2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9458 | MEDIUM | 4.8 | 0.8% | Mar 7, 2025 | The Reservit Hotel WordPress plugin before 3.0 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2024-13857 | MEDIUM | 5.5 | 0.3% | Mar 7, 2025 | The WPGet API – Connect to any external REST API plugin for WordPress is vulnerable to Server-Side Request Forgery in al... |
| CVE-2024-13805 | MEDIUM | 5.4 | 0.2% | Mar 7, 2025 | The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerab... |
| CVE-2024-13668 | HIGH | 7.1 | 0.3% | Mar 7, 2025 | The WordPress Activity O Meter WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting i... |
| CVE-2024-13635 | MEDIUM | 4.3 | 0.3% | Mar 7, 2025 | The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,... |
| CVE-2024-13552 | MEDIUM | 4.3 | 0.3% | Mar 7, 2025 | The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Objec... |
| CVE-2024-9658 | HIGH | 8.8 | 0.3% | Mar 7, 2025 | The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeov... |
| CVE-2024-13904 | CRITICAL | 9.1 | 0.4% | Mar 7, 2025 | The Platform.ly for WooCommerce plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions ... |
| CVE-2024-13781 | MEDIUM | 6.5 | 0.3% | Mar 7, 2025 | The Hero Maps Premium plugin for WordPress is vulnerable to SQL Injection via several AJAX actions in all versions up to... |
| CVE-2024-13431 | MEDIUM | 6.1 | 0.3% | Mar 7, 2025 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Ref... |
| CVE-2024-12876 | CRITICAL | 9.8 | 0.4% | Mar 7, 2025 | The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeo... |
| CVE-2024-12611 | MEDIUM | 5.3 | 0.3% | Mar 7, 2025 | The School Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ... |
| CVE-2024-12610 | MEDIUM | 5.3 | 0.3% | Mar 7, 2025 | The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a miss... |
| CVE-2024-12609 | MEDIUM | 6.5 | 0.4% | Mar 7, 2025 | The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'view-attendance'... |
| CVE-2024-12607 | MEDIUM | 6.5 | 0.3% | Mar 7, 2025 | The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of... |
| CVE-2024-12036 | HIGH | 7.5 | 0.3% | Mar 7, 2025 | The CS Framework plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.9 via... |
| CVE-2024-12035 | HIGH | 8.8 | 0.8% | Mar 7, 2025 | The CS Framework plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation ... |
| CVE-2024-10804 | HIGH | 7.5 | 0.8% | Mar 7, 2025 | The Ultimate Video Player WordPress & WooCommerce Plugin plugin for WordPress is vulnerable to Directory Traversal in al... |
| CVE-2024-13906 | HIGH | 7.2 | 0.7% | Mar 7, 2025 | The Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress plugin for WordPress is vulnerable to ... |
| CVE-2024-12837 | HIGH | 7.8 | 0.2% | Mar 7, 2025 | Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory. |
| CVE-2024-12576 | MEDIUM | 5.5 | 0.1% | Mar 7, 2025 | Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger a crash of the FW r... |
| CVE-2024-13655 | HIGH | 8.1 | 0.3% | Mar 7, 2025 | The Flex Mag - Responsive WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data th... |
| CVE-2024-13320 | HIGH | 7.5 | 0.4% | Mar 7, 2025 | The CURCY - WooCommerce Multi Currency - Currency Switcher plugin for WordPress is vulnerable to SQL Injection via the '... |
| CVE-2024-12809 | MEDIUM | 6.4 | 0.3% | Mar 7, 2025 | The Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wishlist_button' shortc... |
| CVE-2024-13526 | MEDIUM | 4.3 | 0.3% | Mar 7, 2025 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now