2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1893 | HIGH | 8.8 | 0.8% | Apr 9, 2024 | The Easy Property Listings plugin for WordPress is vulnerable to time-based SQL Injection via the ‘property_status’ shor... |
| CVE-2024-1852 | MEDIUM | 6.1 | 0.7% | Apr 9, 2024 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-F... |
| CVE-2024-1850 | MEDIUM | 6.3 | 0.5% | Apr 9, 2024 | The AI Post Generator | AutoWriter plugin for WordPress is vulnerable to unauthorized access, modification or deletion o... |
| CVE-2024-1813 | CRITICAL | 9.8 | 1.1% | Apr 9, 2024 | The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.... |
| CVE-2024-1812 | HIGH | 7.2 | 0.5% | Apr 9, 2024 | The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including... |
| CVE-2024-1794 | MEDIUM | 6.1 | 0.5% | Apr 9, 2024 | The Forminator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. 3gpp file) i... |
| CVE-2024-1792 | HIGH | 7.5 | 0.8% | Apr 9, 2024 | The CMB2 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.10.1 via des... |
| CVE-2024-1790 | MEDIUM | 4.9 | 0.8% | Apr 9, 2024 | The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Path Traversal in all versions up t... |
| CVE-2024-1774 | HIGH | 7.2 | 0.5% | Apr 9, 2024 | The Customily Product Personalizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user cookies in... |
| CVE-2024-1641 | MEDIUM | 5.4 | 0.5% | Apr 9, 2024 | The Accordion plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missin... |
| CVE-2024-1637 | MEDIUM | 4.3 | 0.5% | Apr 9, 2024 | The 360 Javascript Viewer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab... |
| CVE-2024-1587 | MEDIUM | 5.3 | 0.6% | Apr 9, 2024 | The Newsmatic theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, ... |
| CVE-2024-1571 | MEDIUM | 4.8 | 0.4% | Apr 9, 2024 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video Embed parameter in a... |
| CVE-2024-1498 | MEDIUM | 5.4 | 0.5% | Apr 9, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Photo ... |
| CVE-2024-1466 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slider_style... |
| CVE-2024-1465 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘carousel_ski... |
| CVE-2024-1464 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ attri... |
| CVE-2024-1463 | MEDIUM | 4.8 | 0.4% | Apr 9, 2024 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Course, ... |
| CVE-2024-1461 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ attri... |
| CVE-2024-1458 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘text_alignme... |
| CVE-2024-1424 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2024-1412 | MEDIUM | 6.1 | 0.5% | Apr 9, 2024 | The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘message’ and 'error' param... |
| CVE-2024-1387 | MEDIUM | 4.3 | 0.6% | Apr 9, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to insufficient aut... |
| CVE-2024-1352 | MEDIUM | 5.3 | 0.6% | Apr 9, 2024 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized a... |
| CVE-2024-1315 | HIGH | 8.8 | 0.5% | Apr 9, 2024 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Cross-Site Req... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now