2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-13579MEDIUM5.4The WP-Asambleas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'polls_popup' shortc...
CVE-2024-13578MEDIUM5.4The WP-BibTeX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'WpBibTeX' shortcode in...
CVE-2024-13577MEDIUM5.4The CATS Job Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catsone' short...
CVE-2024-13576MEDIUM5.4The Gumlet Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gumlet' shortcode i...
CVE-2024-13573MEDIUM5.4The Zigaform – Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zgf...
CVE-2024-13565MEDIUM5.4The Simple Map No Api plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all...
CVE-2024-13555MEDIUM4.3The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Cross-Site R...
CVE-2024-13540MEDIUM5.3The WooODT Lite – Delivery & pickup date time location for WooCommerce plugin for WordPress is vulnerable to Full Path D...
CVE-2024-13538MEDIUM5.3The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all vers...
CVE-2024-13535MEDIUM5.3The Actionwear products sync plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and inclu...
CVE-2024-13522MEDIUM5.4The magayo Lottery Results plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2024-13501MEDIUM5.4The WP-FormAssembly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'formassembly' sh...
CVE-2024-13464MEDIUM5.4The Library Bookshelves plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bookshelf' s...
CVE-2024-12813MEDIUM5.4The Open Hours – Easy Opening Hours plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
CVE-2024-12525MEDIUM5.4The Easy MLS Listings Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasa...
CVE-2024-13740MEDIUM4.3The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Ref...
CVE-2024-13741MEDIUM5.4The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Reques...
CVE-2024-25066MEDIUM4.3RSA Authentication Manager before 8.7 SP2 Patch 1 allows XML External Entity (XXE) attacks via a license file, resulting...
CVE-2024-13879MEDIUM5.5The Stream plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.2...
CVE-2024-47935MEDIUM6.7Improper Validation of Integrity Check Value vulnerability in TXOne Networks StellarProtect (Legacy Mode), StellarEnforc...
CVE-2024-13627MEDIUM4.7The OWL Carousel Slider WordPress plugin through 2.2 does not sanitise and escape a parameter before outputting it back ...
CVE-2024-13608MEDIUM4.7The Track Logins WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statemen...
CVE-2024-13603MEDIUM6.1The Wise Forms WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow unaut...
CVE-2024-57970MEDIUM4libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c v...
CVE-2024-13834MEDIUM5.4The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme plugin for WordP...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now