2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-2847 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s... |
| CVE-2024-2845 | MEDIUM | 6.4 | 0.4% | Apr 9, 2024 | The BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gutenb... |
| CVE-2024-2804 | CRITICAL | 9.8 | 0.7% | Apr 9, 2024 | The Network Summary plugin for WordPress is vulnerable to SQL Injection via the 'category' parameter in all versions up ... |
| CVE-2024-2792 | MEDIUM | 6.4 | 0.5% | Apr 9, 2024 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widgets in all versio... |
| CVE-2024-2789 | MEDIUM | 5.4 | 0.3% | Apr 9, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Calend... |
| CVE-2024-2788 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title HTML... |
| CVE-2024-2787 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Page Title HTML... |
| CVE-2024-2786 | MEDIUM | 5.4 | 0.5% | Apr 9, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in ... |
| CVE-2024-2783 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPr... |
| CVE-2024-2738 | MEDIUM | 6.1 | 0.6% | Apr 9, 2024 | The Permalink Manager Lite and Pro plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the ‘s’ pa... |
| CVE-2024-2693 | HIGH | 8.8 | 0.8% | Apr 9, 2024 | The Link Whisper Free plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0... |
| CVE-2024-2654 | MEDIUM | 6.8 | 0.9% | Apr 9, 2024 | The File Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.2.5 v... |
| CVE-2024-2650 | MEDIUM | 6.4 | 0.4% | Apr 9, 2024 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress... |
| CVE-2024-2623 | MEDIUM | 6.4 | 0.4% | Apr 9, 2024 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress... |
| CVE-2024-2543 | MEDIUM | 4.3 | 0.6% | Apr 9, 2024 | The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability... |
| CVE-2024-2536 | MEDIUM | 5.4 | 0.3% | Apr 9, 2024 | The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HowTo bloc... |
| CVE-2024-2513 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageAlt' block attribute in ... |
| CVE-2024-2507 | MEDIUM | 5.4 | 0.3% | Apr 9, 2024 | The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget button URL... |
| CVE-2024-2504 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2024-2501 | HIGH | 7.5 | 0.9% | Apr 9, 2024 | The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to PHP Object Injection in al... |
| CVE-2024-2492 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Twitter Twe... |
| CVE-2024-2457 | MEDIUM | 5.4 | 0.3% | Apr 9, 2024 | The Modal Window – create popup modal window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p... |
| CVE-2024-2456 | MEDIUM | 6.4 | 0.4% | Apr 9, 2024 | The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sho... |
| CVE-2024-2436 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s... |
| CVE-2024-2423 | MEDIUM | 6.4 | 0.4% | Apr 9, 2024 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now