2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-3198MEDIUM6.4The WP Font Awesome Share Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp...
CVE-2024-2088MEDIUM6.5The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
CVE-2024-1762MEDIUM6.1The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the H...
CVE-2024-1446MEDIUM4.3The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver...
CVE-2024-5092MEDIUM5.4The Elegant Addons for elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Swit...
CVE-2024-4971MEDIUM5.4The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ ...
CVE-2024-4443HIGH7.5The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based ...
CVE-2024-3611MEDIUM6.4The Toolbar Extras for Elementor & More – WordPress Admin Bar Enhanced plugin for WordPress is vulnerable to Stored Cros...
CVE-2024-3066MEDIUM5.4The Elegant Addons for elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widg...
CVE-2024-35162MEDIUM6.5Path traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6. If this vulne...
CVE-2024-31340MEDIUM4.8TP-Link Tether versions prior to 4.5.13 and TP-Link Tapo versions prior to 3.3.6 do not properly validate certificates, ...
CVE-2024-4980MEDIUM6.4The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'id', 'mixColor'...
CVE-2024-31396MEDIUM6.6Code injection vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series ver...
CVE-2024-31395MEDIUM6.1Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series ...
CVE-2024-31394MEDIUM6.5Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series v...
CVE-2024-30420MEDIUM4.4Server-side request forgery (SSRF) vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and ...
CVE-2024-30419MEDIUM5.4Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series ...
CVE-2024-0453HIGH7.7The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check...
CVE-2024-0452HIGH7.7The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check...
CVE-2024-0451MEDIUM5The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th...
CVE-2024-5190Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2024-3519MEDIUM6.1The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the lang parameter ...
CVE-2024-3518MEDIUM6.5The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all ver...
CVE-2024-21683HIGH8.8This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and...
CVE-2024-5040HIGH8.5There are multiple ways in LCDS LAquis SCADA for an attacker to access locations outside of their own directory.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now