2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-30503MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EverPress Mailster...
CVE-2024-30483MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simple Sponsorship...
CVE-2024-23449MEDIUM5.3An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment pro...
CVE-2024-2250MEDIUM6.4The 130+ Widgets | Best Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2024-2970MEDIUM4.3The News Wall plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1...
CVE-2024-2969MEDIUM5.4The WP-Eggdrop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0....
CVE-2024-2968MEDIUM4.8The WP-Eggdrop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t...
CVE-2024-2964MEDIUM4.3The Pocket News Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2024-2963MEDIUM4.8The Pocket News Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings such as "...
CVE-2024-2476MEDIUM4.3The OceanWP theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the lo...
CVE-2024-2280MEDIUM5.4The Better Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget link URL va...
CVE-2024-2116MEDIUM6.1The Christmas Greetings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the code parameter in a...
CVE-2024-2113MEDIUM4.3The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-...
CVE-2024-2108MEDIUM5.4The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored...
CVE-2024-1858MEDIUM5.4The Lightbox slider – Responsive Lightbox Gallery plugin for WordPress is vulnerable to PHP Object Injection in all vers...
CVE-2024-0956MEDIUM4.9The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is...
CVE-2024-0609MEDIUM6.1The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is...
CVE-2024-0608MEDIUM6.5The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is...
CVE-2024-2936MEDIUM5.4The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id attribute of widgets in...
CVE-2024-2844MEDIUM4.3The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient user v...
CVE-2024-2842MEDIUM5.4The Easy Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ea_full_calend...
CVE-2024-3077MEDIUM6.5An malicious BLE device can crash BLE victim device by sending malformed gatt packet
CVE-2024-2841MEDIUM5.4The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Store...
CVE-2024-2475MEDIUM5.4The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode...
CVE-2024-1729MEDIUM5.9A timing attack vulnerability exists in the gradio-app/gradio repository, specifically within the login function in rout...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now