2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-1497MEDIUM5.4The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form widget addr2_w...
CVE-2024-1489MEDIUM4.3The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ...
CVE-2024-1484MEDIUM6.1The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Reflected Cross-Site Scr...
CVE-2024-1479MEDIUM5.3The WP Show Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2024-1462MEDIUM5.3The Maintenance Page plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and includi...
CVE-2024-1452MEDIUM4.3The GenerateBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu...
CVE-2024-1422MEDIUM5.4The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the modal popup widge...
CVE-2024-1414MEDIUM5.4The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Call To Act...
CVE-2024-1413MEDIUM5.4The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown T...
CVE-2024-1409MEDIUM5.4The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres...
CVE-2024-1393MEDIUM5.4The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'icon_align' attr...
CVE-2024-1392MEDIUM5.4The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button1_icon' at...
CVE-2024-1391MEDIUM5.4The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eae_custom_overl...
CVE-2024-1383MEDIUM6.1The WPvivid Backup for MainWP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' paramete...
CVE-2024-1380MEDIUM5.3The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa...
CVE-2024-1370MEDIUM4.3The Maintenance Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check...
CVE-2024-1365MEDIUM6.1The YML for Yandex Market plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the feed_id paramete...
CVE-2024-1363MEDIUM5.4The Easy Accordion – Best Accordion FAQ Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scr...
CVE-2024-1358MEDIUM6.5The Elementor Addon Elements plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includ...
CVE-2024-1321MEDIUM5.3The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to payment bypass in all versi...
CVE-2024-1296MEDIUM5.4The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block upload...
CVE-2024-1293MEDIUM5.4The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the embedded media custom...
CVE-2024-1291MEDIUM5.4The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown URL paramet...
CVE-2024-1237MEDIUM5.4The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the flyout_l...
CVE-2024-1234MEDIUM5.4The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data attribute ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now