2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-9645MEDIUM5.4The Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry WordPress plugin before 2.2.93 does not validate ...
CVE-2024-9599MEDIUM5.4The Popup Box WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high p...
CVE-2024-9450MEDIUM6.5The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check...
CVE-2024-9390MEDIUM4.8The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could al...
CVE-2024-9238MEDIUM5.4The AVIF Uploader WordPress plugin before 1.1.1 does not sanitise uploaded SVG files, which could allow users with a rol...
CVE-2024-9236MEDIUM4.8The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privil...
CVE-2024-9233MEDIUM4.3The Logo Slider WordPress plugin before 3.7.1 does not have CSRF check in place when updating its settings, which could...
CVE-2024-9227MEDIUM4.8The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its set...
CVE-2024-9182MEDIUM4.8The Maspik WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2024-8854MEDIUM5.4The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow hi...
CVE-2024-8851MEDIUM5.4The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow hi...
CVE-2024-8759MEDIUM4.8The Nested Pages WordPress plugin before 3.2.9 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-8703MEDIUM6.1The Z-Downloads WordPress plugin before 1.11.6 does not sanitise and escape some parameters when outputting them in the ...
CVE-2024-8702MEDIUM4.8The Backup Database WordPress plugin through 4.9 does not sanitise and escape some of its settings, which could allow hi...
CVE-2024-8701MEDIUM4.8The events-calendar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-8670MEDIUM4.8The Photo Gallery by 10Web WordPress plugin before 1.8.29 does not sanitise and escape some of its settings, which coul...
CVE-2024-8620MEDIUM4.8The MapPress Maps for WordPress plugin before 2.93 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-8619MEDIUM4.8The Ajax Search Lite WordPress plugin before 4.12.3 does not sanitise and escape some of its settings, which could allo...
CVE-2024-8618MEDIUM4.8The Page Builder: Pagelayer WordPress plugin before 1.9.0 does not sanitise and escape some of its settings, which coul...
CVE-2024-8617MEDIUM4.8The Quiz Maker WordPress plugin before 6.5.9.9 does not sanitize and escape some of its settings, which could allow high...
CVE-2024-8542MEDIUM4.8The Everest Forms WordPress plugin before 3.0.3.1 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-8493MEDIUM4.8The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow h...
CVE-2024-8492MEDIUM4.8The Hustle WordPress plugin through 7.8.5 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2024-8426MEDIUM4.8The Page Builder: Pagelayer WordPress plugin before 1.8.8 does not sanitise and escape some of its settings, which coul...
CVE-2024-8398MEDIUM4.3The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, whi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now