2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-3989MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2024-3974MEDIUM5.4The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_name’ parameter in versio...
CVE-2024-3956MEDIUM5.4The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pod...
CVE-2024-3952MEDIUM6.4The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanc...
CVE-2024-3941MEDIUM4.7The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in some places, and is missing sanitisatio...
CVE-2024-3923MEDIUM5.4The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the li...
CVE-2024-3916MEDIUM6.4The Swift Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortc...
CVE-2024-3915MEDIUM5.3The Swift Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2024-3831MEDIUM5.4The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scrip...
CVE-2024-3796MEDIUM4.8Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/BackupSchedul...
CVE-2024-3795MEDIUM4.8Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/BackupTemplat...
CVE-2024-3794MEDIUM4.8Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/AdvancedSyste...
CVE-2024-3793MEDIUM4.8Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/CloudAccounts...
CVE-2024-3792MEDIUM4.8Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/DeviceReplica...
CVE-2024-3791MEDIUM4.8Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/SystemConfigu...
CVE-2024-3790MEDIUM4.8Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/SystemUsers, ...
CVE-2024-3789MEDIUM6.5Uncontrolled resource consumption vulnerability in White Bear Solutions WBSAirback, version 21.02.04. This vulnerability...
CVE-2024-3788MEDIUM6.6Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Lice...
CVE-2024-3787MEDIUM6.6Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 d...
CVE-2024-3722MEDIUM5.4The Swift Performance Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o...
CVE-2024-3680MEDIUM5.4The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scrip...
CVE-2024-3595MEDIUM6.4The Pure Chat – Live Chat Plugin & More! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the purec...
CVE-2024-3590MEDIUM6.1The LetterPress WordPress plugin through 1.2.2 does not have CSRF checks in some places, which could allow attackers to...
CVE-2024-3582MEDIUM4.8The UnGallery WordPress plugin through 2.2.4 does not have CSRF check in some places, and is missing sanitisation as wel...
CVE-2024-3547MEDIUM6.1The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected C...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now