2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4097 | HIGH | 7.2 | 0.6% | May 2, 2024 | The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature... |
| CVE-2024-4092 | MEDIUM | 5.4 | 0.4% | May 2, 2024 | The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘htmltag’ parameter in a... |
| CVE-2024-4086 | MEDIUM | 4.3 | 0.3% | May 2, 2024 | The CM Tooltip Glossary – Powerful Glossary Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in a... |
| CVE-2024-4085 | MEDIUM | 4.4 | 0.4% | May 2, 2024 | The Tabellen von faustball.com plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a... |
| CVE-2024-4083 | MEDIUM | 4.3 | 0.3% | May 2, 2024 | The Easy Restaurant Table Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to... |
| CVE-2024-4036 | MEDIUM | 5.4 | 0.6% | May 2, 2024 | The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the style parameter in all vers... |
| CVE-2024-4034 | MEDIUM | 6.4 | 0.6% | May 2, 2024 | The Virtue theme for WordPress is vulnerable to Stored Cross-Site Scripting via a Post Author's name in all versions up ... |
| CVE-2024-4033 | HIGH | 8.8 | 1.6% | May 2, 2024 | The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid... |
| CVE-2024-4003 | MEDIUM | 5.4 | 0.5% | May 2, 2024 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress... |
| CVE-2024-4000 | MEDIUM | 6.4 | 0.5% | May 2, 2024 | The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2024-3991 | MEDIUM | 5.4 | 0.4% | May 2, 2024 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) pl... |
| CVE-2024-3985 | MEDIUM | 5.4 | 0.4% | May 2, 2024 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Ca... |
| CVE-2024-3957 | HIGH | 7.3 | 0.9% | May 2, 2024 | The Booster for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and... |
| CVE-2024-3942 | MEDIUM | 5.4 | 0.4% | May 2, 2024 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthoriz... |
| CVE-2024-3936 | MEDIUM | 4.3 | 0.6% | May 2, 2024 | The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to ... |
| CVE-2024-3897 | MEDIUM | 5.3 | 0.6% | May 2, 2024 | The Popup Box – Best WordPress Popup Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a m... |
| CVE-2024-3895 | HIGH | 8.8 | 0.9% | May 2, 2024 | The WP Datepicker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch... |
| CVE-2024-3891 | MEDIUM | 5.4 | 0.4% | May 2, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML tags in widget... |
| CVE-2024-3885 | MEDIUM | 5.4 | 0.4% | May 2, 2024 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the subcontainer ... |
| CVE-2024-3870 | MEDIUM | 5.3 | 0.7% | May 2, 2024 | The Contact Form 7 Database Addon – CFDB7 plugin for WordPress is vulnerable to Sensitive Information Exposure in versio... |
| CVE-2024-3849 | HIGH | 8.8 | 1.7% | May 2, 2024 | The Click to Chat – HoliThemes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc... |
| CVE-2024-3819 | MEDIUM | 5.4 | 0.5% | May 2, 2024 | The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's JKit - Banner w... |
| CVE-2024-3747 | MEDIUM | 5.4 | 0.4% | May 2, 2024 | The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the className parameter in the About Me... |
| CVE-2024-3743 | MEDIUM | 5.4 | 0.6% | May 2, 2024 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Group... |
| CVE-2024-3734 | MEDIUM | 6.5 | 1.0% | May 2, 2024 | The FOX – Currency Switcher Professional for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Exe... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now