2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13848 | MEDIUM | 4.8 | 0.2% | Feb 18, 2025 | The Reaction Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version... |
| CVE-2024-13687 | MEDIUM | 4.3 | 0.2% | Feb 18, 2025 | The Team Builder – Meet the Team plugin for WordPress is vulnerable to unauthorized modification of data due to a missin... |
| CVE-2024-13609 | MEDIUM | 5.9 | 1.6% | Feb 18, 2025 | The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive In... |
| CVE-2024-13595 | MEDIUM | 6.5 | 0.4% | Feb 18, 2025 | The Simple Signup Form plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'ssf' shortcode... |
| CVE-2024-13588 | MEDIUM | 5.4 | 0.2% | Feb 18, 2025 | The Simplebooklet PDF Viewer and Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug... |
| CVE-2024-13587 | MEDIUM | 5.4 | 0.2% | Feb 18, 2025 | The Zigaform – Price Calculator & Cost Estimation Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2024-13582 | MEDIUM | 5.4 | 0.2% | Feb 18, 2025 | The Simple Pricing Tables For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stor... |
| CVE-2024-13581 | MEDIUM | 5.4 | 0.2% | Feb 18, 2025 | The Simple Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'simple_chart' shor... |
| CVE-2024-13579 | MEDIUM | 5.4 | 0.2% | Feb 18, 2025 | The WP-Asambleas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'polls_popup' shortc... |
| CVE-2024-13578 | MEDIUM | 5.4 | 0.2% | Feb 18, 2025 | The WP-BibTeX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'WpBibTeX' shortcode in... |
| CVE-2024-13577 | MEDIUM | 5.4 | 0.2% | Feb 18, 2025 | The CATS Job Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catsone' short... |
| CVE-2024-13576 | MEDIUM | 5.4 | 0.3% | Feb 18, 2025 | The Gumlet Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gumlet' shortcode i... |
| CVE-2024-13573 | MEDIUM | 5.4 | 0.2% | Feb 18, 2025 | The Zigaform – Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zgf... |
| CVE-2024-13565 | MEDIUM | 5.4 | 0.3% | Feb 18, 2025 | The Simple Map No Api plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all... |
| CVE-2024-13555 | MEDIUM | 4.3 | 0.2% | Feb 18, 2025 | The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Cross-Site R... |
| CVE-2024-13540 | MEDIUM | 5.3 | 0.4% | Feb 18, 2025 | The WooODT Lite – Delivery & pickup date time location for WooCommerce plugin for WordPress is vulnerable to Full Path D... |
| CVE-2024-13538 | MEDIUM | 5.3 | 0.6% | Feb 18, 2025 | The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all vers... |
| CVE-2024-13535 | MEDIUM | 5.3 | 0.5% | Feb 18, 2025 | The Actionwear products sync plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and inclu... |
| CVE-2024-13522 | MEDIUM | 5.4 | 0.2% | Feb 18, 2025 | The magayo Lottery Results plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2024-13501 | MEDIUM | 5.4 | 0.4% | Feb 18, 2025 | The WP-FormAssembly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'formassembly' sh... |
| CVE-2024-13464 | MEDIUM | 5.4 | 0.3% | Feb 18, 2025 | The Library Bookshelves plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bookshelf' s... |
| CVE-2024-12813 | MEDIUM | 5.4 | 0.3% | Feb 18, 2025 | The Open Hours – Easy Opening Hours plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ... |
| CVE-2024-12525 | MEDIUM | 5.4 | 0.3% | Feb 18, 2025 | The Easy MLS Listings Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasa... |
| CVE-2024-13740 | MEDIUM | 4.3 | 0.3% | Feb 18, 2025 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Ref... |
| CVE-2024-13741 | MEDIUM | 5.4 | 0.3% | Feb 18, 2025 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Reques... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now