2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-30503MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EverPress Mailster...
CVE-2024-30483MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simple Sponsorship...
CVE-2024-30458HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOOCS – WooCommerce Currency Switcher.This issue affects W...
CVE-2024-30457HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF).This issu...
CVE-2024-30456HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WPCS.This issue affects WPCS: from n/a through 1.2.0.1.
CVE-2024-23449MEDIUM5.3An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment pro...
CVE-2024-2848HIGH7.5The Responsive theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ...
CVE-2024-3061HIGH7.2The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in a...
CVE-2024-2411CRITICAL9.8The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3...
CVE-2024-2409CRITICAL9.8The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3...
CVE-2024-2250MEDIUM6.4The 130+ Widgets | Best Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2024-2970MEDIUM4.3The News Wall plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1...
CVE-2024-2969MEDIUM5.4The WP-Eggdrop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0....
CVE-2024-2968MEDIUM4.8The WP-Eggdrop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t...
CVE-2024-2964MEDIUM4.3The Pocket News Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2024-2963MEDIUM4.8The Pocket News Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings such as "...
CVE-2024-2476MEDIUM4.3The OceanWP theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the lo...
CVE-2024-2280MEDIUM5.4The Better Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget link URL va...
CVE-2024-2116MEDIUM6.1The Christmas Greetings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the code parameter in a...
CVE-2024-2113MEDIUM4.3The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-...
CVE-2024-2108MEDIUM5.4The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored...
CVE-2024-1872HIGH8.8The Button plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.27 via d...
CVE-2024-1858MEDIUM5.4The Lightbox slider – Responsive Lightbox Gallery plugin for WordPress is vulnerable to PHP Object Injection in all vers...
CVE-2024-0956MEDIUM4.9The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is...
CVE-2024-0913HIGH7.2The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now