2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-3338MEDIUM5.4The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt data parameter ...
CVE-2024-3337MEDIUM5.4The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_bre...
CVE-2024-3312MEDIUM5.3The Easy Custom Auto Excerpt plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,...
CVE-2024-3308MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Im...
CVE-2024-3307MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Co...
CVE-2024-3295MEDIUM6.5The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is ...
CVE-2024-3287MEDIUM5.3The SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer plugin for WordPress is vulnerable to unauthorized ld+...
CVE-2024-3275MEDIUM4.3The eRoom – Zoom Meetings & Webinars plugin for WordPress is vulnerable to Sensitive Information Exposure in all version...
CVE-2024-3233MEDIUM4.3The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to unauthorized modification of data due t...
CVE-2024-3215MEDIUM4.3The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerab...
CVE-2024-3206MEDIUM4.3The Different Menu in Different Pages – Control Menu Visibility (All in One) plugin for WordPress is vulnerable to unaut...
CVE-2024-3199MEDIUM5.4The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown wi...
CVE-2024-3197MEDIUM5.4The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attribute...
CVE-2024-3161MEDIUM5.4The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget's attri...
CVE-2024-3107MEDIUM4.3The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Path Traversal in versions up to, and inc...
CVE-2024-3074MEDIUM6.4The Elementor ImageBox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image box widget in all...
CVE-2024-3071MEDIUM4.3The ACF On-The-Go plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch...
CVE-2024-3045MEDIUM6.1The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via s...
CVE-2024-3023MEDIUM4.4The AnnounceKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ...
CVE-2024-3021MEDIUM4.4The Mhr Post Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Header Title value in all ...
CVE-2024-33949MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vark Min and Max P...
CVE-2024-33948MEDIUM5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixel Industry Twe...
CVE-2024-2967MEDIUM4.4The Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor plugin for WordPress is vuln...
CVE-2024-2960MEDIUM4.3The SVS Pricing Tables plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2024-2959MEDIUM4.3The SVS Pricing Tables plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now