2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-8701MEDIUM4.8The events-calendar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-8700HIGH7.5The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthent...
CVE-2024-8699HIGH7.2The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users ...
CVE-2024-8673CRITICAL9.1The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of S...
CVE-2024-8670MEDIUM4.8The Photo Gallery by 10Web WordPress plugin before 1.8.29 does not sanitise and escape some of its settings, which coul...
CVE-2024-8620MEDIUM4.8The MapPress Maps for WordPress plugin before 2.93 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-8619MEDIUM4.8The Ajax Search Lite WordPress plugin before 4.12.3 does not sanitise and escape some of its settings, which could allo...
CVE-2024-8618MEDIUM4.8The Page Builder: Pagelayer WordPress plugin before 1.9.0 does not sanitise and escape some of its settings, which coul...
CVE-2024-8617MEDIUM4.8The Quiz Maker WordPress plugin before 6.5.9.9 does not sanitize and escape some of its settings, which could allow high...
CVE-2024-8542MEDIUM4.8The Everest Forms WordPress plugin before 3.0.3.1 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-8493MEDIUM4.8The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow h...
CVE-2024-8492MEDIUM4.8The Hustle WordPress plugin through 7.8.5 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2024-8426MEDIUM4.8The Page Builder: Pagelayer WordPress plugin before 1.8.8 does not sanitise and escape some of its settings, which coul...
CVE-2024-8398MEDIUM4.3The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, whi...
CVE-2024-8397MEDIUM5.4The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers whe...
CVE-2024-8286MEDIUM6.5The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which co...
CVE-2024-8284MEDIUM4.8The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow...
CVE-2024-8245MEDIUM4.3The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could a...
CVE-2024-8187MEDIUM4.8The Smart Post Show WordPress plugin before 3.0.1 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-8095MEDIUM6.1The BabelZ WordPress plugin through 1.1.5 does not have CSRF check in some places, and is missing sanitisation as well ...
CVE-2024-8094MEDIUM6.5The Ntz Antispam WordPress plugin through 2.0e does not have CSRF check in place when updating its settings, which could...
CVE-2024-8090MEDIUM6.1The JavaScript Logic WordPress plugin through 0.1 does not have CSRF check in some places, and is missing sanitisation a...
CVE-2024-8085MEDIUM6.1The PeoplePond WordPress plugin through 1.1.9 does not have CSRF check in some places, and is missing sanitisation as we...
CVE-2024-8082MEDIUM4.3The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could...
CVE-2024-8050MEDIUM4.3The Custom Author Base WordPress plugin through 1.1.1 does not have CSRF check in place when updating its settings, whic...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now