2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4097 | HIGH | 7.2 | 0.6% | May 2, 2024 | The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature... |
| CVE-2024-4033 | HIGH | 8.8 | 1.6% | May 2, 2024 | The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid... |
| CVE-2024-3957 | HIGH | 7.3 | 0.9% | May 2, 2024 | The Booster for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and... |
| CVE-2024-3895 | HIGH | 8.8 | 0.9% | May 2, 2024 | The WP Datepicker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch... |
| CVE-2024-3849 | HIGH | 8.8 | 1.7% | May 2, 2024 | The Click to Chat – HoliThemes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc... |
| CVE-2024-3717 | HIGH | 7.5 | 0.7% | May 2, 2024 | The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Expo... |
| CVE-2024-3715 | HIGH | 7.2 | 0.6% | May 2, 2024 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Script... |
| CVE-2024-3500 | HIGH | 8.8 | 1.1% | May 2, 2024 | The ElementsKit Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6... |
| CVE-2024-3499 | HIGH | 8.8 | 1.1% | May 2, 2024 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i... |
| CVE-2024-3047 | HIGH | 7.2 | 0.4% | May 2, 2024 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in ve... |
| CVE-2024-2831 | HIGH | 8.8 | 0.6% | May 2, 2024 | The Calendar plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcodes in all versions up to, and ... |
| CVE-2024-2661 | HIGH | 8.8 | 0.6% | May 2, 2024 | The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plug... |
| CVE-2024-2417 | HIGH | 8.8 | 0.9% | May 2, 2024 | The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is ... |
| CVE-2024-25290 | HIGH | 8 | 0.7% | May 2, 2024 | An issue in Casa Systems NL1901ACV R6B032 allows a remote attacker to execute arbitrary code via the userName parameter ... |
| CVE-2024-1945 | HIGH | 7.1 | 0.4% | May 2, 2024 | The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to... |
| CVE-2024-1897 | HIGH | 7.5 | 0.9% | May 2, 2024 | The Grid Gallery – Photo Image Grid Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions u... |
| CVE-2024-1896 | HIGH | 7.5 | 0.9% | May 2, 2024 | The Photo Gallery – Responsive Photo Gallery, Image Gallery, Portfolio Gallery, Logo Gallery And Team Gallery plugin for... |
| CVE-2024-1797 | HIGH | 8.8 | 0.6% | May 2, 2024 | The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to SQL Injection via the 'st... |
| CVE-2024-1677 | HIGH | 8.8 | 0.5% | May 2, 2024 | The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is ... |
| CVE-2024-1173 | HIGH | 7.2 | 0.8% | May 2, 2024 | The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is... |
| CVE-2024-33530 | HIGH | 7.5 | 0.7% | May 2, 2024 | In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the dis... |
| CVE-2024-31964 | HIGH | 7.5 | 0.6% | May 2, 2024 | A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.... |
| CVE-2024-29309 | HIGH | 7.7 | 0.7% | May 2, 2024 | An issue in Alfresco Content Services v.23.3.0.7 allows a remote attacker to execute arbitrary code via the Transfer Ser... |
| CVE-2024-3544 | HIGH | 7.5 | 0.4% | May 2, 2024 | Unauthenticated attackers can perform actions, using SSH private keys, by knowing the IP address and having access to t... |
| CVE-2024-3543 | HIGH | 7.5 | 0.3% | May 2, 2024 | Use of reversible password encryption algorithm allows attackers to decrypt passwords. Sensitive information can be ea... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now