2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13710 | MEDIUM | 4.3 | 0.1% | Mar 25, 2025 | The Estatebud – Properties & Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u... |
| CVE-2024-13690 | HIGH | 7.2 | 0.3% | Mar 25, 2025 | The WP Church Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several donation form submi... |
| CVE-2024-12623 | MEDIUM | 6.4 | 0.3% | Mar 25, 2025 | The DICOM Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dcm' shortcode in ... |
| CVE-2024-9770 | MEDIUM | 4.7 | 0.3% | Mar 25, 2025 | The WP-Recall WordPress plugin before 16.26.12 does not sanitize and escape a parameter before using it in a SQL statem... |
| CVE-2024-44903 | HIGH | 7.5 | 0.3% | Mar 25, 2025 | SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is ava... |
| CVE-2024-13863 | HIGH | 7.1 | 0.3% | Mar 25, 2025 | The Stylish Google Sheet Reader 4.0 WordPress plugin before 4.1 does not sanitise and escape a parameter before outputt... |
| CVE-2024-13618 | HIGH | 7.2 | 0.3% | Mar 25, 2025 | The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download.... |
| CVE-2024-13617 | HIGH | 8.6 | 0.4% | Mar 25, 2025 | The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unau... |
| CVE-2024-13123 | LOW | 3.5 | 0.2% | Mar 25, 2025 | The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privi... |
| CVE-2024-13122 | LOW | 3.5 | 0.2% | Mar 25, 2025 | The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privi... |
| CVE-2024-13118 | MEDIUM | 4.3 | 0.2% | Mar 25, 2025 | The IP Based Login WordPress plugin before 2.4.1 does not have CSRF checks in some places, which could allow attackers t... |
| CVE-2024-12769 | LOW | 3.5 | 0.2% | Mar 25, 2025 | The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow hi... |
| CVE-2024-12682 | MEDIUM | 6.1 | 0.3% | Mar 25, 2025 | The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could ... |
| CVE-2024-12109 | MEDIUM | 4.1 | 0.3% | Mar 25, 2025 | The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.9 does not sanitize and escape a parameter ... |
| CVE-2024-11503 | MEDIUM | 6.1 | 0.3% | Mar 25, 2025 | The WP Tabs WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high pri... |
| CVE-2024-11273 | MEDIUM | 6.1 | 0.3% | Mar 25, 2025 | The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape s... |
| CVE-2024-11272 | MEDIUM | 6.1 | 0.3% | Mar 25, 2025 | The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape s... |
| CVE-2024-10703 | MEDIUM | 6.1 | 0.3% | Mar 25, 2025 | The Registrations for the Events Calendar WordPress plugin before 2.13.4 does not sanitise and escape some of its setti... |
| CVE-2024-10679 | MEDIUM | 6.1 | 0.3% | Mar 25, 2025 | The Quiz and Survey Master (QSM) WordPress plugin before 9.2.1 does not sanitise and escape some of its settings, which... |
| CVE-2024-10638 | MEDIUM | 4.1 | 0.4% | Mar 25, 2025 | The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.11 does not sanitize and escape a parameter... |
| CVE-2024-10566 | MEDIUM | 6.1 | 0.3% | Mar 25, 2025 | The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow... |
| CVE-2024-10565 | MEDIUM | 6.1 | 0.3% | Mar 25, 2025 | The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow... |
| CVE-2024-10560 | LOW | 3.5 | 0.3% | Mar 25, 2025 | The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could ... |
| CVE-2024-10554 | LOW | 3.5 | 0.3% | Mar 25, 2025 | The WordPress WP-Advanced-Search WordPress plugin before 3.3.9.3 does not sanitise and escape some of its settings, whic... |
| CVE-2024-10472 | MEDIUM | 5.9 | 0.3% | Mar 25, 2025 | The Stylish Price List WordPress plugin before 7.1.12 does not sanitise and escape some of its settings, which could al... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now