2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3198 | MEDIUM | 6.4 | 0.3% | May 22, 2024 | The WP Font Awesome Share Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp... |
| CVE-2024-2088 | MEDIUM | 6.5 | 0.3% | May 22, 2024 | The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Sensitive Information Exposure in all... |
| CVE-2024-1762 | MEDIUM | 6.1 | 0.4% | May 22, 2024 | The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the H... |
| CVE-2024-1446 | MEDIUM | 4.3 | 0.2% | May 22, 2024 | The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver... |
| CVE-2024-5092 | MEDIUM | 5.4 | 0.3% | May 22, 2024 | The Elegant Addons for elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Swit... |
| CVE-2024-4971 | MEDIUM | 5.4 | 0.3% | May 22, 2024 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ ... |
| CVE-2024-4443 | HIGH | 7.5 | 10.3% | May 22, 2024 | The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based ... |
| CVE-2024-3611 | MEDIUM | 6.4 | 0.3% | May 22, 2024 | The Toolbar Extras for Elementor & More – WordPress Admin Bar Enhanced plugin for WordPress is vulnerable to Stored Cros... |
| CVE-2024-3066 | MEDIUM | 5.4 | 0.3% | May 22, 2024 | The Elegant Addons for elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widg... |
| CVE-2024-35162 | MEDIUM | 6.5 | 0.7% | May 22, 2024 | Path traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6. If this vulne... |
| CVE-2024-31340 | MEDIUM | 4.8 | 0.2% | May 22, 2024 | TP-Link Tether versions prior to 4.5.13 and TP-Link Tapo versions prior to 3.3.6 do not properly validate certificates, ... |
| CVE-2024-4980 | MEDIUM | 6.4 | 0.3% | May 22, 2024 | The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'id', 'mixColor'... |
| CVE-2024-31396 | MEDIUM | 6.6 | 0.4% | May 22, 2024 | Code injection vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series ver... |
| CVE-2024-31395 | MEDIUM | 6.1 | 0.3% | May 22, 2024 | Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series ... |
| CVE-2024-31394 | MEDIUM | 6.5 | 0.7% | May 22, 2024 | Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series v... |
| CVE-2024-30420 | MEDIUM | 4.4 | 0.3% | May 22, 2024 | Server-side request forgery (SSRF) vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and ... |
| CVE-2024-30419 | MEDIUM | 5.4 | 0.2% | May 22, 2024 | Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series ... |
| CVE-2024-0453 | HIGH | 7.7 | 0.4% | May 22, 2024 | The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check... |
| CVE-2024-0452 | HIGH | 7.7 | 0.4% | May 22, 2024 | The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check... |
| CVE-2024-0451 | MEDIUM | 5 | 0.4% | May 22, 2024 | The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th... |
| CVE-2024-5190 | — | — | — | May 22, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2024-3519 | MEDIUM | 6.1 | 0.3% | May 22, 2024 | The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the lang parameter ... |
| CVE-2024-3518 | MEDIUM | 6.5 | 0.5% | May 22, 2024 | The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all ver... |
| CVE-2024-21683 | HIGH | 8.8 | 88.3% | May 21, 2024 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and... |
| CVE-2024-5040 | HIGH | 8.5 | 0.4% | May 21, 2024 | There are multiple ways in LCDS LAquis SCADA for an attacker to access locations outside of their own directory. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now