2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-4275MEDIUM5.4The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress...
CVE-2024-4232MEDIUM5.4This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to lack ...
CVE-2024-4231MEDIUM6.8This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to prese...
CVE-2024-4213MEDIUM5.3The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions...
CVE-2024-4209MEDIUM5.4The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si...
CVE-2024-4193MEDIUM6.4The Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'testimonialcategory' s...
CVE-2024-4158MEDIUM5.4The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tagName’ parameter in versions up ...
CVE-2024-4150MEDIUM6.1The Simple Basic Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘scf_email’ p...
CVE-2024-4129HIGH8.8Improper Authentication vulnerability in Snow Software AB Snow License Manager on Windows allows a networked attacker to...
CVE-2024-4107MEDIUM5.4The Elementor Website Builder – More than Just a Page Builder Pro plugin for WordPress is vulnerable to Stored Cross-Sit...
CVE-2024-4104MEDIUM6.1The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '...
CVE-2024-4103MEDIUM4.3The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio...
CVE-2024-4082MEDIUM4.3The Joli FAQ SEO – WordPress FAQ Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
CVE-2024-4068HIGH7.5The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could le...
CVE-2024-4067MEDIUM5.3The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerabi...
CVE-2024-4046MEDIUM5.5Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerability will affect avail...
CVE-2024-4044HIGH7.8A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may...
CVE-2024-4041MEDIUM6.1The Yoast SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and i...
CVE-2024-4039MEDIUM6.5The The Orders Tracking for WooCommerce plugin for WordPress for WordPress is vulnerable to arbitrary shortcode executio...
CVE-2024-4038MEDIUM6.5The The Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro plugin for WordPress for WordPress is vulnerab...
CVE-2024-3990MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the To...
CVE-2024-3989MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2024-3974MEDIUM5.4The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_name’ parameter in versio...
CVE-2024-3956MEDIUM5.4The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pod...
CVE-2024-3954HIGH8.8The Ditty plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.1.38 via deserialization of...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now