2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5456 | HIGH | 8.8 | 0.9% | Jul 9, 2024 | The Panda Video plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.0 v... |
| CVE-2024-4868 | MEDIUM | 5.4 | 0.4% | Jul 9, 2024 | The Extensions for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's EE Event... |
| CVE-2024-4102 | MEDIUM | 5.4 | 0.3% | Jul 9, 2024 | The Pricing Table plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on... |
| CVE-2024-4100 | MEDIUM | 5.3 | 0.2% | Jul 9, 2024 | The Pricing Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2024-3608 | MEDIUM | 5.3 | 0.6% | Jul 9, 2024 | The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check o... |
| CVE-2024-3604 | HIGH | 8.8 | 0.5% | Jul 9, 2024 | The OSM – OpenStreetMap plugin for WordPress is vulnerable to SQL Injection via the 'tagged_filter' attribute of the 'os... |
| CVE-2024-3603 | MEDIUM | 5.4 | 0.3% | Jul 9, 2024 | The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'osm_map' sho... |
| CVE-2024-3563 | MEDIUM | 5.4 | 0.3% | Jul 9, 2024 | The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sharing block in a... |
| CVE-2024-3228 | MEDIUM | 5.3 | 0.4% | Jul 9, 2024 | The Social Sharing Plugin – Kiwi plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i... |
| CVE-2024-37502 | HIGH | 7.5 | 0.3% | Jul 9, 2024 | Deserialization of Untrusted Data vulnerability in wpweb WooCommerce Social Login woo-social-login.This issue affects Wo... |
| CVE-2024-37494 | HIGH | 8.8 | 0.5% | Jul 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in KaineLabs Youzify.... |
| CVE-2024-37486 | HIGH | 7.2 | 0.7% | Jul 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships P... |
| CVE-2024-37256 | HIGH | 7.2 | 0.6% | Jul 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS.... |
| CVE-2024-37225 | HIGH | 8.8 | 0.5% | Jul 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho Marketing Aut... |
| CVE-2024-37112 | CRITICAL | 9.8 | 0.5% | Jul 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Membership Softwar... |
| CVE-2024-6321 | HIGH | 8.8 | 0.4% | Jul 9, 2024 | The ScrollTo Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in version... |
| CVE-2024-6320 | HIGH | 8.8 | 0.4% | Jul 9, 2024 | The ScrollTo Top plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions u... |
| CVE-2024-6317 | HIGH | 8.8 | 0.6% | Jul 9, 2024 | The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File... |
| CVE-2024-6316 | HIGH | 8.8 | 0.5% | Jul 9, 2024 | The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File... |
| CVE-2024-6314 | CRITICAL | 9.8 | 0.9% | Jul 9, 2024 | The IQ Testimonials plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validatio... |
| CVE-2024-6313 | CRITICAL | 9.8 | 1.1% | Jul 9, 2024 | The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowe... |
| CVE-2024-6310 | HIGH | 8.8 | 0.5% | Jul 9, 2024 | The Advanced AJAX Page Loader plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload ... |
| CVE-2024-6309 | HIGH | 8.8 | 0.4% | Jul 9, 2024 | The Attachment File Icons (AF Icons) plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File ... |
| CVE-2024-6180 | HIGH | 7.2 | 0.5% | Jul 9, 2024 | The EventON plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on... |
| CVE-2024-6161 | HIGH | 8.8 | 0.8% | Jul 9, 2024 | The Default Thumbnail Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now