2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-13676MEDIUM6.5The Categorized Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' attribute of the 'ima...
CVE-2024-13674MEDIUM6.4The Cosmic Blocks (40+) Content Editor Blocks Collection plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2024-13663MEDIUM6.4The Coaching Staffs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mstw-cs-table' s...
CVE-2024-13660MEDIUM6.4The Responsive Flickr Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fsho...
CVE-2024-13657MEDIUM6.4The Store Locator Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'storelocato...
CVE-2024-13591MEDIUM5.4The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-...
CVE-2024-13589MEDIUM6.4The YouTube Playlists with Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yt...
CVE-2024-13462MEDIUM6.4The WP Wiki Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wiki' shortcode ...
CVE-2024-13405MEDIUM4.3The Apptivo Business Site CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an...
CVE-2024-13390MEDIUM6.4The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2024-12522MEDIUM6.4The Yay! Forms | Embed Custom Forms, Surveys, and Quizzes Easily plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2024-12339MEDIUM6.1The Digihood HTML Sitemap plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘channel' paramet...
CVE-2024-12069MEDIUM6.1The Lexicata plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg withou...
CVE-2024-11778MEDIUM6.4The CanadaHelps Embedded Donation Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'...
CVE-2024-11753MEDIUM6.4The UMich OIDC Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'umich_oidc_butt...
CVE-2024-11335MEDIUM6.4The UltraEmbed – Advanced Iframe Plugin For WordPress with Gutenberg Block Included plugin for WordPress is vulnerable t...
CVE-2024-13799MEDIUM6.4The User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress is vulnerable to S...
CVE-2024-13443MEDIUM6.4The Easypromos Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Easypromos shor...
CVE-2024-13508MEDIUM6.1The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the locale parameter in all...
CVE-2024-57259MEDIUM6.8sqfs_search_dir in Das U-Boot before 2025.01-rc1 exhibits an off-by-one error and resultant heap memory corruption for s...
CVE-2024-57256MEDIUM6.8An integer overflow in ext4fs_read_symlink in Das U-Boot before 2025.01-rc1 occurs for zalloc (adding one to an le32 var...
CVE-2024-57255MEDIUM6.8An integer overflow in sqfs_resolve_symlink in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem wi...
CVE-2024-57254MEDIUM6.8An integer overflow in sqfs_inode_size in Das U-Boot before 2025.01-rc1 occurs in the symlink size calculation via a cra...
CVE-2024-13743MEDIUM6.4The Wonder Video Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wonderplugin_v...
CVE-2024-45783MEDIUM4.4A flaw was found in grub2. When failing to mount an HFS+ grub, the hfsplus filesystem driver doesn't properly set an ERR...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now