2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6529HIGH7.1The Ultimate Classified Listings WordPress plugin before 1.4 does not sanitise and escape a parameter before outputting ...
CVE-2024-6496MEDIUM6.5The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks when deleting polls, which could allow attackers...
CVE-2024-4090MEDIUM4.8The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin ...
CVE-2024-3983HIGH8.1The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some bulk actions, which cou...
CVE-2024-2872MEDIUM4.8The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which c...
CVE-2024-2843MEDIUM6.5The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some places, which could all...
CVE-2024-1747MEDIUM6.5The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX acti...
CVE-2024-7343MEDIUM6.1A vulnerability was found in Baidu UEditor 1.4.2. It has been declared as problematic. This vulnerability affects unknow...
CVE-2024-7342MEDIUM6.1A vulnerability was found in Baidu UEditor 1.4.3.3. It has been classified as problematic. This affects an unknown part ...
CVE-2024-2090MEDIUM6.4The Remote Content Shortcode plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an...
CVE-2024-7339MEDIUM5.3A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM) and AVISION...
CVE-2024-7338HIGH8.8A vulnerability, which was classified as critical, was found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the...
CVE-2024-6698HIGH8.8The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. T...
CVE-2024-1715Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-34802. Reason: This candidate is a ...
CVE-2024-7337HIGH8.8A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by...
CVE-2024-7336HIGH8.8A vulnerability classified as critical was found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected by this vulnerability...
CVE-2024-7335HIGH8.8A vulnerability classified as critical has been found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected is the function ...
CVE-2024-7334HIGH8.8A vulnerability was found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. It has been rated as critical. This issue affects t...
CVE-2024-7333HIGH8.8A vulnerability was found in TOTOLINK N350RT 9.3.5u.6139_B20201216. It has been declared as critical. This vulnerability...
CVE-2024-6687HIGH7.5The CTT Expresso para WooCommerce plugin for WordPress is vulnerable to sensitive information exposure in all versions u...
CVE-2024-40883HIGH8.8Cross-site request forgery vulnerability exists in ELECOM wireless LAN routers. Viewing a malicious page while logging i...
CVE-2024-39607MEDIUM6.8OS command injection vulnerability exists in ELECOM wireless LAN routers. A specially crafted request may be sent to the...
CVE-2024-34021MEDIUM6.8Unrestricted upload of file with dangerous type vulnerability exists in ELECOM wireless LAN routers. A specially crafted...
CVE-2024-7332CRITICAL9.8A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an u...
CVE-2024-7331HIGH8.8A vulnerability was found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as critical. Affected by this issue i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now