2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6465 | MEDIUM | 4.3 | 0.4% | Jul 13, 2024 | The WP Links Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch... |
| CVE-2024-6574 | MEDIUM | 5.3 | 0.4% | Jul 13, 2024 | The Laposta plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.12. This ... |
| CVE-2024-6070 | MEDIUM | 4.8 | 0.4% | Jul 13, 2024 | The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not sanitise and escape some of its setti... |
| CVE-2024-5744 | MEDIUM | 6.8 | 0.4% | Jul 13, 2024 | The wp-eMember WordPress plugin before 10.6.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it... |
| CVE-2024-5713 | MEDIUM | 5.4 | 0.4% | Jul 13, 2024 | The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not escape the $_SERVER['REQUEST_URI'] pa... |
| CVE-2024-5644 | MEDIUM | 5.4 | 0.4% | Jul 13, 2024 | The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2024-5627 | MEDIUM | 5.4 | 0.3% | Jul 13, 2024 | The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some parameters, which could allow users with... |
| CVE-2024-5575 | MEDIUM | 4.7 | 0.4% | Jul 13, 2024 | The Ditty WordPress plugin before 3.1.43 does not sanitise and escape some of its blocks' settings, which could allow h... |
| CVE-2024-5442 | MEDIUM | 5.9 | 0.4% | Jul 13, 2024 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.3 does not sanitise and escape some of its setti... |
| CVE-2024-5286 | MEDIUM | 4.8 | 0.4% | Jul 13, 2024 | The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it ba... |
| CVE-2024-5284 | MEDIUM | 6.8 | 0.2% | Jul 13, 2024 | The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisa... |
| CVE-2024-5283 | MEDIUM | 6.1 | 0.4% | Jul 13, 2024 | The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it ba... |
| CVE-2024-5282 | MEDIUM | 6.1 | 0.3% | Jul 13, 2024 | The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it ba... |
| CVE-2024-5281 | MEDIUM | 6.1 | 0.4% | Jul 13, 2024 | The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it ba... |
| CVE-2024-5280 | MEDIUM | 4.7 | 0.2% | Jul 13, 2024 | The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisa... |
| CVE-2024-5079 | MEDIUM | 6.1 | 0.4% | Jul 13, 2024 | The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape some of the fields when members register, whi... |
| CVE-2024-5077 | MEDIUM | 6.8 | 0.2% | Jul 13, 2024 | The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as we... |
| CVE-2024-5075 | MEDIUM | 5.9 | 0.3% | Jul 13, 2024 | The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the ... |
| CVE-2024-5074 | MEDIUM | 5.4 | 0.4% | Jul 13, 2024 | The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the ... |
| CVE-2024-5033 | MEDIUM | 5.9 | 0.2% | Jul 13, 2024 | The SULly WordPress plugin before 4.3.1 does not have CSRF check in some places, and is missing sanitisation as well as ... |
| CVE-2024-5032 | MEDIUM | 4.7 | 0.5% | Jul 13, 2024 | The SULly WordPress plugin before 4.3.1 does not sanitise and escape a parameter before outputting it back in the page, ... |
| CVE-2024-5028 | MEDIUM | 6.5 | 0.2% | Jul 13, 2024 | The CM WordPress Search And Replace Plugin WordPress plugin before 1.3.9 does not have CSRF checks in some places, which... |
| CVE-2024-5002 | MEDIUM | 4.8 | 0.4% | Jul 13, 2024 | The User Submitted Posts WordPress plugin before 20240516 does not sanitise and escape some of its settings, which coul... |
| CVE-2024-4977 | MEDIUM | 6.8 | 0.5% | Jul 13, 2024 | The Index WP MySQL For Speed WordPress plugin before 1.4.18 does not sanitise and escape a parameter before outputting i... |
| CVE-2024-4752 | MEDIUM | 5.9 | 0.4% | Jul 13, 2024 | The EventON WordPress plugin before 2.2.15 does not sanitise and escape some of its settings, which could allow high pri... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now