2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-12821MEDIUM6.5The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to p...
CVE-2024-12451MEDIUM5.4The HTML5 chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'HTML5CHAT' shortcode ...
CVE-2024-12444MEDIUM5.4The WP Dispensary plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpd_menu' shortcod...
CVE-2024-12320MEDIUM6.1The Team Rosters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in all ver...
CVE-2024-12299MEDIUM6.1The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Filename parameter in ...
CVE-2024-12177MEDIUM6.1The Ai Image Alt Text Generator for WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pag...
CVE-2024-12102MEDIUM4.3The Typer Core plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.6 vi...
CVE-2024-11583MEDIUM4.3The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable t...
CVE-2024-10847MEDIUM5.4The Storely theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all version...
CVE-2024-13466MEDIUM6.4The Automatically Hierarchic Categories in Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2024-13380MEDIUM6.4The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2024-13706MEDIUM6.1The WP Image Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'file' parameter in a...
CVE-2024-12524MEDIUM6.4The Clinked Client Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'clinked-lo...
CVE-2024-12409MEDIUM6.1The Simple:Press Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all...
CVE-2024-13758MEDIUM6.5The CP Contact Form with PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, ...
CVE-2024-13732MEDIUM5.4The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
CVE-2024-13470MEDIUM5.4The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2024-13642MEDIUM5.4The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image...
CVE-2024-13457MEDIUM5.3The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version...
CVE-2024-12921MEDIUM6.4The EthereumICO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ethereum-ico shortcod...
CVE-2024-12709MEDIUM4.3The Bulk Me Now! WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to m...
CVE-2024-12163MEDIUM6.5The goodlayers-core WordPress plugin before 2.1.3 allows users with a subscriber role and above to upload SVGs containin...
CVE-2024-10309MEDIUM5.9The Tracking Code Manager WordPress plugin before 2.4.0 does not sanitise and escape some of its metabox settings when o...
CVE-2024-57513MEDIUM6.5A floating-point exception (FPE) vulnerability exists in the AP4_TfraAtom::AP4_TfraAtom function in Bento4.
CVE-2024-51182MEDIUM6.1HTML Injection vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary HTML c...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now