2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-5456HIGH8.8The Panda Video plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.0 v...
CVE-2024-4868MEDIUM5.4The Extensions for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's EE Event...
CVE-2024-4102MEDIUM5.4The Pricing Table plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on...
CVE-2024-4100MEDIUM5.3The Pricing Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2024-3608MEDIUM5.3The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check o...
CVE-2024-3604HIGH8.8The OSM – OpenStreetMap plugin for WordPress is vulnerable to SQL Injection via the 'tagged_filter' attribute of the 'os...
CVE-2024-3603MEDIUM5.4The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'osm_map' sho...
CVE-2024-3563MEDIUM5.4The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sharing block in a...
CVE-2024-3228MEDIUM5.3The Social Sharing Plugin – Kiwi plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i...
CVE-2024-37502HIGH7.5Deserialization of Untrusted Data vulnerability in wpweb WooCommerce Social Login woo-social-login.This issue affects Wo...
CVE-2024-37494HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in KaineLabs Youzify....
CVE-2024-37486HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships P...
CVE-2024-37256HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS....
CVE-2024-37225HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho Marketing Aut...
CVE-2024-37112CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Membership Softwar...
CVE-2024-6321HIGH8.8The ScrollTo Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in version...
CVE-2024-6320HIGH8.8The ScrollTo Top plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions u...
CVE-2024-6317HIGH8.8The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File...
CVE-2024-6316HIGH8.8The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File...
CVE-2024-6314CRITICAL9.8The IQ Testimonials plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validatio...
CVE-2024-6313CRITICAL9.8The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowe...
CVE-2024-6310HIGH8.8The Advanced AJAX Page Loader plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload ...
CVE-2024-6309HIGH8.8The Attachment File Icons (AF Icons) plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File ...
CVE-2024-6180HIGH7.2The EventON plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on...
CVE-2024-6161HIGH8.8The Default Thumbnail Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now