2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1133 | MEDIUM | 4.3 | 0.4% | Feb 29, 2024 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of restri... |
| CVE-2024-1130 | MEDIUM | 4.3 | 0.6% | Feb 29, 2024 | The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to unauthorized a... |
| CVE-2024-1129 | MEDIUM | 4.3 | 0.6% | Feb 29, 2024 | The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to unauthorized a... |
| CVE-2024-1128 | LOW | 3.5 | 0.5% | Feb 29, 2024 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to HTML Injection in all version... |
| CVE-2024-1091 | MEDIUM | 4.3 | 0.3% | Feb 29, 2024 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to ... |
| CVE-2024-1090 | MEDIUM | 4.3 | 0.3% | Feb 29, 2024 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to ... |
| CVE-2024-1089 | MEDIUM | 4.3 | 0.4% | Feb 29, 2024 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to ... |
| CVE-2024-1070 | MEDIUM | 5.4 | 0.5% | Feb 29, 2024 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the features attribu... |
| CVE-2024-1058 | MEDIUM | 5.4 | 0.4% | Feb 29, 2024 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the onclick paramete... |
| CVE-2024-1054 | MEDIUM | 5.4 | 0.3% | Feb 29, 2024 | The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wcj_pr... |
| CVE-2024-1044 | MEDIUM | 5.3 | 0.4% | Feb 29, 2024 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a mi... |
| CVE-2024-1043 | MEDIUM | 6.5 | 0.7% | Feb 29, 2024 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missi... |
| CVE-2024-0984 | MEDIUM | 4.3 | 0.4% | Feb 29, 2024 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to ... |
| CVE-2024-0983 | MEDIUM | 4.3 | 0.4% | Feb 29, 2024 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to ... |
| CVE-2024-0978 | MEDIUM | 5.3 | 0.5% | Feb 29, 2024 | The My Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl... |
| CVE-2024-0907 | MEDIUM | 4.3 | 0.6% | Feb 29, 2024 | The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to unauthorized a... |
| CVE-2024-0838 | MEDIUM | 5.4 | 0.5% | Feb 29, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the side image URL ... |
| CVE-2024-0821 | MEDIUM | 6.1 | 0.4% | Feb 29, 2024 | The Cost of Goods Sold (COGS): Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Reflected ... |
| CVE-2024-0792 | MEDIUM | 5.4 | 0.4% | Feb 29, 2024 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2024-0702 | HIGH | 7.3 | 0.5% | Feb 29, 2024 | The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to unauthorized access due to miss... |
| CVE-2024-0658 | MEDIUM | 4.8 | 0.3% | Feb 29, 2024 | The Insert PHP Code Snippet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user's name when a... |
| CVE-2024-0656 | MEDIUM | 4.8 | 0.3% | Feb 29, 2024 | The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vu... |
| CVE-2024-0621 | MEDIUM | 4.8 | 0.5% | Feb 29, 2024 | The Simple Share Buttons Adder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a... |
| CVE-2024-0620 | MEDIUM | 5.3 | 0.5% | Feb 29, 2024 | The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u... |
| CVE-2024-0616 | MEDIUM | 5.3 | 0.5% | Feb 29, 2024 | The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure i... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now