2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-30503 | MEDIUM | 6.1 | 0.4% | Mar 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EverPress Mailster... |
| CVE-2024-30483 | MEDIUM | 5.4 | 0.4% | Mar 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simple Sponsorship... |
| CVE-2024-23449 | MEDIUM | 5.3 | 0.7% | Mar 29, 2024 | An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment pro... |
| CVE-2024-2250 | MEDIUM | 6.4 | 0.3% | Mar 29, 2024 | The 130+ Widgets | Best Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2024-2970 | MEDIUM | 4.3 | 0.2% | Mar 29, 2024 | The News Wall plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1... |
| CVE-2024-2969 | MEDIUM | 5.4 | 0.2% | Mar 29, 2024 | The WP-Eggdrop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.... |
| CVE-2024-2968 | MEDIUM | 4.8 | 0.3% | Mar 29, 2024 | The WP-Eggdrop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t... |
| CVE-2024-2964 | MEDIUM | 4.3 | 0.2% | Mar 29, 2024 | The Pocket News Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2024-2963 | MEDIUM | 4.8 | 0.3% | Mar 29, 2024 | The Pocket News Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings such as "... |
| CVE-2024-2476 | MEDIUM | 4.3 | 0.4% | Mar 29, 2024 | The OceanWP theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the lo... |
| CVE-2024-2280 | MEDIUM | 5.4 | 0.4% | Mar 29, 2024 | The Better Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget link URL va... |
| CVE-2024-2116 | MEDIUM | 6.1 | 0.5% | Mar 29, 2024 | The Christmas Greetings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the code parameter in a... |
| CVE-2024-2113 | MEDIUM | 4.3 | 0.2% | Mar 29, 2024 | The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-... |
| CVE-2024-2108 | MEDIUM | 5.4 | 0.3% | Mar 29, 2024 | The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored... |
| CVE-2024-1858 | MEDIUM | 5.4 | 0.5% | Mar 29, 2024 | The Lightbox slider – Responsive Lightbox Gallery plugin for WordPress is vulnerable to PHP Object Injection in all vers... |
| CVE-2024-0956 | MEDIUM | 4.9 | 0.5% | Mar 29, 2024 | The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is... |
| CVE-2024-0609 | MEDIUM | 6.1 | 0.5% | Mar 29, 2024 | The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is... |
| CVE-2024-0608 | MEDIUM | 6.5 | 0.5% | Mar 29, 2024 | The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is... |
| CVE-2024-2936 | MEDIUM | 5.4 | 0.3% | Mar 29, 2024 | The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id attribute of widgets in... |
| CVE-2024-2844 | MEDIUM | 4.3 | 0.4% | Mar 29, 2024 | The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient user v... |
| CVE-2024-2842 | MEDIUM | 5.4 | 0.3% | Mar 29, 2024 | The Easy Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ea_full_calend... |
| CVE-2024-3077 | MEDIUM | 6.5 | 0.5% | Mar 29, 2024 | An malicious BLE device can crash BLE victim device by sending malformed gatt packet |
| CVE-2024-2841 | MEDIUM | 5.4 | 0.3% | Mar 29, 2024 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Store... |
| CVE-2024-2475 | MEDIUM | 5.4 | 0.4% | Mar 29, 2024 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode... |
| CVE-2024-1729 | MEDIUM | 5.9 | 0.5% | Mar 29, 2024 | A timing attack vulnerability exists in the gradio-app/gradio repository, specifically within the login function in rout... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now