2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-2536 | MEDIUM | 5.4 | 0.3% | Apr 9, 2024 | The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HowTo bloc... |
| CVE-2024-2513 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageAlt' block attribute in ... |
| CVE-2024-2507 | MEDIUM | 5.4 | 0.3% | Apr 9, 2024 | The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget button URL... |
| CVE-2024-2504 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2024-2492 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Twitter Twe... |
| CVE-2024-2457 | MEDIUM | 5.4 | 0.3% | Apr 9, 2024 | The Modal Window – create popup modal window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p... |
| CVE-2024-2456 | MEDIUM | 6.4 | 0.4% | Apr 9, 2024 | The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sho... |
| CVE-2024-2436 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s... |
| CVE-2024-2423 | MEDIUM | 6.4 | 0.4% | Apr 9, 2024 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for ... |
| CVE-2024-2348 | MEDIUM | 6.4 | 0.4% | Apr 9, 2024 | The Gum Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Meta widget in al... |
| CVE-2024-2347 | MEDIUM | 6.4 | 0.4% | Apr 9, 2024 | The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name in all versions up ... |
| CVE-2024-2343 | MEDIUM | 6.4 | 0.5% | Apr 9, 2024 | The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Server-Side Request Forgery... |
| CVE-2024-2341 | MEDIUM | 6.5 | 0.6% | Apr 9, 2024 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL... |
| CVE-2024-2340 | MEDIUM | 5.3 | 28.0% | Apr 9, 2024 | The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11... |
| CVE-2024-2336 | MEDIUM | 5.4 | 0.3% | Apr 9, 2024 | The Popup Maker – Popup for opt-ins, lead gen, & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2024-2335 | MEDIUM | 6.4 | 0.3% | Apr 9, 2024 | The Elements Plus! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widget link URLs in al... |
| CVE-2024-2334 | MEDIUM | 6.4 | 0.4% | Apr 9, 2024 | The Template Kit – Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the template upload func... |
| CVE-2024-2327 | MEDIUM | 6.4 | 0.3% | Apr 9, 2024 | The Global Elementor Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button link URL i... |
| CVE-2024-2325 | MEDIUM | 6.1 | 0.4% | Apr 9, 2024 | The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the searchll parameter in all ... |
| CVE-2024-2311 | MEDIUM | 5.4 | 0.7% | Apr 9, 2024 | The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions u... |
| CVE-2024-2306 | MEDIUM | 6.4 | 0.3% | Apr 9, 2024 | The Revslider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg upload in all versions up to, an... |
| CVE-2024-2305 | MEDIUM | 5.4 | 0.3% | Apr 9, 2024 | The Cards for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the BootstrapCard lin... |
| CVE-2024-2302 | MEDIUM | 5.3 | 0.6% | Apr 9, 2024 | The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPr... |
| CVE-2024-2289 | MEDIUM | 5.4 | 0.3% | Apr 9, 2024 | The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link in ... |
| CVE-2024-2287 | MEDIUM | 6.4 | 0.4% | Apr 9, 2024 | The Knight Lab Timeline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now