2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9069 | MEDIUM | 5.4 | 0.3% | Sep 25, 2024 | The Graphicsly – The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WPBa... |
| CVE-2024-9068 | MEDIUM | 5.4 | 0.3% | Sep 25, 2024 | The OneElements – Best Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File u... |
| CVE-2024-9028 | MEDIUM | 5.4 | 0.3% | Sep 25, 2024 | The WP GPX Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sgpx' shortcode in a... |
| CVE-2024-9027 | MEDIUM | 5.4 | 0.3% | Sep 25, 2024 | The WPZOOM Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode... |
| CVE-2024-9024 | MEDIUM | 5.4 | 0.4% | Sep 25, 2024 | The Material Design Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mdi-icon sh... |
| CVE-2024-8741 | MEDIUM | 6.1 | 0.4% | Sep 25, 2024 | The Beam me up Scotty – Back to Top Button plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to t... |
| CVE-2024-8713 | MEDIUM | 6.1 | 0.4% | Sep 25, 2024 | The Kodex Posts likes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_a... |
| CVE-2024-8621 | MEDIUM | 6.5 | 0.5% | Sep 25, 2024 | The Daily Prayer Time plugin for WordPress is vulnerable to SQL Injection via the 'max_word' attribute of the 'quran_ver... |
| CVE-2024-8549 | MEDIUM | 6.1 | 0.5% | Sep 25, 2024 | The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to... |
| CVE-2024-8485 | CRITICAL | 9.8 | 0.6% | Sep 25, 2024 | The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versio... |
| CVE-2024-8484 | HIGH | 7.5 | 3.6% | Sep 25, 2024 | The REST API TO MiniProgram plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-jso... |
| CVE-2024-8483 | MEDIUM | 6.5 | 0.4% | Sep 25, 2024 | The MAS Static Content plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, ... |
| CVE-2024-8481 | HIGH | 7.3 | 0.6% | Sep 25, 2024 | The The Special Text Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, an... |
| CVE-2024-8476 | MEDIUM | 4.3 | 0.2% | Sep 25, 2024 | The Easy PayPal Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2024-8434 | MEDIUM | 4.3 | 0.3% | Sep 25, 2024 | The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to unauthorized access due to a m... |
| CVE-2024-8350 | LOW | 2.7 | 0.4% | Sep 25, 2024 | The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check ... |
| CVE-2024-8349 | HIGH | 7.2 | 1.1% | Sep 25, 2024 | The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and i... |
| CVE-2024-7617 | MEDIUM | 6.1 | 0.6% | Sep 25, 2024 | The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 form fi... |
| CVE-2024-7491 | MEDIUM | 4.3 | 0.3% | Sep 25, 2024 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Re... |
| CVE-2024-7426 | MEDIUM | 5.3 | 0.4% | Sep 25, 2024 | The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to ... |
| CVE-2024-7386 | MEDIUM | 4.3 | 0.2% | Sep 25, 2024 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Cross-Site Request Forgery i... |
| CVE-2024-6590 | MEDIUM | 4.3 | 0.3% | Sep 25, 2024 | The Spreadsheet Integration – Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins. Also, Disp... |
| CVE-2024-9148 | MEDIUM | 6.1 | 0.6% | Sep 25, 2024 | Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed... |
| CVE-2024-9142 | CRITICAL | 9.8 | 0.4% | Sep 25, 2024 | External Control of File Name or Path, : Incorrect Permission Assignment for Critical Resource vulnerability in Olgu Com... |
| CVE-2024-9141 | MEDIUM | 5.4 | 0.3% | Sep 25, 2024 | Cross-Site Scripting (XSS) vulnerability in the Oct8ne system. This flaw could allow an attacker to embed harmful JavaSc... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now