2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9458MEDIUM4.8The Reservit Hotel WordPress plugin before 3.0 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-13857MEDIUM5.5The WPGet API – Connect to any external REST API plugin for WordPress is vulnerable to Server-Side Request Forgery in al...
CVE-2024-13805MEDIUM5.4The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerab...
CVE-2024-13668HIGH7.1The WordPress Activity O Meter WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting i...
CVE-2024-13635MEDIUM4.3The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
CVE-2024-13552MEDIUM4.3The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Objec...
CVE-2024-9658HIGH8.8The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeov...
CVE-2024-13904CRITICAL9.1The Platform.ly for WooCommerce plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions ...
CVE-2024-13781MEDIUM6.5The Hero Maps Premium plugin for WordPress is vulnerable to SQL Injection via several AJAX actions in all versions up to...
CVE-2024-13431MEDIUM6.1The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Ref...
CVE-2024-12876CRITICAL9.8The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeo...
CVE-2024-12611MEDIUM5.3The School Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ...
CVE-2024-12610MEDIUM5.3The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a miss...
CVE-2024-12609MEDIUM6.5The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'view-attendance'...
CVE-2024-12607MEDIUM6.5The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of...
CVE-2024-12036HIGH7.5The CS Framework plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.9 via...
CVE-2024-12035HIGH8.8The CS Framework plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation ...
CVE-2024-10804HIGH7.5The Ultimate Video Player WordPress & WooCommerce Plugin plugin for WordPress is vulnerable to Directory Traversal in al...
CVE-2024-13906HIGH7.2The Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress plugin for WordPress is vulnerable to ...
CVE-2024-12837HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory.
CVE-2024-12576MEDIUM5.5Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger a crash of the FW r...
CVE-2024-13655HIGH8.1The Flex Mag - Responsive WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data th...
CVE-2024-13320HIGH7.5The CURCY - WooCommerce Multi Currency - Currency Switcher plugin for WordPress is vulnerable to SQL Injection via the '...
CVE-2024-12809MEDIUM6.4The Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wishlist_button' shortc...
CVE-2024-13526MEDIUM4.3The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now