2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-13918MEDIUM6.1The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an im...
CVE-2024-10326MEDIUM4.3The RomethemeKit For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ...
CVE-2024-13675MEDIUM5.4The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cross...
CVE-2024-13649MEDIUM5.4The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2024-13816MEDIUM5.4The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is...
CVE-2024-10321MEDIUM4.3The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Sensitive Information Exposure in ...
CVE-2024-13844MEDIUM4.9The Post SMTP plugin for WordPress is vulnerable to generic SQL Injection via the ‘columns’ parameter in all versions up...
CVE-2024-13826MEDIUM5.4The Email Keep WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could al...
CVE-2024-13825MEDIUM6.1The Email Keep WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the pa...
CVE-2024-12119MEDIUM5.4The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerabl...
CVE-2024-12114MEDIUM4.3The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerabl...
CVE-2024-13640MEDIUM5.9The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure ...
CVE-2024-13895MEDIUM6.3The The Code Snippets CPT plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and...
CVE-2024-13774MEDIUM6.5The Wishlist for WooCommerce: Multi Wishlists Per Customer plugin for WordPress is vulnerable to Cross-Site Request Forg...
CVE-2024-12460MEDIUM6.4The Years Since – Timeless Texts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yea...
CVE-2024-53698MEDIUM4.9A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulner...
CVE-2024-53696MEDIUM4.9A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerabi...
CVE-2024-53692MEDIUM5.1A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the ...
CVE-2024-50405MEDIUM5.5An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP o...
CVE-2024-12634MEDIUM6.1The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress i...
CVE-2024-9458MEDIUM4.8The Reservit Hotel WordPress plugin before 3.0 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-13857MEDIUM5.5The WPGet API – Connect to any external REST API plugin for WordPress is vulnerable to Server-Side Request Forgery in al...
CVE-2024-13805MEDIUM5.4The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerab...
CVE-2024-13635MEDIUM4.3The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
CVE-2024-13552MEDIUM4.3The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Objec...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now