2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25595 | MEDIUM | 5.3 | 0.4% | May 17, 2024 | Authentication Bypass by Spoofing vulnerability in WPMU DEV Defender Security allows Functionality Bypass.This issue aff... |
| CVE-2024-24934 | HIGH | 8.1 | 0.7% | May 17, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Webs... |
| CVE-2024-24882 | CRITICAL | 9.8 | 2.1% | May 17, 2024 | Incorrect Privilege Assignment vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects ... |
| CVE-2024-24874 | MEDIUM | 5.3 | 0.4% | May 17, 2024 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in CodePeople CP Polls allow... |
| CVE-2024-24873 | MEDIUM | 5.3 | 0.4% | May 17, 2024 | : Improper Control of Interaction Frequency vulnerability in CodePeople CP Polls allows Flooding.This issue affects CP P... |
| CVE-2024-24869 | HIGH | 7.5 | 0.7% | May 17, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BoldGrid Total Upkeep al... |
| CVE-2024-24715 | MEDIUM | 6.5 | 0.5% | May 17, 2024 | Improper Validation of Specified Quantity in Input vulnerability in The Events Calendar BookIt allows Manipulating Hidde... |
| CVE-2024-23522 | MEDIUM | 6.1 | 0.3% | May 17, 2024 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Form Builder T... |
| CVE-2024-22157 | CRITICAL | 9.8 | 0.6% | May 17, 2024 | Improper Privilege Management vulnerability in WebWizards SalesKing allows Privilege Escalation.This issue affects Sales... |
| CVE-2024-22145 | HIGH | 8.8 | 1.1% | May 17, 2024 | Incorrect Privilege Assignment vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Conne... |
| CVE-2024-22139 | LOW | 3.7 | 0.4% | May 17, 2024 | Authentication Bypass by Spoofing vulnerability in Filipe Seabra WordPress Manutenção allows Functionality Bypass.This i... |
| CVE-2024-21746 | HIGH | 7.5 | 0.5% | May 17, 2024 | Authentication Bypass by Spoofing vulnerability in Roxnor Wp Ultimate Review wp-ultimate-review allows Identity Spoofing... |
| CVE-2024-35110 | MEDIUM | 5.5 | 0.3% | May 17, 2024 | A reflected XSS vulnerability has been found in YzmCMS 7.1. The vulnerability exists in yzmphp/core/class/application.cl... |
| CVE-2024-33556 | CRITICAL | 9.8 | 0.6% | May 17, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in 8theme XStore Core.This issue affects XStore Core: from... |
| CVE-2024-31351 | CRITICAL | 9.8 | 1.6% | May 17, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Copymatic Copymatic – AI Content Writer & Generator.Thi... |
| CVE-2024-3580 | MEDIUM | 6.1 | 0.4% | May 17, 2024 | The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2024-3231 | MEDIUM | 6.1 | 0.7% | May 17, 2024 | The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some parameters, which could allow unauthent... |
| CVE-2024-34757 | MEDIUM | 5.4 | 0.3% | May 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visualmodo Borderl... |
| CVE-2024-34752 | HIGH | 7.1 | 0.3% | May 17, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PluginOps L... |
| CVE-2024-34575 | MEDIUM | 5.4 | 0.3% | May 17, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in deTheme Det... |
| CVE-2024-34567 | MEDIUM | 6.5 | 0.3% | May 17, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in GhozyLab, I... |
| CVE-2024-32800 | MEDIUM | 6.5 | 0.2% | May 17, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Felix Moira... |
| CVE-2024-2744 | MEDIUM | 4.3 | 0.4% | May 17, 2024 | The NextGEN Gallery WordPress plugin before 3.59.1 does not sanitise and escape some of its settings, which could allow... |
| CVE-2024-2697 | MEDIUM | 6.5 | 0.3% | May 17, 2024 | The socialdriver-framework WordPress plugin before 2024.0.0 does not validate and escape some of its shortcode attribute... |
| CVE-2024-3551 | CRITICAL | 9.8 | 0.7% | May 17, 2024 | The Penci Soledad Data Migrator plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now