2024 CVE Vulnerabilities

39,242 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-4707MEDIUM5.4The Materialis Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's materialis_c...
CVE-2024-4608MEDIUM5.4The SellKit – Funnel builder and checkout optimizer for WooCommerce to sell more, faster plugin for WordPress is vulnera...
CVE-2024-4459MEDIUM5.4The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's w...
CVE-2024-4458MEDIUM5.4The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in several widgets...
CVE-2024-4364MEDIUM5.4The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button wi...
CVE-2024-4212MEDIUM5.4The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's T...
CVE-2024-2922MEDIUM5.4The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget tags in...
CVE-2024-1175MEDIUM5.3The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to unauthorized loss of data d...
CVE-2024-0972MEDIUM5.3The BuddyPress Members Only plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ...
CVE-2024-2017MEDIUM5.4The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to unauthorized access du...
CVE-2024-5342MEDIUM5.4The Simple Image Popup Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sip...
CVE-2024-5324HIGH8.8Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to...
CVE-2024-5224MEDIUM5.4The Easy Social Like Box – Popup – Sidebar Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2024-5179HIGH8.8The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i...
CVE-2024-5001MEDIUM5.4The Image Hover Effects for Elementor with Lightbox and Flipbox plugin for WordPress is vulnerable to Stored Cross-Site ...
CVE-2024-4942MEDIUM4.8The Custom Dash plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ...
CVE-2024-4788MEDIUM4.3The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2024-4705MEDIUM5.4The Testimonials Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonials ...
CVE-2024-4194HIGH7.3The The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to arbitrary shortcode execution in all...
CVE-2024-2350MEDIUM5.4The Clever Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CAFE Icon, CAF...
CVE-2024-0910MEDIUM5.3The Restrict for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a...
CVE-2024-0912MEDIUM4.2Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the C•CURE 9000 Web Server wil...
CVE-2024-5653CRITICAL9.8A vulnerability, which was classified as critical, has been found in Chanjet Smooth T+system 3.5. This issue affects som...
CVE-2024-5171CRITICAL9.8Integer overflow in libaom internal function img_alloc_helper can lead to heap buffer overflow. This function can be rea...
CVE-2024-36670HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mud...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now