2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10508 | CRITICAL | 9.8 | 1.5% | Nov 9, 2024 | The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to pr... |
| CVE-2024-9874 | HIGH | 7.2 | 0.7% | Nov 9, 2024 | The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to time-based SQL Injecti... |
| CVE-2024-10876 | MEDIUM | 6.1 | 0.4% | Nov 9, 2024 | The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vul... |
| CVE-2024-10688 | MEDIUM | 4.3 | 0.3% | Nov 9, 2024 | The Attesa Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.2 ... |
| CVE-2024-10683 | MEDIUM | 6.1 | 0.4% | Nov 9, 2024 | The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to ... |
| CVE-2024-8756 | MEDIUM | 5.3 | 0.4% | Nov 9, 2024 | The Quform - WordPress Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions... |
| CVE-2024-10470 | CRITICAL | 9.8 | 34.1% | Nov 9, 2024 | The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file re... |
| CVE-2024-10814 | MEDIUM | 6.4 | 0.3% | Nov 9, 2024 | The Code Embed plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2... |
| CVE-2024-10770 | MEDIUM | 4.3 | 0.3% | Nov 9, 2024 | The Envo Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.3 vi... |
| CVE-2024-10669 | MEDIUM | 4.3 | 0.3% | Nov 9, 2024 | The Countdown Timer block – Display the event's date into a timer. plugin for WordPress is vulnerable to Informatio... |
| CVE-2024-10667 | MEDIUM | 4.3 | 0.3% | Nov 9, 2024 | The Content Slider Block plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including... |
| CVE-2024-9226 | MEDIUM | 6.1 | 0.4% | Nov 9, 2024 | The Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages plugin for WordPress is vulnerable to Reflecte... |
| CVE-2024-10693 | MEDIUM | 4.3 | 0.3% | Nov 9, 2024 | The SKT Addons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inclu... |
| CVE-2024-10674 | HIGH | 8.8 | 1.7% | Nov 9, 2024 | The Th Shop Mania theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capab... |
| CVE-2024-10673 | HIGH | 8.8 | 1.1% | Nov 9, 2024 | The Top Store theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capabilit... |
| CVE-2024-10627 | CRITICAL | 9.8 | 0.8% | Nov 9, 2024 | The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t... |
| CVE-2024-10626 | HIGH | 8.1 | 0.9% | Nov 9, 2024 | The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient ... |
| CVE-2024-10625 | CRITICAL | 9.1 | 1.0% | Nov 9, 2024 | The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient ... |
| CVE-2024-9775 | MEDIUM | 4.8 | 0.3% | Nov 9, 2024 | The Anih - Creative Agency WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via admin se... |
| CVE-2024-9270 | MEDIUM | 6.4 | 0.3% | Nov 9, 2024 | The Lenxel Core for Lenxel(LNX) LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploa... |
| CVE-2024-9262 | MEDIUM | 6.5 | 0.4% | Nov 9, 2024 | The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to Insecure Direct Ob... |
| CVE-2024-8960 | MEDIUM | 5.4 | 0.3% | Nov 9, 2024 | The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads ... |
| CVE-2024-10779 | MEDIUM | 4.3 | 0.3% | Nov 9, 2024 | The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i... |
| CVE-2024-10588 | MEDIUM | 4.3 | 0.3% | Nov 9, 2024 | The Debug Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th... |
| CVE-2024-10586 | CRITICAL | 9.8 | 2.1% | Nov 9, 2024 | The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the db... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now