2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4261 | MEDIUM | 5.4 | 0.3% | May 22, 2024 | The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to arbitrary shortcode e... |
| CVE-2024-5196 | HIGH | 7.2 | 4.2% | May 22, 2024 | A vulnerability classified as critical has been found in Arris VAP2500 08.50. This affects an unknown part of the file /... |
| CVE-2024-36010 | MEDIUM | 5.5 | 0.2% | May 22, 2024 | In the Linux kernel, the following vulnerability has been resolved: igb: Fix string truncation warnings in igb_set_fw_v... |
| CVE-2024-5195 | HIGH | 7.2 | 4.2% | May 22, 2024 | A vulnerability was found in Arris VAP2500 08.50. It has been rated as critical. Affected by this issue is some unknown ... |
| CVE-2024-5194 | HIGH | 7.2 | 3.6% | May 22, 2024 | A vulnerability was found in Arris VAP2500 08.50. It has been declared as critical. Affected by this vulnerability is an... |
| CVE-2024-5193 | MEDIUM | 5.5 | 0.7% | May 22, 2024 | A security vulnerability has been detected in Ritlabs TinyWeb Server 1.94. This vulnerability affects unknown code of th... |
| CVE-2024-4262 | MEDIUM | 6.4 | 0.3% | May 22, 2024 | The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets ... |
| CVE-2024-4153 | — | — | — | May 22, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-5031 | MEDIUM | 6.4 | 0.3% | May 22, 2024 | The Memberpress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and inclu... |
| CVE-2024-5025 | MEDIUM | 5.4 | 0.3% | May 22, 2024 | The Memberpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘arglist’ parameter in all ver... |
| CVE-2024-4896 | MEDIUM | 5.4 | 0.3% | May 22, 2024 | The WPB Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in al... |
| CVE-2024-4362 | MEDIUM | 5.4 | 0.4% | May 22, 2024 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteor... |
| CVE-2024-3495 | CRITICAL | 9.8 | 13.6% | May 22, 2024 | The Country State City Dropdown CF7 plugin for WordPress is vulnerable to SQL Injection via the ‘cnt’ and 'sid' paramete... |
| CVE-2024-2036 | MEDIUM | 4.3 | 0.4% | May 22, 2024 | The ApplyOnline – Application Form Builder and Manager plugin for WordPress is vulnerable to unauthorized access of data... |
| CVE-2024-5147 | CRITICAL | 9.8 | 1.0% | May 22, 2024 | The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Local File Inclusion in all v... |
| CVE-2024-4157 | HIGH | 8.8 | 0.7% | May 22, 2024 | The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner... |
| CVE-2024-3671 | MEDIUM | 6.4 | 0.3% | May 22, 2024 | The Print-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'print-me' shortcod... |
| CVE-2024-3666 | MEDIUM | 6.4 | 0.3% | May 22, 2024 | The Opal Estate Pro – Property Management and Submission plugin for WordPress is vulnerable to Stored Cross-Site Scripti... |
| CVE-2024-32988 | HIGH | 7.5 | 0.4% | May 22, 2024 | 'OfferBox' App for Android versions 2.0.0 to 2.3.17 and 'OfferBox' App for iOS versions 2.1.7 to 2.6.14 use a hard-coded... |
| CVE-2024-2953 | MEDIUM | 4.8 | 0.3% | May 22, 2024 | The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters ... |
| CVE-2024-2163 | MEDIUM | 6.4 | 0.3% | May 22, 2024 | The Ninja Beaver Add-ons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2024-2119 | MEDIUM | 6.1 | 0.4% | May 22, 2024 | The LuckyWP Table of Contents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the attrs paramet... |
| CVE-2024-0632 | MEDIUM | 4.4 | 0.3% | May 22, 2024 | The Automatic Translator with Google Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2024-3927 | MEDIUM | 5.3 | 0.4% | May 22, 2024 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W... |
| CVE-2024-3663 | MEDIUM | 4.3 | 0.3% | May 22, 2024 | The WP Scraper plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_scr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now