2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-3952MEDIUM6.4The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanc...
CVE-2024-3941MEDIUM4.7The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in some places, and is missing sanitisatio...
CVE-2024-3940HIGH8.8The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in place when updating its settings, which...
CVE-2024-3923MEDIUM5.4The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the li...
CVE-2024-3916MEDIUM6.4The Swift Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortc...
CVE-2024-3915MEDIUM5.3The Swift Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2024-3903HIGH7.1The Add Custom CSS and JS WordPress plugin through 1.20 does not have CSRF check in some places, and is missing sanitisa...
CVE-2024-3831MEDIUM5.4The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scrip...
CVE-2024-3828HIGH8.8The Spectra Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.5. ...
CVE-2024-3809HIGH8.8The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in...
CVE-2024-3808HIGH8.8The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in...
CVE-2024-3807HIGH8.8The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via 'por...
CVE-2024-3806CRITICAL9.8The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via the ...
CVE-2024-3796MEDIUM4.8Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/BackupSchedul...
CVE-2024-3795MEDIUM4.8Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/BackupTemplat...
CVE-2024-3794MEDIUM4.8Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/AdvancedSyste...
CVE-2024-3793MEDIUM4.8Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/CloudAccounts...
CVE-2024-3792MEDIUM4.8Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/DeviceReplica...
CVE-2024-3791MEDIUM4.8Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/SystemConfigu...
CVE-2024-3790MEDIUM4.8Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/SystemUsers, ...
CVE-2024-3789MEDIUM6.5Uncontrolled resource consumption vulnerability in White Bear Solutions WBSAirback, version 21.02.04. This vulnerability...
CVE-2024-3788MEDIUM6.6Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Lice...
CVE-2024-3787MEDIUM6.6Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 d...
CVE-2024-3727HIGH8.3A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authentica...
CVE-2024-3722MEDIUM5.4The Swift Performance Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now