2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13710MEDIUM4.3The Estatebud – Properties & Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u...
CVE-2024-13690HIGH7.2The WP Church Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several donation form submi...
CVE-2024-12623MEDIUM6.4The DICOM Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dcm' shortcode in ...
CVE-2024-9770MEDIUM4.7The WP-Recall WordPress plugin before 16.26.12 does not sanitize and escape a parameter before using it in a SQL statem...
CVE-2024-44903HIGH7.5SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is ava...
CVE-2024-13863HIGH7.1The Stylish Google Sheet Reader 4.0 WordPress plugin before 4.1 does not sanitise and escape a parameter before outputt...
CVE-2024-13618HIGH7.2The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download....
CVE-2024-13617HIGH8.6The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unau...
CVE-2024-13123LOW3.5The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privi...
CVE-2024-13122LOW3.5The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privi...
CVE-2024-13118MEDIUM4.3The IP Based Login WordPress plugin before 2.4.1 does not have CSRF checks in some places, which could allow attackers t...
CVE-2024-12769LOW3.5The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow hi...
CVE-2024-12682MEDIUM6.1The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could ...
CVE-2024-12109MEDIUM4.1The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.9 does not sanitize and escape a parameter ...
CVE-2024-11503MEDIUM6.1The WP Tabs WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2024-11273MEDIUM6.1The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape s...
CVE-2024-11272MEDIUM6.1The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape s...
CVE-2024-10703MEDIUM6.1The Registrations for the Events Calendar WordPress plugin before 2.13.4 does not sanitise and escape some of its setti...
CVE-2024-10679MEDIUM6.1The Quiz and Survey Master (QSM) WordPress plugin before 9.2.1 does not sanitise and escape some of its settings, which...
CVE-2024-10638MEDIUM4.1The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.11 does not sanitize and escape a parameter...
CVE-2024-10566MEDIUM6.1The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow...
CVE-2024-10565MEDIUM6.1The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow...
CVE-2024-10560LOW3.5The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could ...
CVE-2024-10554LOW3.5The WordPress WP-Advanced-Search WordPress plugin before 3.3.9.3 does not sanitise and escape some of its settings, whic...
CVE-2024-10472MEDIUM5.9The Stylish Price List WordPress plugin before 7.1.12 does not sanitise and escape some of its settings, which could al...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now