2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11424 | MEDIUM | 6.4 | 0.5% | Nov 21, 2024 | The Slick Sitemap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slick-sitemap' sho... |
| CVE-2024-11416 | MEDIUM | 6.1 | 0.3% | Nov 21, 2024 | The WIP Incoming Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2024-11414 | MEDIUM | 6.4 | 0.4% | Nov 21, 2024 | The RecipePress Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipe Ingredients in all... |
| CVE-2024-11412 | MEDIUM | 6.4 | 0.9% | Nov 21, 2024 | The Shine PDF Embeder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shinepdf' shor... |
| CVE-2024-11409 | HIGH | 7.2 | 1.1% | Nov 21, 2024 | The Grid View Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1... |
| CVE-2024-11388 | MEDIUM | 5.4 | 1.1% | Nov 21, 2024 | The Dino Game – Embed Google Chrome Dinosaur Game in WordPress plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2024-11385 | MEDIUM | 5.4 | 0.4% | Nov 21, 2024 | The Pure CSS Circle Progress bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cir... |
| CVE-2024-11371 | MEDIUM | 6.1 | 0.6% | Nov 21, 2024 | The Theater for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_que... |
| CVE-2024-11370 | MEDIUM | 6.1 | 0.6% | Nov 21, 2024 | The Subaccounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of a... |
| CVE-2024-11365 | MEDIUM | 6.1 | 0.6% | Nov 21, 2024 | The Crypto and DeFi Widgets – Web3 Cryptocurrency Shortcodes plugin for WordPress is vulnerable to Reflected Cross-Site ... |
| CVE-2024-11360 | MEDIUM | 6.1 | 0.7% | Nov 21, 2024 | The Page Parts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg w... |
| CVE-2024-11354 | MEDIUM | 4.3 | 0.5% | Nov 21, 2024 | The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized modification of... |
| CVE-2024-11334 | MEDIUM | 5.3 | 0.6% | Nov 21, 2024 | The My Contador lesr plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check... |
| CVE-2024-11320 | CRITICAL | 9.8 | 90.5% | Nov 21, 2024 | Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication me... |
| CVE-2024-11197 | MEDIUM | 4.2 | 0.4% | Nov 21, 2024 | The Lock User Account plugin for WordPress is vulnerable to user lock bypass in all versions up to, and including, 1.0.5... |
| CVE-2024-10898 | HIGH | 8.8 | 1.3% | Nov 21, 2024 | The Contact Form 7 Email Add on plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in... |
| CVE-2024-10890 | MEDIUM | 6.1 | 0.6% | Nov 21, 2024 | The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o... |
| CVE-2024-10796 | MEDIUM | 4.3 | 0.5% | Nov 21, 2024 | The If-So Dynamic Content Personalization plugin for WordPress is vulnerable to Information Exposure in all versions up ... |
| CVE-2024-10792 | MEDIUM | 6.1 | 0.6% | Nov 21, 2024 | The Easiest Funnel Builder For WordPress & WooCommerce by WPFunnels plugin for WordPress is vulnerable to Reflected Cros... |
| CVE-2024-10788 | HIGH | 7.2 | 0.8% | Nov 21, 2024 | The Activity Log – Monitor & Record User Changes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2024-10785 | MEDIUM | 5.4 | 0.4% | Nov 21, 2024 | The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si... |
| CVE-2024-10782 | MEDIUM | 4.3 | 0.5% | Nov 21, 2024 | The Theme Builder For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and in... |
| CVE-2024-10726 | MEDIUM | 6.1 | 0.3% | Nov 21, 2024 | The Friendly Functions for Welcart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t... |
| CVE-2024-10696 | MEDIUM | 4.3 | 0.5% | Nov 21, 2024 | The UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere El... |
| CVE-2024-10682 | MEDIUM | 6.1 | 0.6% | Nov 21, 2024 | The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting d... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now