2024 CVE Vulnerabilities
39,242 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4621 | MEDIUM | 4.8 | 0.4% | Jun 7, 2024 | The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 does not sanitise and escape some of its... |
| CVE-2024-4620 | CRITICAL | 9.8 | 3.3% | Jun 7, 2024 | The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify u... |
| CVE-2024-4354 | MEDIUM | 6.4 | 0.4% | Jun 7, 2024 | The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Server-Side Request Forgery in all ... |
| CVE-2024-4042 | MEDIUM | 5.4 | 0.3% | Jun 7, 2024 | The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPre... |
| CVE-2024-3592 | MEDIUM | 6.5 | 0.5% | Jun 7, 2024 | The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to SQL I... |
| CVE-2024-3288 | MEDIUM | 5.4 | 0.3% | Jun 7, 2024 | The Logo Slider WordPress plugin before 4.0.0 does not validate and escape some of its Slider Settings before outputtin... |
| CVE-2024-5640 | MEDIUM | 5.4 | 0.3% | Jun 7, 2024 | The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is ... |
| CVE-2024-5612 | MEDIUM | 5.4 | 0.3% | Jun 7, 2024 | The Essential Addons for Elementor Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eael_l... |
| CVE-2024-4902 | HIGH | 7.2 | 0.5% | Jun 7, 2024 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via ... |
| CVE-2024-5425 | MEDIUM | 5.4 | 0.3% | Jun 7, 2024 | The WP jQuery Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ attribute in al... |
| CVE-2024-4887 | HIGH | 7.5 | 0.6% | Jun 7, 2024 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ... |
| CVE-2024-37385 | CRITICAL | 9.8 | 1.5% | Jun 7, 2024 | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_ide... |
| CVE-2024-37384 | MEDIUM | 6.1 | 0.5% | Jun 7, 2024 | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences. |
| CVE-2024-37383 | MEDIUM | 6.1 | 73.3% | Jun 7, 2024 | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes. |
| CVE-2024-36082 | MEDIUM | 6.5 | 0.5% | Jun 7, 2024 | SQL injection vulnerability in Music Store - WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated ... |
| CVE-2024-1988 | MEDIUM | 5.4 | 0.3% | Jun 7, 2024 | The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPre... |
| CVE-2024-5607 | MEDIUM | 5.4 | 0.3% | Jun 7, 2024 | The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized modification of data... |
| CVE-2024-3987 | MEDIUM | 5.4 | 0.3% | Jun 7, 2024 | The WP Mobile Menu – The Mobile-Friendly Responsive Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripti... |
| CVE-2024-1768 | MEDIUM | 5.4 | 0.3% | Jun 7, 2024 | The Clever Fox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's info box block in all ... |
| CVE-2024-1689 | MEDIUM | 4.3 | 0.3% | Jun 7, 2024 | The WooCommerce Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit... |
| CVE-2024-4013 | MEDIUM | 5.6 | 0.3% | Jun 6, 2024 | A bug exists in the API, mesh_node_power_off(), which fails to copy the contents of the Replay Protection List (RPL) fr... |
| CVE-2024-36823 | HIGH | 7.5 | 0.8% | Jun 6, 2024 | The encrypt() function of Ninja Core v7.0.0 was discovered to use a weak cryptographic algorithm, leading to a possible ... |
| CVE-2024-36775 | MEDIUM | 5.4 | 0.3% | Jun 6, 2024 | A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HT... |
| CVE-2024-36774 | HIGH | 7.2 | 0.7% | Jun 6, 2024 | An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a ... |
| CVE-2024-24199 | HIGH | 7.5 | 0.5% | Jun 6, 2024 | smartdns commit 54b4dc was discovered to contain a misaligned address at smartdns/src/dns.c. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now