2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1852 | MEDIUM | 6.1 | 0.7% | Apr 9, 2024 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-F... |
| CVE-2024-1850 | MEDIUM | 6.3 | 0.5% | Apr 9, 2024 | The AI Post Generator | AutoWriter plugin for WordPress is vulnerable to unauthorized access, modification or deletion o... |
| CVE-2024-1794 | MEDIUM | 6.1 | 0.5% | Apr 9, 2024 | The Forminator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. 3gpp file) i... |
| CVE-2024-1790 | MEDIUM | 4.9 | 0.8% | Apr 9, 2024 | The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Path Traversal in all versions up t... |
| CVE-2024-1641 | MEDIUM | 5.4 | 0.5% | Apr 9, 2024 | The Accordion plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missin... |
| CVE-2024-1637 | MEDIUM | 4.3 | 0.5% | Apr 9, 2024 | The 360 Javascript Viewer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab... |
| CVE-2024-1587 | MEDIUM | 5.3 | 0.6% | Apr 9, 2024 | The Newsmatic theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, ... |
| CVE-2024-1571 | MEDIUM | 4.8 | 0.4% | Apr 9, 2024 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video Embed parameter in a... |
| CVE-2024-1498 | MEDIUM | 5.4 | 0.5% | Apr 9, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Photo ... |
| CVE-2024-1466 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slider_style... |
| CVE-2024-1465 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘carousel_ski... |
| CVE-2024-1464 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ attri... |
| CVE-2024-1463 | MEDIUM | 4.8 | 0.4% | Apr 9, 2024 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Course, ... |
| CVE-2024-1461 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ attri... |
| CVE-2024-1458 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘text_alignme... |
| CVE-2024-1424 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2024-1412 | MEDIUM | 6.1 | 0.5% | Apr 9, 2024 | The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘message’ and 'error' param... |
| CVE-2024-1387 | MEDIUM | 4.3 | 0.6% | Apr 9, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to insufficient aut... |
| CVE-2024-1352 | MEDIUM | 5.3 | 0.6% | Apr 9, 2024 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized a... |
| CVE-2024-1289 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all vers... |
| CVE-2024-0899 | MEDIUM | 5.3 | 0.6% | Apr 9, 2024 | The s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscri... |
| CVE-2024-0873 | MEDIUM | 5.4 | 0.5% | Apr 9, 2024 | The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'watu-basic-chart' shor... |
| CVE-2024-0872 | MEDIUM | 4.3 | 0.5% | Apr 9, 2024 | The Watu Quiz plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,... |
| CVE-2024-0826 | MEDIUM | 5.4 | 0.6% | Apr 9, 2024 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets i... |
| CVE-2024-0662 | MEDIUM | 4.8 | 0.5% | Apr 9, 2024 | The FancyBox for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now