2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-2536MEDIUM5.4The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HowTo bloc...
CVE-2024-2513MEDIUM5.4The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageAlt' block attribute in ...
CVE-2024-2507MEDIUM5.4The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget button URL...
CVE-2024-2504MEDIUM5.4The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2024-2492MEDIUM5.4The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Twitter Twe...
CVE-2024-2457MEDIUM5.4The Modal Window – create popup modal window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p...
CVE-2024-2456MEDIUM6.4The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sho...
CVE-2024-2436MEDIUM5.4The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s...
CVE-2024-2423MEDIUM6.4The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for ...
CVE-2024-2348MEDIUM6.4The Gum Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Meta widget in al...
CVE-2024-2347MEDIUM6.4The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name in all versions up ...
CVE-2024-2343MEDIUM6.4The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Server-Side Request Forgery...
CVE-2024-2341MEDIUM6.5The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL...
CVE-2024-2340MEDIUM5.3The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11...
CVE-2024-2336MEDIUM5.4The Popup Maker – Popup for opt-ins, lead gen, & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2024-2335MEDIUM6.4The Elements Plus! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widget link URLs in al...
CVE-2024-2334MEDIUM6.4The Template Kit – Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the template upload func...
CVE-2024-2327MEDIUM6.4The Global Elementor Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button link URL i...
CVE-2024-2325MEDIUM6.1The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the searchll parameter in all ...
CVE-2024-2311MEDIUM5.4The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions u...
CVE-2024-2306MEDIUM6.4The Revslider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg upload in all versions up to, an...
CVE-2024-2305MEDIUM5.4The Cards for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the BootstrapCard lin...
CVE-2024-2302MEDIUM5.3The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPr...
CVE-2024-2289MEDIUM5.4The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link in ...
CVE-2024-2287MEDIUM6.4The Knight Lab Timeline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now