2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-2348 | MEDIUM | 6.4 | 0.4% | Apr 9, 2024 | The Gum Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Meta widget in al... |
| CVE-2024-2347 | MEDIUM | 6.4 | 0.4% | Apr 9, 2024 | The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name in all versions up ... |
| CVE-2024-2344 | HIGH | 7.2 | 0.8% | Apr 9, 2024 | The Avada theme for WordPress is vulnerable to SQL Injection via the 'entry' parameter in all versions up to, and includ... |
| CVE-2024-2343 | MEDIUM | 6.4 | 0.5% | Apr 9, 2024 | The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Server-Side Request Forgery... |
| CVE-2024-2342 | HIGH | 8.8 | 0.6% | Apr 9, 2024 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL... |
| CVE-2024-2341 | MEDIUM | 6.5 | 0.6% | Apr 9, 2024 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL... |
| CVE-2024-2340 | MEDIUM | 5.3 | 28.0% | Apr 9, 2024 | The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11... |
| CVE-2024-2336 | MEDIUM | 5.4 | 0.3% | Apr 9, 2024 | The Popup Maker – Popup for opt-ins, lead gen, & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2024-2335 | MEDIUM | 6.4 | 0.3% | Apr 9, 2024 | The Elements Plus! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widget link URLs in al... |
| CVE-2024-2334 | MEDIUM | 6.4 | 0.4% | Apr 9, 2024 | The Template Kit – Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the template upload func... |
| CVE-2024-2327 | MEDIUM | 6.4 | 0.3% | Apr 9, 2024 | The Global Elementor Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button link URL i... |
| CVE-2024-2325 | MEDIUM | 6.1 | 0.4% | Apr 9, 2024 | The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the searchll parameter in all ... |
| CVE-2024-2311 | MEDIUM | 5.4 | 0.7% | Apr 9, 2024 | The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions u... |
| CVE-2024-2306 | MEDIUM | 6.4 | 0.3% | Apr 9, 2024 | The Revslider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg upload in all versions up to, an... |
| CVE-2024-2305 | MEDIUM | 5.4 | 0.3% | Apr 9, 2024 | The Cards for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the BootstrapCard lin... |
| CVE-2024-2302 | MEDIUM | 5.3 | 0.6% | Apr 9, 2024 | The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPr... |
| CVE-2024-2289 | MEDIUM | 5.4 | 0.3% | Apr 9, 2024 | The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link in ... |
| CVE-2024-2287 | MEDIUM | 6.4 | 0.4% | Apr 9, 2024 | The Knight Lab Timeline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) ... |
| CVE-2024-2261 | MEDIUM | 4.3 | 0.4% | Apr 9, 2024 | The Event Tickets and Registration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ... |
| CVE-2024-2226 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Store... |
| CVE-2024-2222 | MEDIUM | 4.3 | 0.5% | Apr 9, 2024 | The Advanced Classifieds & Directory Pro plugin for WordPress is vulnerable to unauthorized loss of data due to a missin... |
| CVE-2024-2200 | MEDIUM | 6.1 | 0.5% | Apr 9, 2024 | The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cntctfrm_c... |
| CVE-2024-2198 | MEDIUM | 6.1 | 0.5% | Apr 9, 2024 | The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cntctfrm_c... |
| CVE-2024-2187 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonia... |
| CVE-2024-2186 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Team Membe... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now