2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13649 | MEDIUM | 5.4 | 0.2% | Mar 8, 2025 | The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2024-11640 | HIGH | 8.8 | 0.3% | Mar 8, 2025 | The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers... |
| CVE-2024-13359 | CRITICAL | 9.8 | 0.8% | Mar 8, 2025 | The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficien... |
| CVE-2024-13882 | HIGH | 8.8 | 0.7% | Mar 8, 2025 | The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is... |
| CVE-2024-13816 | MEDIUM | 5.4 | 0.2% | Mar 8, 2025 | The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is... |
| CVE-2024-10321 | MEDIUM | 4.3 | 0.3% | Mar 8, 2025 | The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Sensitive Information Exposure in ... |
| CVE-2024-13908 | HIGH | 7.2 | 0.8% | Mar 8, 2025 | The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation... |
| CVE-2024-11087 | CRITICAL | 9.8 | 0.4% | Mar 8, 2025 | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerab... |
| CVE-2024-13844 | MEDIUM | 4.9 | 0.4% | Mar 8, 2025 | The Post SMTP plugin for WordPress is vulnerable to generic SQL Injection via the ‘columns’ parameter in all versions up... |
| CVE-2024-13826 | MEDIUM | 5.4 | 0.2% | Mar 8, 2025 | The Email Keep WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could al... |
| CVE-2024-13825 | MEDIUM | 6.1 | 0.3% | Mar 8, 2025 | The Email Keep WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the pa... |
| CVE-2024-12119 | MEDIUM | 5.4 | 0.2% | Mar 8, 2025 | The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerabl... |
| CVE-2024-12114 | MEDIUM | 4.3 | 0.3% | Mar 8, 2025 | The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerabl... |
| CVE-2024-13640 | MEDIUM | 5.9 | 0.4% | Mar 8, 2025 | The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure ... |
| CVE-2024-13895 | MEDIUM | 6.3 | 0.3% | Mar 8, 2025 | The The Code Snippets CPT plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and... |
| CVE-2024-13890 | HIGH | 7.2 | 0.4% | Mar 8, 2025 | The Allow PHP Execute plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0... |
| CVE-2024-13835 | HIGH | 7.2 | 0.4% | Mar 8, 2025 | The Post Meta Data Manager plugin for WordPress is vulnerable to multisite privilege escalation in all versions up to, a... |
| CVE-2024-13774 | MEDIUM | 6.5 | 0.2% | Mar 8, 2025 | The Wishlist for WooCommerce: Multi Wishlists Per Customer plugin for WordPress is vulnerable to Cross-Site Request Forg... |
| CVE-2024-12460 | MEDIUM | 6.4 | 0.3% | Mar 8, 2025 | The Years Since – Timeless Texts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yea... |
| CVE-2024-42733 | CRITICAL | 9.8 | 1.0% | Mar 7, 2025 | An issue in Docmosis Tornado v.2.9.7 and before allows a remote attacker to execute arbitrary code via a crafted script ... |
| CVE-2024-53700 | HIGH | 7.2 | 1.2% | Mar 7, 2025 | A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote ... |
| CVE-2024-53699 | HIGH | 7.2 | 0.5% | Mar 7, 2025 | An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, t... |
| CVE-2024-53698 | MEDIUM | 4.9 | 0.4% | Mar 7, 2025 | A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulner... |
| CVE-2024-53697 | HIGH | 7.2 | 0.5% | Mar 7, 2025 | An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, t... |
| CVE-2024-53696 | MEDIUM | 4.9 | 0.4% | Mar 7, 2025 | A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerabi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now