2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-2348MEDIUM6.4The Gum Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Meta widget in al...
CVE-2024-2347MEDIUM6.4The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name in all versions up ...
CVE-2024-2344HIGH7.2The Avada theme for WordPress is vulnerable to SQL Injection via the 'entry' parameter in all versions up to, and includ...
CVE-2024-2343MEDIUM6.4The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Server-Side Request Forgery...
CVE-2024-2342HIGH8.8The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL...
CVE-2024-2341MEDIUM6.5The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL...
CVE-2024-2340MEDIUM5.3The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11...
CVE-2024-2336MEDIUM5.4The Popup Maker – Popup for opt-ins, lead gen, & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2024-2335MEDIUM6.4The Elements Plus! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widget link URLs in al...
CVE-2024-2334MEDIUM6.4The Template Kit – Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the template upload func...
CVE-2024-2327MEDIUM6.4The Global Elementor Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button link URL i...
CVE-2024-2325MEDIUM6.1The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the searchll parameter in all ...
CVE-2024-2311MEDIUM5.4The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions u...
CVE-2024-2306MEDIUM6.4The Revslider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg upload in all versions up to, an...
CVE-2024-2305MEDIUM5.4The Cards for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the BootstrapCard lin...
CVE-2024-2302MEDIUM5.3The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPr...
CVE-2024-2289MEDIUM5.4The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link in ...
CVE-2024-2287MEDIUM6.4The Knight Lab Timeline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) ...
CVE-2024-2261MEDIUM4.3The Event Tickets and Registration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ...
CVE-2024-2226MEDIUM5.4The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Store...
CVE-2024-2222MEDIUM4.3The Advanced Classifieds & Directory Pro plugin for WordPress is vulnerable to unauthorized loss of data due to a missin...
CVE-2024-2200MEDIUM6.1The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cntctfrm_c...
CVE-2024-2198MEDIUM6.1The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cntctfrm_c...
CVE-2024-2187MEDIUM5.4The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonia...
CVE-2024-2186MEDIUM5.4The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Team Membe...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now