2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13424 | MEDIUM | 4.3 | 0.2% | Jan 31, 2025 | The Ni Sales Commission For WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capab... |
| CVE-2024-13415 | MEDIUM | 4.3 | 0.3% | Jan 31, 2025 | The Food Menu – Restaurant Menu & Online Ordering for WooCommerce plugin for WordPress is vulnerable to unauthorized acc... |
| CVE-2024-13226 | MEDIUM | 6.1 | 0.6% | Jan 31, 2025 | The A5 Custom Login Page WordPress plugin through 2.8.1 does not sanitise and escape a parameter before outputting it ba... |
| CVE-2024-13225 | MEDIUM | 6.1 | 0.6% | Jan 31, 2025 | The ECT Home Page Products WordPress plugin through 1.9 does not sanitise and escape a parameter before outputting it ba... |
| CVE-2024-13224 | MEDIUM | 6.1 | 0.6% | Jan 31, 2025 | The SlideDeck 1 Lite Content Slider WordPress plugin through 1.4.8 does not sanitise and escape a parameter before outpu... |
| CVE-2024-13223 | MEDIUM | 6.1 | 0.3% | Jan 31, 2025 | The Tabulate WordPress plugin through 2.10.3 does not sanitise and escape some parameters before outputting them back in... |
| CVE-2024-13222 | MEDIUM | 6.1 | 0.6% | Jan 31, 2025 | The User Messages WordPress plugin through 1.2.4 does not sanitise and escape a parameter before outputting it back in t... |
| CVE-2024-13221 | MEDIUM | 6.1 | 0.6% | Jan 31, 2025 | The Fantastic ElasticSearch WordPress plugin through 4.1.0 does not sanitise and escape a parameter before outputting it... |
| CVE-2024-13220 | MEDIUM | 6.1 | 0.6% | Jan 31, 2025 | The WordPress Google Map Professional (Map In Your Language) WordPress plugin through 1.0 does not sanitise and escape a... |
| CVE-2024-13219 | MEDIUM | 6.1 | 0.6% | Jan 31, 2025 | The Privacy Policy Genius WordPress plugin through 2.0.4 does not sanitise and escape a parameter before outputting it b... |
| CVE-2024-13218 | MEDIUM | 6.1 | 0.3% | Jan 31, 2025 | The Fast Tube WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the p... |
| CVE-2024-13216 | MEDIUM | 4.3 | 0.3% | Jan 31, 2025 | The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information ... |
| CVE-2024-13112 | MEDIUM | 6.1 | 0.6% | Jan 31, 2025 | The WP MediaTagger WordPress plugin through 4.1.1 does not sanitise and escape a parameter before outputting it back in ... |
| CVE-2024-13101 | MEDIUM | 5.4 | 0.3% | Jan 31, 2025 | The WP MediaTagger WordPress plugin through 4.1.1 does not validate and escape some of its shortcode attributes before o... |
| CVE-2024-13100 | MEDIUM | 6.1 | 0.3% | Jan 31, 2025 | The OPSI Israel Domestic Shipments WordPress plugin through 2.6.3 does not sanitise and escape a parameter before output... |
| CVE-2024-12872 | MEDIUM | 4.8 | 0.2% | Jan 31, 2025 | The Zalomení WordPress plugin through 1.5 does not sanitise and escape some of its settings, which could allow high priv... |
| CVE-2024-12772 | MEDIUM | 5.4 | 0.3% | Jan 31, 2025 | The Ninja Tables WordPress plugin before 5.0.17 does not sanitize and escape a parameter before outputting it back in t... |
| CVE-2024-12275 | MEDIUM | 6.1 | 0.3% | Jan 31, 2025 | The Canvasflow for WordPress plugin through 1.5.5 does not sanitise and escape a parameter before outputting it back in ... |
| CVE-2024-11886 | MEDIUM | 6.4 | 0.3% | Jan 31, 2025 | The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ... |
| CVE-2024-10867 | MEDIUM | 5.4 | 0.3% | Jan 31, 2025 | The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable t... |
| CVE-2024-13463 | MEDIUM | 6.4 | 0.2% | Jan 31, 2025 | The SeatReg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'seatreg' shortcode in al... |
| CVE-2024-13399 | MEDIUM | 6.4 | 0.3% | Jan 31, 2025 | The Gosign – Posts Slider Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'posts-slider-... |
| CVE-2024-13397 | MEDIUM | 6.4 | 0.4% | Jan 31, 2025 | The WPRadio – WordPress Radio Streaming Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2024-13396 | MEDIUM | 6.4 | 0.4% | Jan 31, 2025 | The Frictionless plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'frictionless_form' ... |
| CVE-2024-23970 | MEDIUM | 6.5 | 0.2% | Jan 31, 2025 | This vulnerability allows network-adjacent attackers to compromise transport security on affected installations of Charg... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now