2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6486 | HIGH | 7.2 | 2.1% | May 15, 2025 | The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injec... |
| CVE-2024-6478 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The CTT Expresso para WooCommerce WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, whic... |
| CVE-2024-6462 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The DL Yandex Metrika WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-6335 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Tracking Code Manager WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could a... |
| CVE-2024-6159 | CRITICAL | 9.8 | 2.5% | May 15, 2025 | The Push Notification for Post and BuddyPress WordPress plugin before 1.9.4 does not properly sanitise and escape a para... |
| CVE-2024-5440 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.3 does not validate and escape some of its short... |
| CVE-2024-5026 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The CM Tooltip Glossary WordPress plugin before 4.3.4 does not sanitise and escape some of its settings, which could all... |
| CVE-2024-4665 | MEDIUM | 6.4 | 0.3% | May 15, 2025 | The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing use... |
| CVE-2024-4091 | LOW | 3.5 | 0.3% | May 15, 2025 | The Responsive Gallery Grid WordPress plugin before 2.3.15 does not sanitise and escape some of its settings, which coul... |
| CVE-2024-4004 | LOW | 3.5 | 0.3% | May 15, 2025 | The Advanced Cron Manager WordPress plugin before 2.5.7 does not sanitise and escape some of its settings, which could ... |
| CVE-2024-4002 | LOW | 3.5 | 0.3% | May 15, 2025 | The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.6.9 does not sanitise and escape some of its set... |
| CVE-2024-3996 | LOW | 3.5 | 0.3% | May 15, 2025 | The Smart Post Show WordPress plugin before 2.4.28 does not sanitise and escape some of its settings, which could allow... |
| CVE-2024-3901 | MEDIUM | 6.8 | 0.5% | May 15, 2025 | The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blo... |
| CVE-2024-3062 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Save as Image Plugin by Pdfcrowd WordPress plugin before 3.2.2 does not sanitise and escape some of its settings, wh... |
| CVE-2024-2869 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could ... |
| CVE-2024-2643 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin ... |
| CVE-2024-1663 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Ultimate Noindex Nofollow Tool II WordPress plugin before 1.3.6 does not sanitise and escape some of its settings, w... |
| CVE-2024-13865 | MEDIUM | 6.1 | 0.3% | May 15, 2025 | The S3Player WordPress plugin through 4.2.1 does not sanitise and escape a parameter before outputting it back in the p... |
| CVE-2024-13828 | MEDIUM | 6.1 | 0.3% | May 15, 2025 | The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape a parameter before outputting it back in the ... |
| CVE-2024-13823 | MEDIUM | 6.1 | 0.3% | May 15, 2025 | The 360 Product Rotation WordPress plugin through 1.5.8 does not sanitise and escape a parameter before outputting it ba... |
| CVE-2024-13730 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Podlove Podcast Publisher WordPress plugin before 4.2.1 does not sanitise and escape some of its settings, which cou... |
| CVE-2024-13729 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Podlove Podcast Publisher WordPress plugin before 4.1.24 does not sanitise and escape some of its settings, which co... |
| CVE-2024-13727 | MEDIUM | 6.1 | 0.6% | May 15, 2025 | The MemberSpace WordPress plugin before 2.1.14 does not sanitise and escape a parameter before outputting it back in th... |
| CVE-2024-13621 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The GDPR Framework By Data443 WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which cou... |
| CVE-2024-13619 | MEDIUM | 6.1 | 0.5% | May 15, 2025 | The LifterLMS WordPress plugin before 8.0.1 does not sanitise and escape a parameter before outputting it back in the p... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now