2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-4455MEDIUM6.1The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘item’ parame...
CVE-2024-5315CRITICAL9.1Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could all...
CVE-2024-5314CRITICAL9.1Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could all...
CVE-2024-5310MEDIUM5.4A vulnerability classified as problematic has been found in JFinalCMS up to 20221020. This affects an unknown part of th...
CVE-2024-4037HIGH7.3The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and i...
CVE-2024-4366MEDIUM5.4The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bloc...
CVE-2024-5060MEDIUM5.4The LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor plugin for WordPress is vulnerable to Stored Cro...
CVE-2024-4485MEDIUM5.4The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre...
CVE-2024-4484MEDIUM5.4The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre...
CVE-2024-1376MEDIUM4.3The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing capability check...
CVE-2024-1332MEDIUM5.4The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg fil...
CVE-2024-0893MEDIUM4.3The Schema App Structured Data plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ...
CVE-2024-5142MEDIUM5.4Stored Cross-Site Scripting vulnerability in Social Module in M-Files Hubshare before version 5.0.6.0 allows authenticat...
CVE-2024-3718MEDIUM5.4The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the p...
CVE-2024-36361MEDIUM6.8Pug through 3.0.2 allows JavaScript code execution if an application accepts untrusted input for the name option of the ...
CVE-2024-1134MEDIUM5.4The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SEO title and descr...
CVE-2024-0867HIGH8.1The Email Log plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including,...
CVE-2024-3557MEDIUM5.4The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-2784MEDIUM5.4The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Hover Card w...
CVE-2024-2618MEDIUM5.4The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the size att...
CVE-2024-4544CRITICAL9.8The Pie Register - Social Sites Login (Add on) plugin for WordPress is vulnerable to authentication bypass in versions u...
CVE-2024-5205MEDIUM6.4The Videojs HTML5 Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's videojs_vide...
CVE-2024-4409MEDIUM4.3The WP-ViperGB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1....
CVE-2024-5279MEDIUM5.3A vulnerability was found in Qiwen Netdisk up to 1.4.0. It has been declared as problematic. Affected by this vulnerabil...
CVE-2024-5299HIGH8.8D-Link D-View execMonitorScript Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now