2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-25099MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David de Boer Payt...
CVE-2024-25097MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeNcode LLC TNC...
CVE-2024-24549HIGH7.5Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing a...
CVE-2024-23672MEDIUM6.3Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep W...
CVE-2024-1997MEDIUM5.4The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premium_fbchat_app_id'...
CVE-2024-1996MEDIUM5.4The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's IHover widget ...
CVE-2024-1985MEDIUM6.1The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Display Name' parameter...
CVE-2024-1951HIGH7.5The Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to PHP Object Inj...
CVE-2024-1950HIGH8.8The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection i...
CVE-2024-1935MEDIUM6.1The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin for...
CVE-2024-1894MEDIUM5.4The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to Stored Cross-Site ...
CVE-2024-1862MEDIUM6.5The WooCommerce Add to Cart Custom Redirect plugin for WordPress is vulnerable to unauthorized modification of data and ...
CVE-2024-1854MEDIUM5.4The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored ...
CVE-2024-1843MEDIUM4.3The Auto Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2024-1806MEDIUM5.4The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres...
CVE-2024-1793HIGH7.2The AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth plugin fo...
CVE-2024-1772HIGH8.8The Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to PHP Object...
CVE-2024-1763MEDIUM5.3The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to unauthorized modification of data ...
CVE-2024-1751HIGH8.8The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via ...
CVE-2024-1723MEDIUM5.4The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters i...
CVE-2024-1691MEDIUM6.1The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE PRO plugin for WordPress is vulnerable to S...
CVE-2024-1690MEDIUM4.3The TeraWallet – Best WooCommerce Wallet System With Cashback Rewards, Partial Payment, Wallet Refunds plugin for WordPr...
CVE-2024-1684MEDIUM5.4The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Store...
CVE-2024-1680MEDIUM5.4The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Setting...
CVE-2024-1668MEDIUM6.5The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Expos...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now