2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13823 | MEDIUM | 6.1 | 0.3% | May 15, 2025 | The 360 Product Rotation WordPress plugin through 1.5.8 does not sanitise and escape a parameter before outputting it ba... |
| CVE-2024-13730 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Podlove Podcast Publisher WordPress plugin before 4.2.1 does not sanitise and escape some of its settings, which cou... |
| CVE-2024-13729 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Podlove Podcast Publisher WordPress plugin before 4.1.24 does not sanitise and escape some of its settings, which co... |
| CVE-2024-13727 | MEDIUM | 6.1 | 0.6% | May 15, 2025 | The MemberSpace WordPress plugin before 2.1.14 does not sanitise and escape a parameter before outputting it back in th... |
| CVE-2024-13621 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The GDPR Framework By Data443 WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which cou... |
| CVE-2024-13619 | MEDIUM | 6.1 | 0.5% | May 15, 2025 | The LifterLMS WordPress plugin before 8.0.1 does not sanitise and escape a parameter before outputting it back in the p... |
| CVE-2024-13616 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.7.2 does not sanitise and escape some of its setting... |
| CVE-2024-13486 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-13482 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-13384 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.24 does not sanitise and escape some ... |
| CVE-2024-13383 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The HD Quiz WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high priv... |
| CVE-2024-13382 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Calculated Fields Form WordPress plugin before 5.2.64 does not sanitise and escape some of its settings, which could... |
| CVE-2024-13357 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Ditty WordPress plugin before 3.1.52 does not sanitise and escape some of its settings, which could allow high priv... |
| CVE-2024-13313 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The AWeber WordPress plugin through 7.3.20 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2024-13128 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2024-13127 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2024-13053 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could ... |
| CVE-2024-12874 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Top Comments WordPress plugin through 1.0 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2024-12873 | MEDIUM | 6.1 | 0.5% | May 15, 2025 | The Custom Field Manager WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back... |
| CVE-2024-12808 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before... |
| CVE-2024-12800 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The IP Based Login WordPress plugin before 2.4.1 does not sanitise values when importing, which could allow high privile... |
| CVE-2024-12770 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The WP ULike WordPress plugin before 4.7.6 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2024-12750 | MEDIUM | 4.3 | 0.2% | May 15, 2025 | The Competition Form WordPress plugin through 2.0 does not have CSRF check in place when updating its settings, which co... |
| CVE-2024-12743 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The MailPoet WordPress plugin before 5.5.2 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2024-12739 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Mobile Contact Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allo... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now