2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13649MEDIUM5.4The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2024-11640HIGH8.8The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers...
CVE-2024-13359CRITICAL9.8The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficien...
CVE-2024-13882HIGH8.8The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is...
CVE-2024-13816MEDIUM5.4The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is...
CVE-2024-10321MEDIUM4.3The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Sensitive Information Exposure in ...
CVE-2024-13908HIGH7.2The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation...
CVE-2024-11087CRITICAL9.8The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerab...
CVE-2024-13844MEDIUM4.9The Post SMTP plugin for WordPress is vulnerable to generic SQL Injection via the ‘columns’ parameter in all versions up...
CVE-2024-13826MEDIUM5.4The Email Keep WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could al...
CVE-2024-13825MEDIUM6.1The Email Keep WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the pa...
CVE-2024-12119MEDIUM5.4The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerabl...
CVE-2024-12114MEDIUM4.3The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerabl...
CVE-2024-13640MEDIUM5.9The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure ...
CVE-2024-13895MEDIUM6.3The The Code Snippets CPT plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and...
CVE-2024-13890HIGH7.2The Allow PHP Execute plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0...
CVE-2024-13835HIGH7.2The Post Meta Data Manager plugin for WordPress is vulnerable to multisite privilege escalation in all versions up to, a...
CVE-2024-13774MEDIUM6.5The Wishlist for WooCommerce: Multi Wishlists Per Customer plugin for WordPress is vulnerable to Cross-Site Request Forg...
CVE-2024-12460MEDIUM6.4The Years Since – Timeless Texts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yea...
CVE-2024-42733CRITICAL9.8An issue in Docmosis Tornado v.2.9.7 and before allows a remote attacker to execute arbitrary code via a crafted script ...
CVE-2024-53700HIGH7.2A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote ...
CVE-2024-53699HIGH7.2An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, t...
CVE-2024-53698MEDIUM4.9A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulner...
CVE-2024-53697HIGH7.2An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, t...
CVE-2024-53696MEDIUM4.9A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerabi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now