2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-4636MEDIUM6.4The Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF plugin for WordPress is vulnerable to Stored Cr...
CVE-2024-3824MEDIUM5.5The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings,...
CVE-2024-3822MEDIUM4.8The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it ...
CVE-2024-3749MEDIUM6.5The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in u...
CVE-2024-3748MEDIUM6.5The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a...
CVE-2024-3634MEDIUM4.8The month name translation benaceur WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, whi...
CVE-2024-3631MEDIUM4.3The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check when unlinking twitter accounts, which could ...
CVE-2024-3630MEDIUM5.4The HL Twitter WordPress plugin through 2014.1.18 does not sanitise and escape some of its settings, which could allow h...
CVE-2024-3548MEDIUM6.1The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.1.2 does not sanitise and escape a parameter be...
CVE-2024-3407MEDIUM5.3The WP Prayer WordPress plugin through 2.0.9 does not have CSRF checks in some places, which could allow attackers to ma...
CVE-2024-4894MEDIUM5.3ITPison OMICARD EDM fails to properly filter specific URL parameter, allowing unauthenticated remote attackers to modif...
CVE-2024-4208MEDIUM5.4The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si...
CVE-2024-3189MEDIUM5.4The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2024-4734MEDIUM4.4The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin se...
CVE-2024-4656MEDIUM4.4The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user...
CVE-2024-4618MEDIUM5.4The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Team Member...
CVE-2024-4373MEDIUM5.4The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elem...
CVE-2024-4199MEDIUM4.3The Bulk Posts Editing For WordPress plugin for WordPress is vulnerable to unauthorized access of functionality due to a...
CVE-2024-35109MEDIUM6.5idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /homePro_deal.php?mudi=add&...
CVE-2024-3744MEDIUM6.5A security issue was discovered in azure-file-csi-driver where an actor with access to the driver logs could observe ser...
CVE-2024-4370MEDIUM5.4The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2024-4363MEDIUM6.4The Visual Portfolio, Photo Gallery & Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2024-0437MEDIUM4.3The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vu...
CVE-2024-4666MEDIUM5.4The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable t...
CVE-2024-31483MEDIUM6.5An authenticated sensitive information disclosure vulnerability exists in the CLI service accessed via the PAPI protocol...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now