2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-4448MEDIUM6.4The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress...
CVE-2024-4446MEDIUM6.4The Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) plugin for...
CVE-2024-4444MEDIUM6.5The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to bypass to user registration in versions up t...
CVE-2024-4441HIGH8.1The XML Sitemap & Google News plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and incl...
CVE-2024-4434CRITICAL9.8The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ p...
CVE-2024-4430MEDIUM5.4The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ph...
CVE-2024-4425MEDIUM5.4The access control in CemiPark software stores integration (e.g. FTP or SIP) credentials in plain-text. An attacker who ...
CVE-2024-4424MEDIUM6.1The access control in CemiPark software does not properly validate user-entered data, which allows the stored cross-site...
CVE-2024-4423HIGH7.2The access control in CemiPark software does not properly validate user-entered data, which allows the authentication by...
CVE-2024-4417MEDIUM4.4The Falang multilanguage for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setti...
CVE-2024-4413CRITICAL9.8The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, ...
CVE-2024-4411MEDIUM6.4The Mihdan: Yandex Turbo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortco...
CVE-2024-4398MEDIUM6.4The HTML5 Audio Player- Best WordPress Audio Player Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scrip...
CVE-2024-4397HIGH8.8The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t...
CVE-2024-4386MEDIUM6.4The Gallery Block (Meow Gallery) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data_atts’ p...
CVE-2024-4383MEDIUM5.4The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_su...
CVE-2024-4339MEDIUM5.4The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is ...
CVE-2024-4335MEDIUM5.4The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘text...
CVE-2024-4329MEDIUM6.4The Thim Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all v...
CVE-2024-4317MEDIUM4.3Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database u...
CVE-2024-4316MEDIUM5.4The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gute...
CVE-2024-4314MEDIUM4.3The Hostel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5....
CVE-2024-4312MEDIUM4.3The Soccer Engine – Soccer Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ...
CVE-2024-4280MEDIUM5.3The White Label CMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2024-4277MEDIUM5.4The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘layout_...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now