2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9069MEDIUM5.4The Graphicsly – The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WPBa...
CVE-2024-9068MEDIUM5.4The OneElements – Best Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File u...
CVE-2024-9028MEDIUM5.4The WP GPX Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sgpx' shortcode in a...
CVE-2024-9027MEDIUM5.4The WPZOOM Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode...
CVE-2024-9024MEDIUM5.4The Material Design Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mdi-icon sh...
CVE-2024-8741MEDIUM6.1The Beam me up Scotty – Back to Top Button plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to t...
CVE-2024-8713MEDIUM6.1The Kodex Posts likes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_a...
CVE-2024-8621MEDIUM6.5The Daily Prayer Time plugin for WordPress is vulnerable to SQL Injection via the 'max_word' attribute of the 'quran_ver...
CVE-2024-8549MEDIUM6.1The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to...
CVE-2024-8485CRITICAL9.8The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versio...
CVE-2024-8484HIGH7.5The REST API TO MiniProgram plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-jso...
CVE-2024-8483MEDIUM6.5The MAS Static Content plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, ...
CVE-2024-8481HIGH7.3The The Special Text Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, an...
CVE-2024-8476MEDIUM4.3The Easy PayPal Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2024-8434MEDIUM4.3The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to unauthorized access due to a m...
CVE-2024-8350LOW2.7The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check ...
CVE-2024-8349HIGH7.2The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and i...
CVE-2024-7617MEDIUM6.1The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 form fi...
CVE-2024-7491MEDIUM4.3The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Re...
CVE-2024-7426MEDIUM5.3The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to ...
CVE-2024-7386MEDIUM4.3The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Cross-Site Request Forgery i...
CVE-2024-6590MEDIUM4.3The Spreadsheet Integration – Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins. Also, Disp...
CVE-2024-9148MEDIUM6.1Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed...
CVE-2024-9142CRITICAL9.8External Control of File Name or Path, : Incorrect Permission Assignment for Critical Resource vulnerability in Olgu Com...
CVE-2024-9141MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in the Oct8ne system. This flaw could allow an attacker to embed harmful JavaSc...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now