2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8678 | MEDIUM | 5.3 | 0.3% | Sep 25, 2024 | The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2024-3866 | MEDIUM | 6.1 | 0.3% | Sep 25, 2024 | The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Re... |
| CVE-2024-8658 | MEDIUM | 5.3 | 0.3% | Sep 25, 2024 | The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, Woo... |
| CVE-2024-7892 | MEDIUM | 4.3 | 0.2% | Sep 25, 2024 | The adstxt Plugin WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which cou... |
| CVE-2024-7878 | MEDIUM | 4.8 | 0.4% | Sep 25, 2024 | The WP ULike WordPress plugin before 4.7.4 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2024-6845 | MEDIUM | 5.3 | 1.1% | Sep 25, 2024 | The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, a... |
| CVE-2024-8668 | MEDIUM | 5.4 | 0.4% | Sep 25, 2024 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) pl... |
| CVE-2024-8516 | MEDIUM | 4.3 | 0.4% | Sep 25, 2024 | The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, an... |
| CVE-2024-8515 | MEDIUM | 5.4 | 0.4% | Sep 25, 2024 | The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget... |
| CVE-2024-9073 | MEDIUM | 5.4 | 0.3% | Sep 25, 2024 | The GutenGeek Free Gutenberg Blocks for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2024-9069 | MEDIUM | 5.4 | 0.3% | Sep 25, 2024 | The Graphicsly – The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WPBa... |
| CVE-2024-9068 | MEDIUM | 5.4 | 0.3% | Sep 25, 2024 | The OneElements – Best Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File u... |
| CVE-2024-9028 | MEDIUM | 5.4 | 0.3% | Sep 25, 2024 | The WP GPX Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sgpx' shortcode in a... |
| CVE-2024-9027 | MEDIUM | 5.4 | 0.3% | Sep 25, 2024 | The WPZOOM Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode... |
| CVE-2024-9024 | MEDIUM | 5.4 | 0.4% | Sep 25, 2024 | The Material Design Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mdi-icon sh... |
| CVE-2024-8741 | MEDIUM | 6.1 | 0.4% | Sep 25, 2024 | The Beam me up Scotty – Back to Top Button plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to t... |
| CVE-2024-8713 | MEDIUM | 6.1 | 0.4% | Sep 25, 2024 | The Kodex Posts likes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_a... |
| CVE-2024-8621 | MEDIUM | 6.5 | 0.5% | Sep 25, 2024 | The Daily Prayer Time plugin for WordPress is vulnerable to SQL Injection via the 'max_word' attribute of the 'quran_ver... |
| CVE-2024-8549 | MEDIUM | 6.1 | 0.5% | Sep 25, 2024 | The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to... |
| CVE-2024-8483 | MEDIUM | 6.5 | 0.4% | Sep 25, 2024 | The MAS Static Content plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, ... |
| CVE-2024-8476 | MEDIUM | 4.3 | 0.2% | Sep 25, 2024 | The Easy PayPal Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2024-8434 | MEDIUM | 4.3 | 0.3% | Sep 25, 2024 | The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to unauthorized access due to a m... |
| CVE-2024-7617 | MEDIUM | 6.1 | 0.6% | Sep 25, 2024 | The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 form fi... |
| CVE-2024-7491 | MEDIUM | 4.3 | 0.3% | Sep 25, 2024 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Re... |
| CVE-2024-7426 | MEDIUM | 5.3 | 0.4% | Sep 25, 2024 | The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now