2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1100CRITICAL10Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vadi Corporate Inf...
CVE-2024-5326HIGH8.8The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized modi...
CVE-2024-3583MEDIUM6.4The Simple Like Page Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode...
CVE-2024-4668MEDIUM6.4The Gum Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Price Table and Post S...
CVE-2024-4427MEDIUM4.3The Comparison Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2024-4426MEDIUM4.3The Comparison Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2024-4422MEDIUM5.4The Comparison Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slider title parameter i...
CVE-2024-4355MEDIUM4.3The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to...
CVE-2024-2657MEDIUM4.4The Font Farsi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t...
CVE-2024-2089MEDIUM5.4The Remote Content Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'remote_content' ...
CVE-2024-5327MEDIUM5.4The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to DOM-Ba...
CVE-2024-5073MEDIUM5.4The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress...
CVE-2024-5341MEDIUM5.4The The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-5207HIGH7.2The POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications plugin for W...
CVE-2024-36267HIGH8.1Path traversal vulnerability exists in Redmine DMSF Plugin versions prior to 3.1.4. If this vulnerability is exploited, ...
CVE-2024-4356MEDIUM6.4The List categories plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'categories' shor...
CVE-2024-4218MEDIUM6.5The AffiEasy plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1....
CVE-2024-3947MEDIUM4.3The WP To Do plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3....
CVE-2024-3946MEDIUM4.8The WP To Do plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to,...
CVE-2024-3945MEDIUM4.3The WP To Do plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3....
CVE-2024-3943MEDIUM4.3The WP To Do plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3....
CVE-2024-3277MEDIUM5The Yumpu ePaper publishing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap...
CVE-2024-5223MEDIUM6.4The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2024-3269MEDIUM5.4The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capabil...
CVE-2024-3190MEDIUM4.6The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cros...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now