2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13699 | MEDIUM | 5.4 | 0.3% | Feb 4, 2025 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor’ parameter... |
| CVE-2024-27137 | MEDIUM | 5.3 | 0.3% | Feb 4, 2025 | In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration... |
| CVE-2024-13733 | MEDIUM | 5.4 | 0.3% | Feb 4, 2025 | The SKT Blocks – Gutenberg based Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ... |
| CVE-2024-13529 | MEDIUM | 6.5 | 0.4% | Feb 4, 2025 | The SocialV - Social Network and Community BuddyPress Theme theme for WordPress is vulnerable to unauthorized access of ... |
| CVE-2024-13510 | MEDIUM | 6.1 | 0.1% | Feb 4, 2025 | The ShopSite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.... |
| CVE-2024-13356 | MEDIUM | 6.5 | 0.2% | Feb 4, 2025 | The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
| CVE-2024-13403 | MEDIUM | 5.4 | 0.4% | Feb 4, 2025 | The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vu... |
| CVE-2024-13514 | MEDIUM | 4.3 | 0.3% | Feb 4, 2025 | The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Information Exposure in all versions u... |
| CVE-2024-12046 | MEDIUM | 4.3 | 0.4% | Feb 4, 2025 | The Medical Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions u... |
| CVE-2024-13607 | MEDIUM | 4.3 | 0.4% | Feb 4, 2025 | The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object ... |
| CVE-2024-12597 | MEDIUM | 5.4 | 0.3% | Feb 4, 2025 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'b... |
| CVE-2024-13332 | MEDIUM | 6.1 | 0.3% | Feb 4, 2025 | The TransFinanz WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the... |
| CVE-2024-13331 | MEDIUM | 6.1 | 0.6% | Feb 4, 2025 | The WP Dream Carousel WordPress plugin through 1.0.1b does not sanitise and escape a parameter before outputting it back... |
| CVE-2024-13328 | MEDIUM | 6.1 | 0.6% | Feb 4, 2025 | The Giga Messenger WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in... |
| CVE-2024-13327 | MEDIUM | 6.1 | 0.6% | Feb 4, 2025 | The Musicbox WordPress plugin through 2.0.3 does not sanitise and escape a parameter before outputting it back in the pa... |
| CVE-2024-13326 | MEDIUM | 6.1 | 0.6% | Feb 4, 2025 | The iBuildApp WordPress plugin through 0.2.0 does not sanitise and escape a parameter before outputting it back in the p... |
| CVE-2024-13325 | MEDIUM | 6.1 | 0.6% | Feb 4, 2025 | The Glossy WordPress plugin through 2.3.5 does not sanitise and escape a parameter before outputting it back in the page... |
| CVE-2024-13115 | MEDIUM | 6.1 | 0.2% | Feb 4, 2025 | The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not have CSRF check in some places,... |
| CVE-2024-13114 | MEDIUM | 6.1 | 0.6% | Feb 4, 2025 | The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not sanitise and escape a parameter... |
| CVE-2024-44449 | MEDIUM | 6.1 | 0.5% | Feb 3, 2025 | Cross Site Scripting vulnerability in Quorum onQ OS v.6.0.0.5.2064 allows a remote attacker to obtain sensitive informat... |
| CVE-2024-57498 | MEDIUM | 4.8 | 0.3% | Feb 3, 2025 | Cross Site Scripting vulnerability in sayski ForestBlog 20241223 allows a remote attacker to escalate privileges via the... |
| CVE-2024-57097 | MEDIUM | 4.8 | 0.2% | Feb 3, 2025 | ClassCMS 4.8 is vulnerable to Cross Site Scripting (XSS) in class/admin/channel.php. |
| CVE-2024-56946 | MEDIUM | 5.3 | 0.4% | Feb 3, 2025 | Denial of service in DNS-over-QUIC in Technitium DNS Server <= v13.2.2 allows remote attackers to permanently stop the s... |
| CVE-2024-11134 | MEDIUM | 6.5 | 0.3% | Feb 3, 2025 | The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '... |
| CVE-2024-11133 | MEDIUM | 5.3 | 0.3% | Feb 3, 2025 | The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now