2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-0964CRITICAL9.4A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API reques...
CVE-2024-24595HIGH7.1Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a co...
CVE-2024-1210MEDIUM5.3The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2024-1209MEDIUM5.3The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2024-1208MEDIUM5.3The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2024-1177MEDIUM5.3The WP Club Manager – WordPress Sports Club Plugin plugin for WordPress is vulnerable to unauthorized modification of da...
CVE-2024-1121MEDIUM5.3The Advanced Forms for ACF plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability...
CVE-2024-1092MEDIUM4.3The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is...
CVE-2024-1075MEDIUM5.3The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information...
CVE-2024-1072HIGH7.5The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for Wor...
CVE-2024-1046MEDIUM5.4The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres...
CVE-2024-0969MEDIUM5.3The ARMember plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, ...
CVE-2024-0961MEDIUM5.4The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the code editor in a...
CVE-2024-0954MEDIUM5.4The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress...
CVE-2024-0869MEDIUM6.5The Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay and Pexels plugin for WordPress is vulner...
CVE-2024-0859MEDIUM4.3The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2024-0835MEDIUM4.3The Royal Elementor Kit theme for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing ca...
CVE-2024-0834MEDIUM5.4The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link_to parameter...
CVE-2024-0823MEDIUM5.4The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' u...
CVE-2024-0797MEDIUM4.3The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is v...
CVE-2024-0796MEDIUM4.3The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is v...
CVE-2024-0791MEDIUM4.3The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to unauthorized acces...
CVE-2024-0790MEDIUM4.3The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to Cross-Site Request...
CVE-2024-0761HIGH7.5The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi...
CVE-2024-0709HIGH7.5The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coin...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now