2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13616MEDIUM4.8The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.7.2 does not sanitise and escape some of its setting...
CVE-2024-13486MEDIUM4.8The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-13482MEDIUM4.8The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-13384MEDIUM4.8The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.24 does not sanitise and escape some ...
CVE-2024-13383MEDIUM4.8The HD Quiz WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2024-13382MEDIUM4.8The Calculated Fields Form WordPress plugin before 5.2.64 does not sanitise and escape some of its settings, which could...
CVE-2024-13357MEDIUM4.8The Ditty WordPress plugin before 3.1.52 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2024-13313MEDIUM4.8The AWeber WordPress plugin through 7.3.20 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2024-13128MEDIUM4.8The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow h...
CVE-2024-13127MEDIUM4.8The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow h...
CVE-2024-13053MEDIUM4.8The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could ...
CVE-2024-12874MEDIUM4.8The Top Comments WordPress plugin through 1.0 does not sanitise and escape some of its settings, which could allow high ...
CVE-2024-12873MEDIUM6.1The Custom Field Manager WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back...
CVE-2024-12812HIGH7.5The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before...
CVE-2024-12808MEDIUM4.8The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before...
CVE-2024-12800MEDIUM4.8The IP Based Login WordPress plugin before 2.4.1 does not sanitise values when importing, which could allow high privile...
CVE-2024-12770MEDIUM4.8The WP ULike WordPress plugin before 4.7.6 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2024-12767LOW3.5The buddyboss-platform WordPress plugin before 2.7.60 lacks proper access controls and allows a logged-in user to view c...
CVE-2024-12750MEDIUM4.3The Competition Form WordPress plugin through 2.0 does not have CSRF check in place when updating its settings, which co...
CVE-2024-12743MEDIUM4.8The MailPoet WordPress plugin before 5.5.2 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2024-12739MEDIUM4.8The Mobile Contact Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allo...
CVE-2024-12735HIGH7.2The Advance Post Prefix WordPress plugin through 1.1.1 does not sanitize and escape a parameter before using it in a SQL...
CVE-2024-12734MEDIUM6.1The Advance Post Prefix WordPress plugin through 1.1.1, Advance Post Prefix WordPress plugin through 1.1.1 does not sani...
CVE-2024-12733MEDIUM6.1The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it bac...
CVE-2024-12732MEDIUM6.1The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it bac...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now