2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8032 | MEDIUM | 6.1 | 0.1% | May 15, 2025 | The Smooth Gallery Replacement WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sani... |
| CVE-2024-8031 | MEDIUM | 6.5 | 0.4% | May 15, 2025 | The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloade... |
| CVE-2024-8009 | MEDIUM | 4.3 | 0.3% | May 15, 2025 | The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers ... |
| CVE-2024-7984 | MEDIUM | 4.3 | 0.2% | May 15, 2025 | The Joy Of Text Lite WordPress plugin through 2.3.1 does not have CSRF check in place when updating its settings, which... |
| CVE-2024-7769 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The ClickSold IDX WordPress plugin through 1.90 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2024-7762 | LOW | 3.7 | 0.3% | May 15, 2025 | The Simple Job Board WordPress plugin before 2.12.6 does not prevent uploaded files from being listed, allowing unauthen... |
| CVE-2024-7761 | MEDIUM | 6.1 | 0.3% | May 15, 2025 | In the process of testing the Simple Job Board WordPress plugin before 2.12.2, a vulnerability was found that allows you... |
| CVE-2024-7759 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The PWA for WP WordPress plugin before 1.7.72 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2024-7758 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Stylish Price List WordPress plugin before 7.1.8 does not sanitise and escape some of its settings, which could all... |
| CVE-2024-7556 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Simple Share WordPress plugin through 0.5.3 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2024-6809 | CRITICAL | 9.8 | 0.6% | May 15, 2025 | The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using ... |
| CVE-2024-6798 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The DL Verification WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow hi... |
| CVE-2024-6797 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The DL Robots.txt WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2024-6719 | HIGH | 8.1 | 0.2% | May 15, 2025 | The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which co... |
| CVE-2024-6718 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The PVN Auth Popup WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before o... |
| CVE-2024-6713 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The PVN Auth Popup WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2024-6712 | MEDIUM | 6.1 | 0.2% | May 15, 2025 | The MapFig Studio WordPress plugin through 0.2.1 does not have CSRF check in some places, and is missing sanitisation as... |
| CVE-2024-6711 | LOW | 3.5 | 0.3% | May 15, 2025 | The Event Tickets with Ticket Scanner WordPress plugin before 2.3.8 does not sanitise and escape some parameters, which ... |
| CVE-2024-6708 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting ... |
| CVE-2024-6693 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The wccp-pro WordPress plugin before 15.3 does not sanitise and escape some of its settings, which could allow high priv... |
| CVE-2024-6690 | MEDIUM | 6.1 | 0.5% | May 15, 2025 | The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirectio... |
| CVE-2024-6668 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The ProfilePro WordPress plugin through 1.3 does not sanitise and escape some parameters and lacks proper access control... |
| CVE-2024-6667 | MEDIUM | 6.1 | 0.3% | May 15, 2025 | The KBucket: Your Curated Content in WordPress plugin before 4.1.5 does not sanitise and escape a parameter before outpu... |
| CVE-2024-6665 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, wh... |
| CVE-2024-6584 | CRITICAL | 9.1 | 0.5% | May 15, 2025 | The 'wp_ajax_boost_proxy_ig' action allows administrators to make GET requests to arbitrary URLs. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now