2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4275 | MEDIUM | 5.4 | 0.3% | May 14, 2024 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress... |
| CVE-2024-4232 | MEDIUM | 5.4 | 0.3% | May 14, 2024 | This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to lack ... |
| CVE-2024-4231 | MEDIUM | 6.8 | 0.6% | May 14, 2024 | This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to prese... |
| CVE-2024-4213 | MEDIUM | 5.3 | 0.5% | May 14, 2024 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions... |
| CVE-2024-4209 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si... |
| CVE-2024-4193 | MEDIUM | 6.4 | 0.4% | May 14, 2024 | The Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'testimonialcategory' s... |
| CVE-2024-4158 | MEDIUM | 5.4 | 0.3% | May 14, 2024 | The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tagName’ parameter in versions up ... |
| CVE-2024-4150 | MEDIUM | 6.1 | 0.5% | May 14, 2024 | The Simple Basic Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘scf_email’ p... |
| CVE-2024-4129 | HIGH | 8.8 | 0.5% | May 14, 2024 | Improper Authentication vulnerability in Snow Software AB Snow License Manager on Windows allows a networked attacker to... |
| CVE-2024-4107 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The Elementor Website Builder – More than Just a Page Builder Pro plugin for WordPress is vulnerable to Stored Cross-Sit... |
| CVE-2024-4104 | MEDIUM | 6.1 | 0.5% | May 14, 2024 | The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '... |
| CVE-2024-4103 | MEDIUM | 4.3 | 0.2% | May 14, 2024 | The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio... |
| CVE-2024-4082 | MEDIUM | 4.3 | 0.2% | May 14, 2024 | The Joli FAQ SEO – WordPress FAQ Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions... |
| CVE-2024-4068 | HIGH | 7.5 | 1.5% | May 14, 2024 | The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could le... |
| CVE-2024-4067 | MEDIUM | 5.3 | 1.4% | May 14, 2024 | The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerabi... |
| CVE-2024-4046 | MEDIUM | 5.5 | 0.1% | May 14, 2024 | Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerability will affect avail... |
| CVE-2024-4044 | HIGH | 7.8 | 14.7% | May 14, 2024 | A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may... |
| CVE-2024-4041 | MEDIUM | 6.1 | 0.8% | May 14, 2024 | The Yoast SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and i... |
| CVE-2024-4039 | MEDIUM | 6.5 | 0.6% | May 14, 2024 | The The Orders Tracking for WooCommerce plugin for WordPress for WordPress is vulnerable to arbitrary shortcode executio... |
| CVE-2024-4038 | MEDIUM | 6.5 | 0.5% | May 14, 2024 | The The Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro plugin for WordPress for WordPress is vulnerab... |
| CVE-2024-3990 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the To... |
| CVE-2024-3989 | MEDIUM | 5.4 | 0.3% | May 14, 2024 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2024-3974 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_name’ parameter in versio... |
| CVE-2024-3956 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pod... |
| CVE-2024-3954 | HIGH | 8.8 | 0.7% | May 14, 2024 | The Ditty plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.1.38 via deserialization of... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now