2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3989 | MEDIUM | 5.4 | 0.3% | May 14, 2024 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2024-3974 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_name’ parameter in versio... |
| CVE-2024-3956 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pod... |
| CVE-2024-3952 | MEDIUM | 6.4 | 0.4% | May 14, 2024 | The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanc... |
| CVE-2024-3941 | MEDIUM | 4.7 | 0.3% | May 14, 2024 | The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in some places, and is missing sanitisatio... |
| CVE-2024-3923 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the li... |
| CVE-2024-3916 | MEDIUM | 6.4 | 0.4% | May 14, 2024 | The Swift Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortc... |
| CVE-2024-3915 | MEDIUM | 5.3 | 0.4% | May 14, 2024 | The Swift Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ... |
| CVE-2024-3831 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scrip... |
| CVE-2024-3796 | MEDIUM | 4.8 | 0.4% | May 14, 2024 | Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/BackupSchedul... |
| CVE-2024-3795 | MEDIUM | 4.8 | 0.4% | May 14, 2024 | Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/BackupTemplat... |
| CVE-2024-3794 | MEDIUM | 4.8 | 0.4% | May 14, 2024 | Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/AdvancedSyste... |
| CVE-2024-3793 | MEDIUM | 4.8 | 0.4% | May 14, 2024 | Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/CloudAccounts... |
| CVE-2024-3792 | MEDIUM | 4.8 | 0.5% | May 14, 2024 | Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/DeviceReplica... |
| CVE-2024-3791 | MEDIUM | 4.8 | 0.4% | May 14, 2024 | Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/SystemConfigu... |
| CVE-2024-3790 | MEDIUM | 4.8 | 0.4% | May 14, 2024 | Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/SystemUsers, ... |
| CVE-2024-3789 | MEDIUM | 6.5 | 1.0% | May 14, 2024 | Uncontrolled resource consumption vulnerability in White Bear Solutions WBSAirback, version 21.02.04. This vulnerability... |
| CVE-2024-3788 | MEDIUM | 6.6 | 0.6% | May 14, 2024 | Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Lice... |
| CVE-2024-3787 | MEDIUM | 6.6 | 0.6% | May 14, 2024 | Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 d... |
| CVE-2024-3722 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The Swift Performance Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o... |
| CVE-2024-3680 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scrip... |
| CVE-2024-3595 | MEDIUM | 6.4 | 0.4% | May 14, 2024 | The Pure Chat – Live Chat Plugin & More! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the purec... |
| CVE-2024-3590 | MEDIUM | 6.1 | 0.2% | May 14, 2024 | The LetterPress WordPress plugin through 1.2.2 does not have CSRF checks in some places, which could allow attackers to... |
| CVE-2024-3582 | MEDIUM | 4.8 | 0.2% | May 14, 2024 | The UnGallery WordPress plugin through 2.2.4 does not have CSRF check in some places, and is missing sanitisation as wel... |
| CVE-2024-3547 | MEDIUM | 6.1 | 0.4% | May 14, 2024 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected C... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now