2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4636 | MEDIUM | 6.4 | 0.4% | May 15, 2024 | The Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF plugin for WordPress is vulnerable to Stored Cr... |
| CVE-2024-3824 | MEDIUM | 5.5 | 0.2% | May 15, 2024 | The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings,... |
| CVE-2024-3822 | MEDIUM | 4.8 | 0.7% | May 15, 2024 | The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it ... |
| CVE-2024-3749 | MEDIUM | 6.5 | 0.5% | May 15, 2024 | The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in u... |
| CVE-2024-3748 | MEDIUM | 6.5 | 0.4% | May 15, 2024 | The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a... |
| CVE-2024-3634 | MEDIUM | 4.8 | 0.4% | May 15, 2024 | The month name translation benaceur WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, whi... |
| CVE-2024-3631 | MEDIUM | 4.3 | 0.2% | May 15, 2024 | The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check when unlinking twitter accounts, which could ... |
| CVE-2024-3630 | MEDIUM | 5.4 | 0.3% | May 15, 2024 | The HL Twitter WordPress plugin through 2014.1.18 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2024-3548 | MEDIUM | 6.1 | 0.4% | May 15, 2024 | The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.1.2 does not sanitise and escape a parameter be... |
| CVE-2024-3407 | MEDIUM | 5.3 | 0.2% | May 15, 2024 | The WP Prayer WordPress plugin through 2.0.9 does not have CSRF checks in some places, which could allow attackers to ma... |
| CVE-2024-4894 | MEDIUM | 5.3 | 0.5% | May 15, 2024 | ITPison OMICARD EDM fails to properly filter specific URL parameter, allowing unauthenticated remote attackers to modif... |
| CVE-2024-4208 | MEDIUM | 5.4 | 0.3% | May 15, 2024 | The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si... |
| CVE-2024-3189 | MEDIUM | 5.4 | 0.4% | May 15, 2024 | The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2024-4734 | MEDIUM | 4.4 | 0.3% | May 15, 2024 | The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin se... |
| CVE-2024-4656 | MEDIUM | 4.4 | 0.3% | May 15, 2024 | The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user... |
| CVE-2024-4618 | MEDIUM | 5.4 | 0.4% | May 15, 2024 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Team Member... |
| CVE-2024-4373 | MEDIUM | 5.4 | 0.4% | May 15, 2024 | The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elem... |
| CVE-2024-4199 | MEDIUM | 4.3 | 0.3% | May 15, 2024 | The Bulk Posts Editing For WordPress plugin for WordPress is vulnerable to unauthorized access of functionality due to a... |
| CVE-2024-35109 | MEDIUM | 6.5 | 0.2% | May 15, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /homePro_deal.php?mudi=add&... |
| CVE-2024-3744 | MEDIUM | 6.5 | 0.3% | May 15, 2024 | A security issue was discovered in azure-file-csi-driver where an actor with access to the driver logs could observe ser... |
| CVE-2024-4370 | MEDIUM | 5.4 | 0.4% | May 15, 2024 | The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2024-4363 | MEDIUM | 6.4 | 0.4% | May 15, 2024 | The Visual Portfolio, Photo Gallery & Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th... |
| CVE-2024-0437 | MEDIUM | 4.3 | 0.4% | May 15, 2024 | The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vu... |
| CVE-2024-4666 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable t... |
| CVE-2024-31483 | MEDIUM | 6.5 | 0.4% | May 14, 2024 | An authenticated sensitive information disclosure vulnerability exists in the CLI service accessed via the PAPI protocol... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now