2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-30503 | MEDIUM | 6.1 | 0.4% | Mar 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EverPress Mailster... |
| CVE-2024-30483 | MEDIUM | 5.4 | 0.4% | Mar 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simple Sponsorship... |
| CVE-2024-30458 | HIGH | 8.8 | 0.2% | Mar 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOOCS – WooCommerce Currency Switcher.This issue affects W... |
| CVE-2024-30457 | HIGH | 8.8 | 0.2% | Mar 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF).This issu... |
| CVE-2024-30456 | HIGH | 8.8 | 0.2% | Mar 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WPCS.This issue affects WPCS: from n/a through 1.2.0.1. |
| CVE-2024-23449 | MEDIUM | 5.3 | 0.7% | Mar 29, 2024 | An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment pro... |
| CVE-2024-2848 | HIGH | 7.5 | 0.7% | Mar 29, 2024 | The Responsive theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ... |
| CVE-2024-3061 | HIGH | 7.2 | 0.8% | Mar 29, 2024 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in a... |
| CVE-2024-2411 | CRITICAL | 9.8 | 1.5% | Mar 29, 2024 | The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3... |
| CVE-2024-2409 | CRITICAL | 9.8 | 0.8% | Mar 29, 2024 | The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3... |
| CVE-2024-2250 | MEDIUM | 6.4 | 0.3% | Mar 29, 2024 | The 130+ Widgets | Best Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2024-2970 | MEDIUM | 4.3 | 0.2% | Mar 29, 2024 | The News Wall plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1... |
| CVE-2024-2969 | MEDIUM | 5.4 | 0.2% | Mar 29, 2024 | The WP-Eggdrop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.... |
| CVE-2024-2968 | MEDIUM | 4.8 | 0.3% | Mar 29, 2024 | The WP-Eggdrop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t... |
| CVE-2024-2964 | MEDIUM | 4.3 | 0.2% | Mar 29, 2024 | The Pocket News Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2024-2963 | MEDIUM | 4.8 | 0.3% | Mar 29, 2024 | The Pocket News Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings such as "... |
| CVE-2024-2476 | MEDIUM | 4.3 | 0.4% | Mar 29, 2024 | The OceanWP theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the lo... |
| CVE-2024-2280 | MEDIUM | 5.4 | 0.4% | Mar 29, 2024 | The Better Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget link URL va... |
| CVE-2024-2116 | MEDIUM | 6.1 | 0.5% | Mar 29, 2024 | The Christmas Greetings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the code parameter in a... |
| CVE-2024-2113 | MEDIUM | 4.3 | 0.2% | Mar 29, 2024 | The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-... |
| CVE-2024-2108 | MEDIUM | 5.4 | 0.3% | Mar 29, 2024 | The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored... |
| CVE-2024-1872 | HIGH | 8.8 | 0.9% | Mar 29, 2024 | The Button plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.27 via d... |
| CVE-2024-1858 | MEDIUM | 5.4 | 0.5% | Mar 29, 2024 | The Lightbox slider – Responsive Lightbox Gallery plugin for WordPress is vulnerable to PHP Object Injection in all vers... |
| CVE-2024-0956 | MEDIUM | 4.9 | 0.5% | Mar 29, 2024 | The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is... |
| CVE-2024-0913 | HIGH | 7.2 | 0.6% | Mar 29, 2024 | The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now