2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9224 | MEDIUM | 6.5 | 1.4% | Oct 1, 2024 | The Hello World plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 2.1.1... |
| CVE-2024-9220 | MEDIUM | 6.1 | 0.4% | Oct 1, 2024 | The LH Copy Media File plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_... |
| CVE-2024-9209 | MEDIUM | 6.1 | 0.4% | Oct 1, 2024 | The WP Search Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query... |
| CVE-2024-9018 | HIGH | 8.8 | 0.5% | Oct 1, 2024 | The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘k... |
| CVE-2024-8799 | MEDIUM | 6.1 | 0.3% | Oct 1, 2024 | The Custom Banners plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg ... |
| CVE-2024-8793 | MEDIUM | 6.1 | 0.4% | Oct 1, 2024 | The Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin for WordPress... |
| CVE-2024-8786 | MEDIUM | 6.1 | 0.3% | Oct 1, 2024 | The Auto Featured Image from Title plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o... |
| CVE-2024-8430 | MEDIUM | 5.3 | 0.3% | Oct 1, 2024 | The Spice Starter Sites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil... |
| CVE-2024-8324 | MEDIUM | 6.4 | 0.3% | Oct 1, 2024 | The XO Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘get_slider’ function in all ver... |
| CVE-2024-8288 | MEDIUM | 6.4 | 0.3% | Oct 1, 2024 | The Guten Post Layout – An Advanced Post Grid Collection for WordPress Gutenberg plugin for WordPress is vulnerable to S... |
| CVE-2024-9304 | MEDIUM | 6.4 | 0.3% | Oct 1, 2024 | The LocateAndFilter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio... |
| CVE-2024-9274 | MEDIUM | 6.4 | 0.3% | Oct 1, 2024 | The Elastik Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all v... |
| CVE-2024-9272 | MEDIUM | 6.4 | 0.3% | Oct 1, 2024 | The R Animated Icon Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all... |
| CVE-2024-9269 | MEDIUM | 6.4 | 0.3% | Oct 1, 2024 | The Relogo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to,... |
| CVE-2024-9267 | MEDIUM | 6.1 | 0.4% | Oct 1, 2024 | The Easy WordPress Subscribe – Optin Hound plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to t... |
| CVE-2024-9145 | HIGH | 7.1 | 0.8% | Oct 1, 2024 | Wiz Code Visual Studio Code extension in versions 1.0.0 up to 1.5.3 and Wiz (legacy) Visual Studio Code extension in ver... |
| CVE-2024-9119 | MEDIUM | 6.4 | 0.3% | Oct 1, 2024 | The SVG Complete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions ... |
| CVE-2024-9108 | CRITICAL | 9.8 | 0.8% | Oct 1, 2024 | The Wechat Social login plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valid... |
| CVE-2024-9106 | CRITICAL | 9.8 | 1.7% | Oct 1, 2024 | The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.... |
| CVE-2024-8990 | MEDIUM | 6.4 | 0.4% | Oct 1, 2024 | The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's geo_mashup_visible_pos... |
| CVE-2024-8989 | MEDIUM | 6.4 | 0.3% | Oct 1, 2024 | The Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials plugin for WordPress i... |
| CVE-2024-8728 | MEDIUM | 6.1 | 0.3% | Oct 1, 2024 | The Easy Load More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg ... |
| CVE-2024-8727 | MEDIUM | 6.1 | 0.3% | Oct 1, 2024 | The DK PDF plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without ... |
| CVE-2024-8720 | MEDIUM | 6.4 | 0.3% | Oct 1, 2024 | The RumbleTalk Live Group Chat – HTML5 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'... |
| CVE-2024-8718 | MEDIUM | 6.1 | 0.4% | Oct 1, 2024 | The Gravity Forms Toolbar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter i... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now