2024 CVE Vulnerabilities

39,242 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-4621MEDIUM4.8The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 does not sanitise and escape some of its...
CVE-2024-4620CRITICAL9.8The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify u...
CVE-2024-4354MEDIUM6.4The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Server-Side Request Forgery in all ...
CVE-2024-4042MEDIUM5.4The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPre...
CVE-2024-3592MEDIUM6.5The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to SQL I...
CVE-2024-3288MEDIUM5.4The Logo Slider WordPress plugin before 4.0.0 does not validate and escape some of its Slider Settings before outputtin...
CVE-2024-5640MEDIUM5.4The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is ...
CVE-2024-5612MEDIUM5.4The Essential Addons for Elementor Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eael_l...
CVE-2024-4902HIGH7.2The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via ...
CVE-2024-5425MEDIUM5.4The WP jQuery Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ attribute in al...
CVE-2024-4887HIGH7.5The Qi Addons For Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ...
CVE-2024-37385CRITICAL9.8Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_ide...
CVE-2024-37384MEDIUM6.1Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.
CVE-2024-37383MEDIUM6.1Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
CVE-2024-36082MEDIUM6.5SQL injection vulnerability in Music Store - WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated ...
CVE-2024-1988MEDIUM5.4The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPre...
CVE-2024-5607MEDIUM5.4The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2024-3987MEDIUM5.4The WP Mobile Menu – The Mobile-Friendly Responsive Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2024-1768MEDIUM5.4The Clever Fox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's info box block in all ...
CVE-2024-1689MEDIUM4.3The WooCommerce Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2024-4013MEDIUM5.6A bug exists in the API, mesh_node_power_off(), which fails to copy the contents of the Replay Protection List (RPL) fr...
CVE-2024-36823HIGH7.5The encrypt() function of Ninja Core v7.0.0 was discovered to use a weak cryptographic algorithm, leading to a possible ...
CVE-2024-36775MEDIUM5.4A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HT...
CVE-2024-36774HIGH7.2An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a ...
CVE-2024-24199HIGH7.5smartdns commit 54b4dc was discovered to contain a misaligned address at smartdns/src/dns.c.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now