2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-32826 | MEDIUM | 5.3 | 0.4% | Apr 26, 2024 | Missing Authorization vulnerability in Vektor,Inc. VK Block Patterns.This issue affects VK Block Patterns: from n/a thro... |
| CVE-2024-3682 | MEDIUM | 5.3 | 0.6% | Apr 26, 2024 | The WP STAGING and WP STAGING Pro plugins for WordPress are vulnerable to Sensitive Information Exposure in versions up ... |
| CVE-2024-4183 | MEDIUM | 6.5 | 0.6% | Apr 26, 2024 | Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the nu... |
| CVE-2024-4182 | MEDIUM | 4.3 | 0.6% | Apr 26, 2024 | Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing e... |
| CVE-2024-32046 | MEDIUM | 4.3 | 0.5% | Apr 26, 2024 | Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error mes... |
| CVE-2024-22091 | MEDIUM | 6.5 | 0.5% | Apr 26, 2024 | Mattermost versions 8.1.x <= 8.1.10, 9.6.x <= 9.6.0, 9.5.x <= 9.5.2 and 8.1.x <= 8.1.11 fail to limit the size of a requ... |
| CVE-2024-3890 | MEDIUM | 5.4 | 0.3% | Apr 26, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Calendly widget... |
| CVE-2024-3678 | MEDIUM | 5.3 | 0.6% | Apr 26, 2024 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure... |
| CVE-2024-33650 | MEDIUM | 4.3 | 0.2% | Apr 26, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Cryout Creations Serious Slider.This issue affects Serious Slider: fr... |
| CVE-2024-33642 | MEDIUM | 5.9 | 0.4% | Apr 26, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EkoJR Advanced Pos... |
| CVE-2024-33639 | MEDIUM | 4.8 | 0.4% | Apr 26, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AccessAlly PopupAl... |
| CVE-2024-33638 | MEDIUM | 5.4 | 0.2% | Apr 26, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Brijesh Kothari Smart Maintenance Mode.This issue affects Smart Maint... |
| CVE-2024-33598 | MEDIUM | 5.9 | 0.4% | Apr 26, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Twinpictures Annua... |
| CVE-2024-2920 | MEDIUM | 5.3 | 0.5% | Apr 26, 2024 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i... |
| CVE-2024-3188 | MEDIUM | 6.3 | 0.4% | Apr 26, 2024 | The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.1.0 does not validate and escape some of its sh... |
| CVE-2024-3060 | MEDIUM | 4.5 | 0.5% | Apr 26, 2024 | The ENL Newsletter WordPress plugin through 1.0.1 does not sanitize and escape a parameter before using it in a SQL stat... |
| CVE-2024-3059 | MEDIUM | 5.7 | 0.3% | Apr 26, 2024 | The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF checks in some places, which could allow attackers ... |
| CVE-2024-3058 | MEDIUM | 5.4 | 0.2% | Apr 26, 2024 | The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation a... |
| CVE-2024-3048 | MEDIUM | 5.5 | 0.4% | Apr 26, 2024 | The Bannerlid WordPress plugin through 1.1.0 does not escape generated URLs before outputting them in attributes, leadin... |
| CVE-2024-2908 | MEDIUM | 4.3 | 0.7% | Apr 26, 2024 | The Call Now Button WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-2837 | MEDIUM | 5.4 | 0.5% | Apr 26, 2024 | The WP Chat App WordPress plugin before 3.6.4 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2024-2603 | MEDIUM | 6.3 | 0.5% | Apr 26, 2024 | The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could a... |
| CVE-2024-2439 | MEDIUM | 4.8 | 0.4% | Apr 26, 2024 | The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could a... |
| CVE-2024-2429 | MEDIUM | 4.3 | 0.2% | Apr 26, 2024 | The Salon booking system WordPress plugin through 9.6.5 does not have CSRF check in place when updating its settings, wh... |
| CVE-2024-2310 | MEDIUM | 5.9 | 0.3% | Apr 26, 2024 | The WP Google Review Slider WordPress plugin before 13.6 does not sanitise and escape some of its settings, which could ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now