2024 CVE Vulnerabilities
39,242 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4707 | MEDIUM | 5.4 | 0.3% | Jun 6, 2024 | The Materialis Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's materialis_c... |
| CVE-2024-4608 | MEDIUM | 5.4 | 0.3% | Jun 6, 2024 | The SellKit – Funnel builder and checkout optimizer for WooCommerce to sell more, faster plugin for WordPress is vulnera... |
| CVE-2024-4459 | MEDIUM | 5.4 | 0.3% | Jun 6, 2024 | The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's w... |
| CVE-2024-4458 | MEDIUM | 5.4 | 0.3% | Jun 6, 2024 | The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in several widgets... |
| CVE-2024-4364 | MEDIUM | 5.4 | 0.3% | Jun 6, 2024 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button wi... |
| CVE-2024-4212 | MEDIUM | 5.4 | 0.4% | Jun 6, 2024 | The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's T... |
| CVE-2024-2922 | MEDIUM | 5.4 | 0.3% | Jun 6, 2024 | The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget tags in... |
| CVE-2024-1175 | MEDIUM | 5.3 | 0.4% | Jun 6, 2024 | The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to unauthorized loss of data d... |
| CVE-2024-0972 | MEDIUM | 5.3 | 0.4% | Jun 6, 2024 | The BuddyPress Members Only plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ... |
| CVE-2024-2017 | MEDIUM | 5.4 | 0.3% | Jun 6, 2024 | The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to unauthorized access du... |
| CVE-2024-5342 | MEDIUM | 5.4 | 0.3% | Jun 6, 2024 | The Simple Image Popup Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sip... |
| CVE-2024-5324 | HIGH | 8.8 | 1.5% | Jun 6, 2024 | Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to... |
| CVE-2024-5224 | MEDIUM | 5.4 | 0.3% | Jun 6, 2024 | The Easy Social Like Box – Popup – Sidebar Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2024-5179 | HIGH | 8.8 | 0.9% | Jun 6, 2024 | The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i... |
| CVE-2024-5001 | MEDIUM | 5.4 | 0.3% | Jun 6, 2024 | The Image Hover Effects for Elementor with Lightbox and Flipbox plugin for WordPress is vulnerable to Stored Cross-Site ... |
| CVE-2024-4942 | MEDIUM | 4.8 | 0.3% | Jun 6, 2024 | The Custom Dash plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ... |
| CVE-2024-4788 | MEDIUM | 4.3 | 0.3% | Jun 6, 2024 | The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to unauthorized modification of data... |
| CVE-2024-4705 | MEDIUM | 5.4 | 0.3% | Jun 6, 2024 | The Testimonials Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonials ... |
| CVE-2024-4194 | HIGH | 7.3 | 0.5% | Jun 6, 2024 | The The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to arbitrary shortcode execution in all... |
| CVE-2024-2350 | MEDIUM | 5.4 | 0.3% | Jun 6, 2024 | The Clever Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CAFE Icon, CAF... |
| CVE-2024-0910 | MEDIUM | 5.3 | 0.5% | Jun 6, 2024 | The Restrict for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a... |
| CVE-2024-0912 | MEDIUM | 4.2 | 0.2% | Jun 6, 2024 | Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the C•CURE 9000 Web Server wil... |
| CVE-2024-5653 | CRITICAL | 9.8 | 0.5% | Jun 5, 2024 | A vulnerability, which was classified as critical, has been found in Chanjet Smooth T+system 3.5. This issue affects som... |
| CVE-2024-5171 | CRITICAL | 9.8 | 1.3% | Jun 5, 2024 | Integer overflow in libaom internal function img_alloc_helper can lead to heap buffer overflow. This function can be rea... |
| CVE-2024-36670 | HIGH | 8.8 | 0.3% | Jun 5, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mud... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now