2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-2401MEDIUM4.4The Admin Page Spider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio...
CVE-2024-2349MEDIUM6.4The Fancy Elementor Flipbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Fancy Elementor Fl...
CVE-2024-2346MEDIUM5.4The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Insecure Direct Obje...
CVE-2024-2345MEDIUM5.4The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2024-2328MEDIUM5.4The Real Media Library: Media Library Folder & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2024-2324MEDIUM5.4The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2024-2273MEDIUM5.4The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2024-2109MEDIUM5.3The Booster Extension plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in...
CVE-2024-2085MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 's...
CVE-2024-2084MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2024-2082MEDIUM6.1The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to Stored Cross...
CVE-2024-2043MEDIUM5.3The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized...
CVE-2024-25290HIGH8An issue in Casa Systems NL1901ACV R6B032 allows a remote attacker to execute arbitrary code via the userName parameter ...
CVE-2024-1993MEDIUM6.4The Icon Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all v...
CVE-2024-1959MEDIUM6.4The Social Sharing Plugin – Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu...
CVE-2024-1945HIGH7.1The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to...
CVE-2024-1897HIGH7.5The Grid Gallery – Photo Image Grid Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions u...
CVE-2024-1896HIGH7.5The Photo Gallery – Responsive Photo Gallery, Image Gallery, Portfolio Gallery, Logo Gallery And Team Gallery plugin for...
CVE-2024-1842MEDIUM5.4The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Heading tag attribute in a...
CVE-2024-1841MEDIUM5.4The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title tag attribute in all v...
CVE-2024-1840MEDIUM5.4The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Author tag attribute in all ...
CVE-2024-1809MEDIUM5.4The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to...
CVE-2024-1805MEDIUM5.4The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all v...
CVE-2024-1797HIGH8.8The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to SQL Injection via the 'st...
CVE-2024-1759MEDIUM5.4The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripti...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now