2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-12031MEDIUM6.5The Advanced Floating Content plugin for WordPress is vulnerable to SQL Injection via the 'floating_content_duplicate_po...
CVE-2024-12468MEDIUM6.1The WP Datepicker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpdp_get_selected_datepi...
CVE-2024-11896MEDIUM6.4The Text Prompter – Unlimited chatgpt text prompts for openai tasks plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2024-12814MEDIUM6.4The Loan Comparison plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'loancomparison' ...
CVE-2024-41887MEDIUM5.1Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker can...
CVE-2024-41886MEDIUM6.9Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker cou...
CVE-2024-41885MEDIUM5.6Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. The seed string...
CVE-2024-41884MEDIUM6.9Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. If an attacker ...
CVE-2024-41883MEDIUM6.9Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR . An attacker...
CVE-2024-41882MEDIUM6.9Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker can...
CVE-2024-12622MEDIUM6.4The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'w...
CVE-2024-12405MEDIUM6.1The Export Customers Data plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 't' parameter in ...
CVE-2024-12210MEDIUM4.3The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of da...
CVE-2024-12100MEDIUM6.1The Bitcoin Lightning Publisher for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t...
CVE-2024-12096MEDIUM6.1The Exhibit to WP Gallery WordPress plugin through 0.0.2 does not sanitise and escape a parameter before outputting it b...
CVE-2024-12034MEDIUM5.3The Advanced Google reCAPTCHA plugin for WordPress is vulnerable to IP unblocking in all versions up to, and including, ...
CVE-2024-11885MEDIUM6.4The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'njte...
CVE-2024-12710MEDIUM6.1The WP-Appbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versi...
CVE-2024-12617MEDIUM5.4The WC Price History for Omnibus plugin for WordPress is vulnerable to unauthorized access due to a missing capability c...
CVE-2024-12518MEDIUM6.4The ShMapper by Teplitsa plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shmMap' sho...
CVE-2024-12507MEDIUM6.4The Optio Dentistry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'optio-lightbox' ...
CVE-2024-12266MEDIUM6.5The ELEX WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthorized access of data due...
CVE-2024-9427MEDIUM5.4A vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link ...
CVE-2024-56362MEDIUM5.5Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext...
CVE-2024-53276MEDIUM6.3Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now