2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-2401 | MEDIUM | 4.4 | 0.4% | May 2, 2024 | The Admin Page Spider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio... |
| CVE-2024-2349 | MEDIUM | 6.4 | 0.4% | May 2, 2024 | The Fancy Elementor Flipbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Fancy Elementor Fl... |
| CVE-2024-2346 | MEDIUM | 5.4 | 0.3% | May 2, 2024 | The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Insecure Direct Obje... |
| CVE-2024-2345 | MEDIUM | 5.4 | 0.3% | May 2, 2024 | The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2024-2328 | MEDIUM | 5.4 | 0.4% | May 2, 2024 | The Real Media Library: Media Library Folder & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2024-2324 | MEDIUM | 5.4 | 0.3% | May 2, 2024 | The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2024-2273 | MEDIUM | 5.4 | 0.3% | May 2, 2024 | The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2024-2109 | MEDIUM | 5.3 | 0.5% | May 2, 2024 | The Booster Extension plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in... |
| CVE-2024-2085 | MEDIUM | 5.4 | 0.3% | May 2, 2024 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 's... |
| CVE-2024-2084 | MEDIUM | 5.4 | 0.3% | May 2, 2024 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2024-2082 | MEDIUM | 6.1 | 0.4% | May 2, 2024 | The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2024-2043 | MEDIUM | 5.3 | 0.5% | May 2, 2024 | The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized... |
| CVE-2024-25290 | HIGH | 8 | 0.7% | May 2, 2024 | An issue in Casa Systems NL1901ACV R6B032 allows a remote attacker to execute arbitrary code via the userName parameter ... |
| CVE-2024-1993 | MEDIUM | 6.4 | 0.4% | May 2, 2024 | The Icon Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all v... |
| CVE-2024-1959 | MEDIUM | 6.4 | 0.4% | May 2, 2024 | The Social Sharing Plugin – Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu... |
| CVE-2024-1945 | HIGH | 7.1 | 0.4% | May 2, 2024 | The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to... |
| CVE-2024-1897 | HIGH | 7.5 | 0.9% | May 2, 2024 | The Grid Gallery – Photo Image Grid Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions u... |
| CVE-2024-1896 | HIGH | 7.5 | 0.9% | May 2, 2024 | The Photo Gallery – Responsive Photo Gallery, Image Gallery, Portfolio Gallery, Logo Gallery And Team Gallery plugin for... |
| CVE-2024-1842 | MEDIUM | 5.4 | 0.3% | May 2, 2024 | The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Heading tag attribute in a... |
| CVE-2024-1841 | MEDIUM | 5.4 | 0.3% | May 2, 2024 | The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title tag attribute in all v... |
| CVE-2024-1840 | MEDIUM | 5.4 | 0.3% | May 2, 2024 | The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Author tag attribute in all ... |
| CVE-2024-1809 | MEDIUM | 5.4 | 0.3% | May 2, 2024 | The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to... |
| CVE-2024-1805 | MEDIUM | 5.4 | 0.3% | May 2, 2024 | The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all v... |
| CVE-2024-1797 | HIGH | 8.8 | 0.6% | May 2, 2024 | The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to SQL Injection via the 'st... |
| CVE-2024-1759 | MEDIUM | 5.4 | 0.3% | May 2, 2024 | The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripti... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now