2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13918 | MEDIUM | 6.1 | 0.6% | Mar 10, 2025 | The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an im... |
| CVE-2024-10326 | MEDIUM | 4.3 | 0.3% | Mar 8, 2025 | The RomethemeKit For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ... |
| CVE-2024-13675 | MEDIUM | 5.4 | 0.2% | Mar 8, 2025 | The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2024-13649 | MEDIUM | 5.4 | 0.2% | Mar 8, 2025 | The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2024-13816 | MEDIUM | 5.4 | 0.2% | Mar 8, 2025 | The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is... |
| CVE-2024-10321 | MEDIUM | 4.3 | 0.3% | Mar 8, 2025 | The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Sensitive Information Exposure in ... |
| CVE-2024-13844 | MEDIUM | 4.9 | 0.4% | Mar 8, 2025 | The Post SMTP plugin for WordPress is vulnerable to generic SQL Injection via the ‘columns’ parameter in all versions up... |
| CVE-2024-13826 | MEDIUM | 5.4 | 0.2% | Mar 8, 2025 | The Email Keep WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could al... |
| CVE-2024-13825 | MEDIUM | 6.1 | 0.3% | Mar 8, 2025 | The Email Keep WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the pa... |
| CVE-2024-12119 | MEDIUM | 5.4 | 0.2% | Mar 8, 2025 | The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerabl... |
| CVE-2024-12114 | MEDIUM | 4.3 | 0.3% | Mar 8, 2025 | The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerabl... |
| CVE-2024-13640 | MEDIUM | 5.9 | 0.4% | Mar 8, 2025 | The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure ... |
| CVE-2024-13895 | MEDIUM | 6.3 | 0.3% | Mar 8, 2025 | The The Code Snippets CPT plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and... |
| CVE-2024-13774 | MEDIUM | 6.5 | 0.2% | Mar 8, 2025 | The Wishlist for WooCommerce: Multi Wishlists Per Customer plugin for WordPress is vulnerable to Cross-Site Request Forg... |
| CVE-2024-12460 | MEDIUM | 6.4 | 0.3% | Mar 8, 2025 | The Years Since – Timeless Texts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yea... |
| CVE-2024-53698 | MEDIUM | 4.9 | 0.4% | Mar 7, 2025 | A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulner... |
| CVE-2024-53696 | MEDIUM | 4.9 | 0.4% | Mar 7, 2025 | A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerabi... |
| CVE-2024-53692 | MEDIUM | 5.1 | 0.8% | Mar 7, 2025 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the ... |
| CVE-2024-50405 | MEDIUM | 5.5 | 0.4% | Mar 7, 2025 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP o... |
| CVE-2024-12634 | MEDIUM | 6.1 | 0.2% | Mar 7, 2025 | The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress i... |
| CVE-2024-9458 | MEDIUM | 4.8 | 0.8% | Mar 7, 2025 | The Reservit Hotel WordPress plugin before 3.0 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2024-13857 | MEDIUM | 5.5 | 0.3% | Mar 7, 2025 | The WPGet API – Connect to any external REST API plugin for WordPress is vulnerable to Server-Side Request Forgery in al... |
| CVE-2024-13805 | MEDIUM | 5.4 | 0.2% | Mar 7, 2025 | The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerab... |
| CVE-2024-13635 | MEDIUM | 4.3 | 0.3% | Mar 7, 2025 | The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,... |
| CVE-2024-13552 | MEDIUM | 4.3 | 0.3% | Mar 7, 2025 | The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Objec... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now