2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-5087MEDIUM5.4The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to unauthorized modification of data due t...
CVE-2024-4661MEDIUM4.3The WP Reset plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o...
CVE-2024-5770MEDIUM4.3The WP Force SSL & HTTPS SSL Redirect plugin for WordPress is vulnerable to unauthorized modification of data due to a m...
CVE-2024-5663MEDIUM5.4The Cards for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Cards wi...
CVE-2024-37162MEDIUM5.3zsa is a library for building typesafe server actions in Next.js. All users are impacted. The zsa application transfers ...
CVE-2024-36788MEDIUM4.8Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 does not properly set the HTTPOnly flag for cookies. This allows attackers...
CVE-2024-36773MEDIUM4.8A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HT...
CVE-2024-37160MEDIUM4.8Formwork is a flat file-based Content Management System (CMS). An attackers (requires administrator privilege) to execut...
CVE-2024-31878MEDIUM5.3IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST user enumeration by a remote attacker. Thi...
CVE-2024-5542MEDIUM6.1The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vu...
CVE-2024-5438MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere...
CVE-2024-5382MEDIUM5.3The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vu...
CVE-2024-5645MEDIUM5.4The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_css_id’ parameter withi...
CVE-2024-5426MEDIUM5.4The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scrip...
CVE-2024-4703MEDIUM5.4The One Page Express Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's one_pa...
CVE-2024-4489MEDIUM5.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cust...
CVE-2024-4488MEDIUM5.4The Royal Elementor Addons and Templates for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘inline_list...
CVE-2024-4451MEDIUM5.4The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_vide...
CVE-2024-5003MEDIUM5.4The WP Stacker WordPress plugin through 1.8.5 does not have CSRF check in some places, and is missing sanitisation as we...
CVE-2024-4756MEDIUM5.4The WP Backpack WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high p...
CVE-2024-4621MEDIUM4.8The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 does not sanitise and escape some of its...
CVE-2024-4354MEDIUM6.4The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Server-Side Request Forgery in all ...
CVE-2024-4042MEDIUM5.4The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPre...
CVE-2024-3592MEDIUM6.5The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to SQL I...
CVE-2024-3288MEDIUM5.4The Logo Slider WordPress plugin before 4.0.0 does not validate and escape some of its Slider Settings before outputtin...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now