2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0604 | MEDIUM | 4.8 | 0.6% | Feb 29, 2024 | The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm... |
| CVE-2024-0602 | MEDIUM | 4 | 0.5% | Feb 29, 2024 | The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin... |
| CVE-2024-0590 | MEDIUM | 6.1 | 1.3% | Feb 29, 2024 | The Microsoft Clarity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2024-0516 | MEDIUM | 5.3 | 0.2% | Feb 29, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to ... |
| CVE-2024-0515 | MEDIUM | 4.3 | 0.2% | Feb 29, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version... |
| CVE-2024-0514 | MEDIUM | 4.3 | 0.2% | Feb 29, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version... |
| CVE-2024-0513 | MEDIUM | 4.3 | 0.2% | Feb 29, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version... |
| CVE-2024-0512 | MEDIUM | 4.3 | 0.2% | Feb 29, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version... |
| CVE-2024-0506 | MEDIUM | 5.4 | 0.5% | Feb 29, 2024 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site... |
| CVE-2024-0442 | MEDIUM | 6.4 | 0.5% | Feb 29, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via element U... |
| CVE-2024-0438 | MEDIUM | 5.4 | 0.6% | Feb 29, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wrapper link pa... |
| CVE-2024-0379 | MEDIUM | 4.3 | 1.0% | Feb 29, 2024 | The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request For... |
| CVE-2024-26146 | HIGH | 7.5 | 2.0% | Feb 29, 2024 | Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer t... |
| CVE-2024-26141 | HIGH | 7.5 | 1.6% | Feb 29, 2024 | Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexp... |
| CVE-2024-25126 | HIGH | 7.5 | 35.4% | Feb 29, 2024 | Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser t... |
| CVE-2024-26559 | MEDIUM | 5.3 | 0.7% | Feb 28, 2024 | An issue in uverif v.2.0 allows a remote attacker to obtain sensitive information. |
| CVE-2024-25579 | MEDIUM | 6.8 | 0.8% | Feb 28, 2024 | OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrat... |
| CVE-2024-25422 | CRITICAL | 9.8 | 1.0% | Feb 28, 2024 | SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive info... |
| CVE-2024-23910 | HIGH | 8.8 | 0.2% | Feb 28, 2024 | Cross-site request forgery (CSRF) vulnerability in ELECOM wireless LAN routers and wireless LAN repeater allows a remote... |
| CVE-2024-22532 | MEDIUM | 6.5 | 1.1% | Feb 28, 2024 | Buffer Overflow vulnerability in XNSoft NConvert 7.163 (for Windows x86) allows attackers to cause a denial of service v... |
| CVE-2024-21798 | MEDIUM | 4.8 | 1.3% | Feb 28, 2024 | ELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user co... |
| CVE-2024-26476 | LOW | 3.5 | 0.4% | Feb 28, 2024 | An issue in open-emr before v.7.0.2 allows a remote attacker to escalate privileges via a crafted script to the formid p... |
| CVE-2024-26450 | MEDIUM | 5.4 | 0.2% | Feb 28, 2024 | An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit invol... |
| CVE-2024-25869 | HIGH | 8.8 | 18.7% | Feb 28, 2024 | An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacke... |
| CVE-2024-25868 | MEDIUM | 6.1 | 0.6% | Feb 28, 2024 | A Cross Site Scripting (XSS) vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attack... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now