2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9838 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The Auto Affiliate Links WordPress plugin before 6.4.7 does not sanitize and escape a parameter before using it in a SQL... |
| CVE-2024-9765 | MEDIUM | 6.5 | 1.4% | May 15, 2025 | The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of th... |
| CVE-2024-9711 | MEDIUM | 5.4 | 0.2% | May 15, 2025 | The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, w... |
| CVE-2024-9709 | MEDIUM | 5.4 | 0.2% | May 15, 2025 | The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, w... |
| CVE-2024-9663 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2024-9662 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2024-9645 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry WordPress plugin before 2.2.93 does not validate ... |
| CVE-2024-9599 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The Popup Box WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high p... |
| CVE-2024-9450 | MEDIUM | 6.5 | 0.2% | May 15, 2025 | The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check... |
| CVE-2024-9390 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could al... |
| CVE-2024-9238 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The AVIF Uploader WordPress plugin before 1.1.1 does not sanitise uploaded SVG files, which could allow users with a rol... |
| CVE-2024-9236 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privil... |
| CVE-2024-9233 | MEDIUM | 4.3 | 0.2% | May 15, 2025 | The Logo Slider WordPress plugin before 3.7.1 does not have CSRF check in place when updating its settings, which could... |
| CVE-2024-9227 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its set... |
| CVE-2024-9182 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Maspik WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could allow high priv... |
| CVE-2024-8854 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow hi... |
| CVE-2024-8851 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow hi... |
| CVE-2024-8759 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Nested Pages WordPress plugin before 3.2.9 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2024-8703 | MEDIUM | 6.1 | 0.3% | May 15, 2025 | The Z-Downloads WordPress plugin before 1.11.6 does not sanitise and escape some parameters when outputting them in the ... |
| CVE-2024-8702 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Backup Database WordPress plugin through 4.9 does not sanitise and escape some of its settings, which could allow hi... |
| CVE-2024-8701 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The events-calendar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-8670 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Photo Gallery by 10Web WordPress plugin before 1.8.29 does not sanitise and escape some of its settings, which coul... |
| CVE-2024-8620 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The MapPress Maps for WordPress plugin before 2.93 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-8619 | MEDIUM | 4.8 | 0.4% | May 15, 2025 | The Ajax Search Lite WordPress plugin before 4.12.3 does not sanitise and escape some of its settings, which could allo... |
| CVE-2024-8618 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Page Builder: Pagelayer WordPress plugin before 1.9.0 does not sanitise and escape some of its settings, which coul... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now