2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4448 | MEDIUM | 6.4 | 0.5% | May 14, 2024 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress... |
| CVE-2024-4446 | MEDIUM | 6.4 | 0.4% | May 14, 2024 | The Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) plugin for... |
| CVE-2024-4444 | MEDIUM | 6.5 | 0.7% | May 14, 2024 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to bypass to user registration in versions up t... |
| CVE-2024-4441 | HIGH | 8.1 | 0.7% | May 14, 2024 | The XML Sitemap & Google News plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and incl... |
| CVE-2024-4434 | CRITICAL | 9.8 | 36.9% | May 14, 2024 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ p... |
| CVE-2024-4430 | MEDIUM | 5.4 | 0.5% | May 14, 2024 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ph... |
| CVE-2024-4425 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The access control in CemiPark software stores integration (e.g. FTP or SIP) credentials in plain-text. An attacker who ... |
| CVE-2024-4424 | MEDIUM | 6.1 | 0.4% | May 14, 2024 | The access control in CemiPark software does not properly validate user-entered data, which allows the stored cross-site... |
| CVE-2024-4423 | HIGH | 7.2 | 0.9% | May 14, 2024 | The access control in CemiPark software does not properly validate user-entered data, which allows the authentication by... |
| CVE-2024-4417 | MEDIUM | 4.4 | 0.4% | May 14, 2024 | The Falang multilanguage for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setti... |
| CVE-2024-4413 | CRITICAL | 9.8 | 0.9% | May 14, 2024 | The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, ... |
| CVE-2024-4411 | MEDIUM | 6.4 | 0.4% | May 14, 2024 | The Mihdan: Yandex Turbo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortco... |
| CVE-2024-4398 | MEDIUM | 6.4 | 0.5% | May 14, 2024 | The HTML5 Audio Player- Best WordPress Audio Player Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scrip... |
| CVE-2024-4397 | HIGH | 8.8 | 1.0% | May 14, 2024 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t... |
| CVE-2024-4386 | MEDIUM | 6.4 | 0.4% | May 14, 2024 | The Gallery Block (Meow Gallery) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data_atts’ p... |
| CVE-2024-4383 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_su... |
| CVE-2024-4339 | MEDIUM | 5.4 | 0.3% | May 14, 2024 | The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is ... |
| CVE-2024-4335 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘text... |
| CVE-2024-4329 | MEDIUM | 6.4 | 0.4% | May 14, 2024 | The Thim Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all v... |
| CVE-2024-4317 | MEDIUM | 4.3 | 0.7% | May 14, 2024 | Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database u... |
| CVE-2024-4316 | MEDIUM | 5.4 | 0.3% | May 14, 2024 | The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gute... |
| CVE-2024-4314 | MEDIUM | 4.3 | 0.2% | May 14, 2024 | The Hostel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5.... |
| CVE-2024-4312 | MEDIUM | 4.3 | 0.2% | May 14, 2024 | The Soccer Engine – Soccer Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ... |
| CVE-2024-4280 | MEDIUM | 5.3 | 0.4% | May 14, 2024 | The White Label CMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ... |
| CVE-2024-4277 | MEDIUM | 5.4 | 0.3% | May 14, 2024 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘layout_... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now