2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0839 | MEDIUM | 5.3 | 0.6% | Mar 13, 2024 | The FeedWordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and incl... |
| CVE-2024-0830 | MEDIUM | 4.3 | 0.3% | Mar 13, 2024 | The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Cross-Site Request Forgery in all... |
| CVE-2024-0829 | MEDIUM | 4.3 | 0.5% | Mar 13, 2024 | The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Missing Authorization in all vers... |
| CVE-2024-0828 | MEDIUM | 6.3 | 0.4% | Mar 13, 2024 | The Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to unauthoriz... |
| CVE-2024-0827 | MEDIUM | 4.3 | 0.2% | Mar 13, 2024 | The Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to Cross-Site... |
| CVE-2024-0700 | MEDIUM | 5.4 | 0.5% | Mar 13, 2024 | The Simple Tweet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Tweet this text value in all ... |
| CVE-2024-0687 | MEDIUM | 5.3 | 0.5% | Mar 13, 2024 | The Restrict User Access – Ultimate Membership & Content Protection plugin for WordPress is vulnerable to Information Ex... |
| CVE-2024-0683 | HIGH | 7.5 | 1.2% | Mar 13, 2024 | The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to missing capability ch... |
| CVE-2024-0681 | MEDIUM | 5.3 | 0.6% | Mar 13, 2024 | The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to information disclosure... |
| CVE-2024-0631 | MEDIUM | 5.3 | 0.6% | Mar 13, 2024 | The Duitku Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa... |
| CVE-2024-0614 | MEDIUM | 4.8 | 0.7% | Mar 13, 2024 | The Events Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions ... |
| CVE-2024-0592 | MEDIUM | 5.4 | 0.3% | Mar 13, 2024 | The Related Posts for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, ... |
| CVE-2024-0591 | MEDIUM | 6.1 | 0.6% | Mar 13, 2024 | The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Refl... |
| CVE-2024-0449 | MEDIUM | 4.8 | 0.5% | Mar 13, 2024 | The ArtiBot Free Chat Bot for WordPress WebSites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a... |
| CVE-2024-0447 | MEDIUM | 5 | 0.6% | Mar 13, 2024 | The ArtiBot Free Chat Bot for WordPress WebSites plugin for WordPress is vulnerable to unauthorized modification of data... |
| CVE-2024-0385 | MEDIUM | 4.3 | 0.6% | Mar 13, 2024 | The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check... |
| CVE-2024-0377 | MEDIUM | 5.3 | 0.7% | Mar 13, 2024 | The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to unauthorized modification of da... |
| CVE-2024-0369 | MEDIUM | 4.3 | 0.4% | Mar 13, 2024 | The Bulk Edit Post Titles plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab... |
| CVE-2024-0368 | HIGH | 8.6 | 0.8% | Mar 13, 2024 | The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Informatio... |
| CVE-2024-0326 | MEDIUM | 6.4 | 0.6% | Mar 13, 2024 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Link... |
| CVE-2024-0161 | HIGH | 8.4 | 0.2% | Mar 13, 2024 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulner... |
| CVE-2024-27441 | — | — | — | Mar 13, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-25155 | MEDIUM | 6.1 | 0.4% | Mar 13, 2024 | In FileCatalyst Direct 3.8.8 and earlier through 3.8.6, the web server does not properly sanitize illegal characters in ... |
| CVE-2024-25154 | MEDIUM | 5.3 | 0.5% | Mar 13, 2024 | Improper URL validation leads to path traversal in FileCatalyst Direct 3.8.8 and earlier allowing an encoded payload to ... |
| CVE-2024-25153 | CRITICAL | 9.8 | 41.7% | Mar 13, 2024 | A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outsid... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now