2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1642 | MEDIUM | 4.3 | 0.3% | Mar 13, 2024 | The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to Cross-... |
| CVE-2024-1640 | MEDIUM | 5.3 | 0.5% | Mar 13, 2024 | The Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form plugin fo... |
| CVE-2024-1585 | MEDIUM | 5.4 | 0.5% | Mar 13, 2024 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu... |
| CVE-2024-1541 | MEDIUM | 5.4 | 0.5% | Mar 13, 2024 | The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2024-1537 | MEDIUM | 6.4 | 0.4% | Mar 13, 2024 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress... |
| CVE-2024-1536 | HIGH | 7.4 | 0.5% | Mar 13, 2024 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress... |
| CVE-2024-1535 | MEDIUM | 5.4 | 0.6% | Mar 13, 2024 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres... |
| CVE-2024-1505 | HIGH | 8.8 | 0.8% | Mar 13, 2024 | The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to privilege esc... |
| CVE-2024-1499 | MEDIUM | 5.4 | 0.5% | Mar 13, 2024 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pricing Table widge... |
| CVE-2024-1497 | MEDIUM | 5.4 | 0.5% | Mar 13, 2024 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form widget addr2_w... |
| CVE-2024-1489 | MEDIUM | 4.3 | 0.2% | Mar 13, 2024 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ... |
| CVE-2024-1484 | MEDIUM | 6.1 | 0.5% | Mar 13, 2024 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Reflected Cross-Site Scr... |
| CVE-2024-1479 | MEDIUM | 5.3 | 0.7% | Mar 13, 2024 | The WP Show Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ... |
| CVE-2024-1462 | MEDIUM | 5.3 | 0.5% | Mar 13, 2024 | The Maintenance Page plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and includi... |
| CVE-2024-1452 | MEDIUM | 4.3 | 0.6% | Mar 13, 2024 | The GenerateBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu... |
| CVE-2024-1422 | MEDIUM | 5.4 | 0.5% | Mar 13, 2024 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the modal popup widge... |
| CVE-2024-1414 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Call To Act... |
| CVE-2024-1413 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown T... |
| CVE-2024-1409 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres... |
| CVE-2024-1393 | MEDIUM | 5.4 | 0.5% | Mar 13, 2024 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'icon_align' attr... |
| CVE-2024-1392 | MEDIUM | 5.4 | 0.5% | Mar 13, 2024 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button1_icon' at... |
| CVE-2024-1391 | MEDIUM | 5.4 | 0.5% | Mar 13, 2024 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eae_custom_overl... |
| CVE-2024-1383 | MEDIUM | 6.1 | 0.6% | Mar 13, 2024 | The WPvivid Backup for MainWP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' paramete... |
| CVE-2024-1380 | MEDIUM | 5.3 | 50.2% | Mar 13, 2024 | The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa... |
| CVE-2024-1370 | MEDIUM | 4.3 | 0.4% | Mar 13, 2024 | The Maintenance Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now