2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-12308MEDIUM5.4The Logo Slider WordPress plugin before 4.6.0 does not validate and escape some of its shortcode attributes before outp...
CVE-2024-13728MEDIUM6.1The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the r...
CVE-2024-13564MEDIUM5.4The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2024-13798MEDIUM5.3The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in al...
CVE-2024-12467MEDIUM6.1The Pago por Redsys plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'Ds_MerchantParameters'...
CVE-2024-12038MEDIUM5.4The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) p...
CVE-2024-13873MEDIUM4.3The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to...
CVE-2024-55159MEDIUM4.2GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the SortName parameter at /system/l...
CVE-2024-55156MEDIUM5.5An XML External Entity (XXE) vulnerability in the deserializeArgs() method of Java SDK for CloudEvents v4.0.1 allows att...
CVE-2024-45673MEDIUM5.5IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 thro...
CVE-2024-10222MEDIUM5.4The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions u...
CVE-2024-13846MEDIUM4.9The Indeed Ultimate Learning Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘post_id’ parame...
CVE-2024-13713MEDIUM6.5The WPExperts Square For GiveWP plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all vers...
CVE-2024-13455MEDIUM5.4The igumbi Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'igumbi_cal...
CVE-2024-13648MEDIUM5.4The Maps for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MapOnePoint' shortco...
CVE-2024-13461MEDIUM5.4The Autoship Cloud for WooCommerce Subscription Products plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2024-12452MEDIUM5.4The Ziggeo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ziggeo_event' shortcode i...
CVE-2024-12276MEDIUM6.5The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2024-13883MEDIUM4.3The WPUpper Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2024-13751MEDIUM5.4The 3D Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'des[]' parameter in all ...
CVE-2024-13672MEDIUM5.4The Mini Course Generator | Embed mini-courses and interactive content plugin for WordPress is vulnerable to Stored Cros...
CVE-2024-13537MEDIUM5.3The C9 Blocks plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.7.7. Th...
CVE-2024-13388MEDIUM5.4The TCBD Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbdtooltip_text' s...
CVE-2024-13379MEDIUM5.4The C9 Admin Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver...
CVE-2024-13235MEDIUM6.5The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'l...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now