2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-9838MEDIUM5.4The Auto Affiliate Links WordPress plugin before 6.4.7 does not sanitize and escape a parameter before using it in a SQL...
CVE-2024-9765MEDIUM6.5The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of th...
CVE-2024-9711MEDIUM5.4The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, w...
CVE-2024-9709MEDIUM5.4The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, w...
CVE-2024-9663MEDIUM5.4The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high ...
CVE-2024-9662MEDIUM5.4The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high ...
CVE-2024-9645MEDIUM5.4The Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry WordPress plugin before 2.2.93 does not validate ...
CVE-2024-9599MEDIUM5.4The Popup Box WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high p...
CVE-2024-9450MEDIUM6.5The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check...
CVE-2024-9390MEDIUM4.8The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could al...
CVE-2024-9238MEDIUM5.4The AVIF Uploader WordPress plugin before 1.1.1 does not sanitise uploaded SVG files, which could allow users with a rol...
CVE-2024-9236MEDIUM4.8The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privil...
CVE-2024-9233MEDIUM4.3The Logo Slider WordPress plugin before 3.7.1 does not have CSRF check in place when updating its settings, which could...
CVE-2024-9227MEDIUM4.8The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its set...
CVE-2024-9182MEDIUM4.8The Maspik WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2024-8854MEDIUM5.4The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow hi...
CVE-2024-8851MEDIUM5.4The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow hi...
CVE-2024-8759MEDIUM4.8The Nested Pages WordPress plugin before 3.2.9 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-8703MEDIUM6.1The Z-Downloads WordPress plugin before 1.11.6 does not sanitise and escape some parameters when outputting them in the ...
CVE-2024-8702MEDIUM4.8The Backup Database WordPress plugin through 4.9 does not sanitise and escape some of its settings, which could allow hi...
CVE-2024-8701MEDIUM4.8The events-calendar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-8670MEDIUM4.8The Photo Gallery by 10Web WordPress plugin before 1.8.29 does not sanitise and escape some of its settings, which coul...
CVE-2024-8620MEDIUM4.8The MapPress Maps for WordPress plugin before 2.93 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-8619MEDIUM4.8The Ajax Search Lite WordPress plugin before 4.12.3 does not sanitise and escape some of its settings, which could allo...
CVE-2024-8618MEDIUM4.8The Page Builder: Pagelayer WordPress plugin before 1.9.0 does not sanitise and escape some of its settings, which coul...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now