434MEDIUM4.3The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to unauthorized access due to a m...
CVE-2024-7617MEDIUM6.1The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 form fi...
CVE-2024-7491MEDIUM4.3The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Re...
CVE-2024-7426MEDIUM5.3The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now