2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1497 | MEDIUM | 5.4 | 0.5% | Mar 13, 2024 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form widget addr2_w... |
| CVE-2024-1489 | MEDIUM | 4.3 | 0.2% | Mar 13, 2024 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ... |
| CVE-2024-1484 | MEDIUM | 6.1 | 0.5% | Mar 13, 2024 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Reflected Cross-Site Scr... |
| CVE-2024-1479 | MEDIUM | 5.3 | 0.7% | Mar 13, 2024 | The WP Show Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ... |
| CVE-2024-1462 | MEDIUM | 5.3 | 0.5% | Mar 13, 2024 | The Maintenance Page plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and includi... |
| CVE-2024-1452 | MEDIUM | 4.3 | 0.6% | Mar 13, 2024 | The GenerateBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu... |
| CVE-2024-1422 | MEDIUM | 5.4 | 0.5% | Mar 13, 2024 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the modal popup widge... |
| CVE-2024-1414 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Call To Act... |
| CVE-2024-1413 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown T... |
| CVE-2024-1409 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres... |
| CVE-2024-1393 | MEDIUM | 5.4 | 0.5% | Mar 13, 2024 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'icon_align' attr... |
| CVE-2024-1392 | MEDIUM | 5.4 | 0.5% | Mar 13, 2024 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button1_icon' at... |
| CVE-2024-1391 | MEDIUM | 5.4 | 0.5% | Mar 13, 2024 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eae_custom_overl... |
| CVE-2024-1383 | MEDIUM | 6.1 | 0.6% | Mar 13, 2024 | The WPvivid Backup for MainWP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' paramete... |
| CVE-2024-1380 | MEDIUM | 5.3 | 50.2% | Mar 13, 2024 | The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa... |
| CVE-2024-1370 | MEDIUM | 4.3 | 0.4% | Mar 13, 2024 | The Maintenance Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check... |
| CVE-2024-1365 | MEDIUM | 6.1 | 0.5% | Mar 13, 2024 | The YML for Yandex Market plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the feed_id paramete... |
| CVE-2024-1363 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | The Easy Accordion – Best Accordion FAQ Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scr... |
| CVE-2024-1358 | MEDIUM | 6.5 | 1.2% | Mar 13, 2024 | The Elementor Addon Elements plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includ... |
| CVE-2024-1321 | MEDIUM | 5.3 | 0.3% | Mar 13, 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to payment bypass in all versi... |
| CVE-2024-1296 | MEDIUM | 5.4 | 0.5% | Mar 13, 2024 | The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block upload... |
| CVE-2024-1293 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the embedded media custom... |
| CVE-2024-1291 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown URL paramet... |
| CVE-2024-1237 | MEDIUM | 5.4 | 0.5% | Mar 13, 2024 | The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the flyout_l... |
| CVE-2024-1234 | MEDIUM | 5.4 | 1.6% | Mar 13, 2024 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data attribute ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now