2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-0604MEDIUM4.8The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm...
CVE-2024-0602MEDIUM4The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin...
CVE-2024-0590MEDIUM6.1The Microsoft Clarity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2024-0516MEDIUM5.3The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to ...
CVE-2024-0515MEDIUM4.3The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...
CVE-2024-0514MEDIUM4.3The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...
CVE-2024-0513MEDIUM4.3The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...
CVE-2024-0512MEDIUM4.3The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...
CVE-2024-0506MEDIUM5.4The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site...
CVE-2024-0442MEDIUM6.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via element U...
CVE-2024-0438MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wrapper link pa...
CVE-2024-0379MEDIUM4.3The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request For...
CVE-2024-26146HIGH7.5Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer t...
CVE-2024-26141HIGH7.5Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexp...
CVE-2024-25126HIGH7.5Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser t...
CVE-2024-26559MEDIUM5.3An issue in uverif v.2.0 allows a remote attacker to obtain sensitive information.
CVE-2024-25579MEDIUM6.8OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrat...
CVE-2024-25422CRITICAL9.8SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive info...
CVE-2024-23910HIGH8.8Cross-site request forgery (CSRF) vulnerability in ELECOM wireless LAN routers and wireless LAN repeater allows a remote...
CVE-2024-22532MEDIUM6.5Buffer Overflow vulnerability in XNSoft NConvert 7.163 (for Windows x86) allows attackers to cause a denial of service v...
CVE-2024-21798MEDIUM4.8ELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user co...
CVE-2024-26476LOW3.5An issue in open-emr before v.7.0.2 allows a remote attacker to escalate privileges via a crafted script to the formid p...
CVE-2024-26450MEDIUM5.4An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit invol...
CVE-2024-25869HIGH8.8An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacke...
CVE-2024-25868MEDIUM6.1A Cross Site Scripting (XSS) vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attack...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now