2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10614 | MEDIUM | 4.3 | 0.3% | Nov 16, 2024 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabili... |
| CVE-2024-8856 | CRITICAL | 9.8 | 93.7% | Nov 16, 2024 | The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi... |
| CVE-2024-10728 | HIGH | 8.8 | 36.5% | Nov 16, 2024 | The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plug... |
| CVE-2024-9938 | MEDIUM | 6.1 | 0.4% | Nov 16, 2024 | The Bounce Handler MailPoet 3 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parame... |
| CVE-2024-9935 | HIGH | 7.5 | 7.5% | Nov 16, 2024 | The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions ... |
| CVE-2024-9850 | MEDIUM | 6.4 | 0.3% | Nov 16, 2024 | The SVG Case Study plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all version... |
| CVE-2024-9849 | HIGH | 8.8 | 1.2% | Nov 16, 2024 | The Real3D Flipbook Lite – 3D FlipBook, PDF Viewer, PDF Embedder plugin for WordPress is vulnerable to arbitrary file up... |
| CVE-2024-9839 | HIGH | 7.3 | 0.6% | Nov 16, 2024 | The The Uix Slideshow plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inc... |
| CVE-2024-9615 | MEDIUM | 6.1 | 0.4% | Nov 16, 2024 | The BulkPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg witho... |
| CVE-2024-9386 | MEDIUM | 6.4 | 0.4% | Nov 16, 2024 | The Exclusive Divi – Divi Preloader, Modules for Divi & Extra Theme plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2024-9192 | HIGH | 8.8 | 0.6% | Nov 16, 2024 | The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to privilege escalation due t... |
| CVE-2024-8873 | MEDIUM | 6.1 | 0.5% | Nov 16, 2024 | The PeproDev WooCommerce Receipt Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to th... |
| CVE-2024-6628 | MEDIUM | 4.3 | 0.2% | Nov 16, 2024 | The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to Cross-Site R... |
| CVE-2024-11118 | MEDIUM | 5.3 | 0.3% | Nov 16, 2024 | The 404 Error Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2024-11092 | MEDIUM | 6.4 | 0.3% | Nov 16, 2024 | The SVGPlus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versi... |
| CVE-2024-11085 | MEDIUM | 5.4 | 0.3% | Nov 16, 2024 | The WP Log Viewer plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability ch... |
| CVE-2024-10884 | MEDIUM | 6.1 | 0.4% | Nov 16, 2024 | The SimpleForm Contact Form Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the ... |
| CVE-2024-10883 | MEDIUM | 6.1 | 0.4% | Nov 16, 2024 | The SimpleForm – Contact form made simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to th... |
| CVE-2024-10875 | MEDIUM | 6.1 | 0.4% | Nov 16, 2024 | The Gallery Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_Query_... |
| CVE-2024-10533 | MEDIUM | 4.3 | 0.4% | Nov 16, 2024 | The WP Chat App plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check... |
| CVE-2024-10262 | MEDIUM | 6.3 | 0.6% | Nov 16, 2024 | The The Drop Shadow Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and... |
| CVE-2024-10147 | MEDIUM | 6.4 | 0.3% | Nov 16, 2024 | The Steel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn shortcode in all versio... |
| CVE-2024-10017 | MEDIUM | 6.4 | 0.3% | Nov 16, 2024 | The PJW Mime Config plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio... |
| CVE-2024-10015 | MEDIUM | 6.4 | 0.8% | Nov 16, 2024 | The ConvertCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and '... |
| CVE-2024-10861 | MEDIUM | 5.3 | 0.4% | Nov 16, 2024 | The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now