2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8201 | MEDIUM | 5.4 | 0.1% | May 16, 2025 | Cross-Site WebSocket Hijacking vulnerability in Hitachi Ops Center Analyzer (RAID Agent component).This issue affects Hi... |
| CVE-2024-51475 | MEDIUM | 6.1 | 0.2% | May 16, 2025 | IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to HTML injection. A remote attacker could inject maliciou... |
| CVE-2024-9882 | MEDIUM | 4.8 | 0.2% | May 15, 2025 | The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses WordPress plugin before 1.9.4 does ... |
| CVE-2024-9879 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The Melapress File Monitor WordPress plugin before 2.1.1 does not sanitize and escape a parameter before using it in a S... |
| CVE-2024-9838 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The Auto Affiliate Links WordPress plugin before 6.4.7 does not sanitize and escape a parameter before using it in a SQL... |
| CVE-2024-9831 | HIGH | 7.2 | 0.5% | May 15, 2025 | The Taskbuilder WordPress plugin before 3.0.9 does not sanitize and escape a parameter before using it in a SQL stateme... |
| CVE-2024-9765 | MEDIUM | 6.5 | 1.4% | May 15, 2025 | The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of th... |
| CVE-2024-9711 | MEDIUM | 5.4 | 0.2% | May 15, 2025 | The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, w... |
| CVE-2024-9709 | MEDIUM | 5.4 | 0.2% | May 15, 2025 | The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, w... |
| CVE-2024-9663 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2024-9662 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2024-9645 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry WordPress plugin before 2.2.93 does not validate ... |
| CVE-2024-9599 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The Popup Box WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high p... |
| CVE-2024-9450 | MEDIUM | 6.5 | 0.2% | May 15, 2025 | The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check... |
| CVE-2024-9390 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could al... |
| CVE-2024-9238 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The AVIF Uploader WordPress plugin before 1.1.1 does not sanitise uploaded SVG files, which could allow users with a rol... |
| CVE-2024-9236 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privil... |
| CVE-2024-9233 | MEDIUM | 4.3 | 0.2% | May 15, 2025 | The Logo Slider WordPress plugin before 3.7.1 does not have CSRF check in place when updating its settings, which could... |
| CVE-2024-9227 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its set... |
| CVE-2024-9182 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Maspik WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could allow high priv... |
| CVE-2024-8854 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow hi... |
| CVE-2024-8851 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow hi... |
| CVE-2024-8759 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Nested Pages WordPress plugin before 3.2.9 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2024-8703 | MEDIUM | 6.1 | 0.3% | May 15, 2025 | The Z-Downloads WordPress plugin before 1.11.6 does not sanitise and escape some parameters when outputting them in the ... |
| CVE-2024-8702 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Backup Database WordPress plugin through 4.9 does not sanitise and escape some of its settings, which could allow hi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now