2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9705 | MEDIUM | 4.3 | 0.3% | Dec 6, 2024 | The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a ... |
| CVE-2024-12155 | CRITICAL | 9.8 | 1.2% | Dec 6, 2024 | The SV100 Companion plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e... |
| CVE-2024-12110 | MEDIUM | 4.3 | 0.3% | Dec 6, 2024 | The Gold Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c... |
| CVE-2024-12060 | MEDIUM | 6.1 | 0.3% | Dec 6, 2024 | The WP Media Optimizer (.webp) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wpmowebp-cs... |
| CVE-2024-12028 | MEDIUM | 5.3 | 0.4% | Dec 6, 2024 | The Friends plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST ... |
| CVE-2024-12027 | MEDIUM | 4.3 | 0.3% | Dec 6, 2024 | The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a m... |
| CVE-2024-12003 | MEDIUM | 6.1 | 0.2% | Dec 6, 2024 | The WP System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1... |
| CVE-2024-11823 | MEDIUM | 6.1 | 0.3% | Dec 6, 2024 | The Folder Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'foldergallery' sh... |
| CVE-2024-11687 | MEDIUM | 6.1 | 0.3% | Dec 6, 2024 | The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th... |
| CVE-2024-11450 | MEDIUM | 6.4 | 0.2% | Dec 6, 2024 | The ONLYOFFICE Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'onlyoffice' shor... |
| CVE-2024-11444 | MEDIUM | 4.3 | 0.2% | Dec 6, 2024 | The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up ... |
| CVE-2024-11368 | MEDIUM | 6.1 | 0.4% | Dec 6, 2024 | The Splash Sync plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg wit... |
| CVE-2024-11352 | MEDIUM | 6.4 | 0.3% | Dec 6, 2024 | The TwentyTwenty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'twentytwenty' short... |
| CVE-2024-11339 | MEDIUM | 6.4 | 0.2% | Dec 6, 2024 | The Smart PopUp Blaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spb-button'... |
| CVE-2024-11336 | MEDIUM | 6.1 | 0.1% | Dec 6, 2024 | The Clickbank WordPress Plugin (Storefront) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers... |
| CVE-2024-11323 | HIGH | 8.8 | 0.4% | Dec 6, 2024 | The AI Quiz | Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privil... |
| CVE-2024-11292 | MEDIUM | 5.3 | 0.4% | Dec 6, 2024 | The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ... |
| CVE-2024-11276 | MEDIUM | 6.1 | 0.3% | Dec 6, 2024 | The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to Reflected ... |
| CVE-2024-11204 | MEDIUM | 6.1 | 0.3% | Dec 6, 2024 | The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url... |
| CVE-2024-10879 | MEDIUM | 6.1 | 0.4% | Dec 6, 2024 | The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the u... |
| CVE-2024-10849 | MEDIUM | 6.4 | 0.3% | Dec 6, 2024 | The NewsMash theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all versio... |
| CVE-2024-10692 | MEDIUM | 4.3 | 0.3% | Dec 6, 2024 | The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Informatio... |
| CVE-2024-10689 | MEDIUM | 4.3 | 0.3% | Dec 6, 2024 | The XLTab – Accordions and Tabs for Elementor Page Builder plugin for WordPress is vulnerable to Information Exposure in... |
| CVE-2024-10320 | MEDIUM | 6.4 | 0.3% | Dec 6, 2024 | The Cookielay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cookielay shortcode in ... |
| CVE-2024-11178 | HIGH | 8.1 | 0.6% | Dec 6, 2024 | The Login With OTP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.4.2. ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now