2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10677MEDIUM4.3The BTEV WordPress plugin through 2.0.2 does not have CSRF check in place when updating its settings, which could allow ...
CVE-2024-10639MEDIUM4.8The Auto Prune Posts WordPress plugin before 3.0.0 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-10634MEDIUM4.3The Nokaut Offers Box WordPress plugin through 1.4.0 does not have CSRF check in place when updating its settings, which...
CVE-2024-10632MEDIUM4.8The Nokaut Offers Box WordPress plugin through 1.4.0 does not sanitize and escape some of its settings, which could allo...
CVE-2024-10631MEDIUM6.5The Countdown Timer for WordPress Block Editor WordPress plugin through 1.0.5 does not validate and escape some of its b...
CVE-2024-10504MEDIUM5.4The Contact Form, Survey, Quiz & Popup Form Builder WordPress plugin before 1.7.1 does not sanitise and escape some par...
CVE-2024-10475MEDIUM4.8The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin before 1.9.8 does not sanitise and escape ...
CVE-2024-10362MEDIUM4.8The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.9.1 does not sanitize and escape some of...
CVE-2024-10149MEDIUM4.8The Social Slider Feed WordPress plugin before 2.2.9 does not sanitise and escape some of its settings, which could allo...
CVE-2024-10145MEDIUM4.8The Hubbub Lite WordPress plugin before 1.34.4 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-10144MEDIUM4.8The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some ...
CVE-2024-10143MEDIUM4.8The MB Custom Post Types & Custom Taxonomies WordPress plugin before 2.7.7 does not sanitise and escape some of its sett...
CVE-2024-10107MEDIUM4.8The Giveaways and Contests by RafflePress WordPress plugin before 1.12.17 does not sanitise and escape some of its sett...
CVE-2024-10098LOW2.7The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing ...
CVE-2024-10076MEDIUM5.9The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelera...
CVE-2024-10075MEDIUM5.6The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible t...
CVE-2024-10054MEDIUM4.8The Happyforms WordPress plugin before 1.26.3 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-10009MEDIUM4.1The Melapress File Monitor WordPress plugin before 2.1.0 does not sanitize and escape a parameter before using it in a S...
CVE-2024-0970MEDIUM5.3This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrust...
CVE-2024-0852HIGH8.8The coreActivity: Activity Logging for WordPress plugin before 1.8.1 does not escape some request data when outputting i...
CVE-2024-0249HIGH7.1The Advanced Schedule Posts WordPress plugin through 2.1.8 does not sanitise and escape a parameter before outputting it...
CVE-2024-56006MEDIUM5.3Missing Authorization vulnerability in Automattic Jetpack Debug Tools.This issue affects Jetpack Debug Tools: from n/a b...
CVE-2024-51666MEDIUM4.3Missing Authorization vulnerability in Tosin Oguntuyi Tours tours.This issue affects Tours: from n/a through <= 1.0.0.
CVE-2024-52880HIGH7.9An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kern...
CVE-2024-52879HIGH7.5An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kern...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now