2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8701 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The events-calendar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-8700 | HIGH | 7.5 | 0.4% | May 15, 2025 | The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthent... |
| CVE-2024-8699 | HIGH | 7.2 | 0.6% | May 15, 2025 | The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users ... |
| CVE-2024-8673 | CRITICAL | 9.1 | 1.6% | May 15, 2025 | The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of S... |
| CVE-2024-8670 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Photo Gallery by 10Web WordPress plugin before 1.8.29 does not sanitise and escape some of its settings, which coul... |
| CVE-2024-8620 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The MapPress Maps for WordPress plugin before 2.93 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-8619 | MEDIUM | 4.8 | 0.4% | May 15, 2025 | The Ajax Search Lite WordPress plugin before 4.12.3 does not sanitise and escape some of its settings, which could allo... |
| CVE-2024-8618 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Page Builder: Pagelayer WordPress plugin before 1.9.0 does not sanitise and escape some of its settings, which coul... |
| CVE-2024-8617 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Quiz Maker WordPress plugin before 6.5.9.9 does not sanitize and escape some of its settings, which could allow high... |
| CVE-2024-8542 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Everest Forms WordPress plugin before 3.0.3.1 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-8493 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2024-8492 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Hustle WordPress plugin through 7.8.5 does not sanitise and escape some of its settings, which could allow high pri... |
| CVE-2024-8426 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Page Builder: Pagelayer WordPress plugin before 1.8.8 does not sanitise and escape some of its settings, which coul... |
| CVE-2024-8398 | MEDIUM | 4.3 | 0.2% | May 15, 2025 | The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, whi... |
| CVE-2024-8397 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers whe... |
| CVE-2024-8286 | MEDIUM | 6.5 | 0.2% | May 15, 2025 | The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which co... |
| CVE-2024-8284 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow... |
| CVE-2024-8245 | MEDIUM | 4.3 | 0.2% | May 15, 2025 | The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could a... |
| CVE-2024-8187 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Smart Post Show WordPress plugin before 3.0.1 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-8095 | MEDIUM | 6.1 | 0.1% | May 15, 2025 | The BabelZ WordPress plugin through 1.1.5 does not have CSRF check in some places, and is missing sanitisation as well ... |
| CVE-2024-8094 | MEDIUM | 6.5 | 0.2% | May 15, 2025 | The Ntz Antispam WordPress plugin through 2.0e does not have CSRF check in place when updating its settings, which could... |
| CVE-2024-8090 | MEDIUM | 6.1 | 0.2% | May 15, 2025 | The JavaScript Logic WordPress plugin through 0.1 does not have CSRF check in some places, and is missing sanitisation a... |
| CVE-2024-8085 | MEDIUM | 6.1 | 0.1% | May 15, 2025 | The PeoplePond WordPress plugin through 1.1.9 does not have CSRF check in some places, and is missing sanitisation as we... |
| CVE-2024-8082 | MEDIUM | 4.3 | 0.2% | May 15, 2025 | The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could... |
| CVE-2024-8050 | MEDIUM | 4.3 | 0.2% | May 15, 2025 | The Custom Author Base WordPress plugin through 1.1.1 does not have CSRF check in place when updating its settings, whic... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now