2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5282 | MEDIUM | 6.1 | 0.3% | Jul 13, 2024 | The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it ba... |
| CVE-2024-5281 | MEDIUM | 6.1 | 0.4% | Jul 13, 2024 | The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it ba... |
| CVE-2024-5280 | MEDIUM | 4.7 | 0.2% | Jul 13, 2024 | The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisa... |
| CVE-2024-5167 | HIGH | 8.1 | 0.3% | Jul 13, 2024 | The CM Email Registration Blacklist and Whitelist WordPress plugin before 1.4.9 does not have CSRF check when adding or ... |
| CVE-2024-5151 | HIGH | 7.1 | 0.4% | Jul 13, 2024 | The SULly WordPress plugin before 4.3.1 does not sanitise and escape some of its settings, which could allow high privil... |
| CVE-2024-5080 | HIGH | 8.8 | 0.7% | Jul 13, 2024 | The wp-eMember WordPress plugin before 10.6.6 does not validate files to be uploaded, which could allow admins to upload... |
| CVE-2024-5079 | MEDIUM | 6.1 | 0.4% | Jul 13, 2024 | The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape some of the fields when members register, whi... |
| CVE-2024-5077 | MEDIUM | 6.8 | 0.2% | Jul 13, 2024 | The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as we... |
| CVE-2024-5076 | HIGH | 8.8 | 0.3% | Jul 13, 2024 | The wp-eMember WordPress plugin before 10.6.6 does not have CSRF checks in some places, which could allow attackers to m... |
| CVE-2024-5075 | MEDIUM | 5.9 | 0.3% | Jul 13, 2024 | The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the ... |
| CVE-2024-5074 | MEDIUM | 5.4 | 0.4% | Jul 13, 2024 | The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the ... |
| CVE-2024-5034 | HIGH | 8.8 | 0.4% | Jul 13, 2024 | The SULly WordPress plugin before 4.3.1 does not have CSRF checks in some places, which could allow attackers to make lo... |
| CVE-2024-5033 | MEDIUM | 5.9 | 0.2% | Jul 13, 2024 | The SULly WordPress plugin before 4.3.1 does not have CSRF check in some places, and is missing sanitisation as well as ... |
| CVE-2024-5032 | MEDIUM | 4.7 | 0.5% | Jul 13, 2024 | The SULly WordPress plugin before 4.3.1 does not sanitise and escape a parameter before outputting it back in the page, ... |
| CVE-2024-5028 | MEDIUM | 6.5 | 0.2% | Jul 13, 2024 | The CM WordPress Search And Replace Plugin WordPress plugin before 1.3.9 does not have CSRF checks in some places, which... |
| CVE-2024-5002 | MEDIUM | 4.8 | 0.4% | Jul 13, 2024 | The User Submitted Posts WordPress plugin before 20240516 does not sanitise and escape some of its settings, which coul... |
| CVE-2024-4977 | MEDIUM | 6.8 | 0.5% | Jul 13, 2024 | The Index WP MySQL For Speed WordPress plugin before 1.4.18 does not sanitise and escape a parameter before outputting i... |
| CVE-2024-4752 | MEDIUM | 5.9 | 0.4% | Jul 13, 2024 | The EventON WordPress plugin before 2.2.15 does not sanitise and escape some of its settings, which could allow high pri... |
| CVE-2024-4602 | MEDIUM | 5.4 | 0.4% | Jul 13, 2024 | The Embed Peertube Playlist WordPress plugin before 1.10 does not sanitise and escape some of its settings, which could ... |
| CVE-2024-4272 | MEDIUM | 6.1 | 0.4% | Jul 13, 2024 | The Support SVG WordPress plugin before 1.1.0 does not sanitize SVG file contents, which enables users with at least th... |
| CVE-2024-4269 | MEDIUM | 6.1 | 0.4% | Jul 13, 2024 | The SVG Block WordPress plugin before 1.1.20 does not sanitize SVG file contents, which enables users with at least the ... |
| CVE-2024-4217 | MEDIUM | 4.7 | 0.5% | Jul 13, 2024 | The shortcodes-ultimate-pro WordPress plugin before 7.1.5 does not properly escape some of its shortcodes' settings, mak... |
| CVE-2024-3964 | MEDIUM | 5.9 | 0.5% | Jul 13, 2024 | The Product Enquiry for WooCommerce WordPress plugin before 3.1.8 does not sanitise and escape some of its settings, whi... |
| CVE-2024-3963 | MEDIUM | 6.5 | 0.5% | Jul 13, 2024 | The Giveaways and Contests by RafflePress WordPress plugin before 1.12.14 does not sanitise and escape some parameters,... |
| CVE-2024-3919 | MEDIUM | 4.6 | 0.3% | Jul 13, 2024 | The OpenPGP Form Encryption for WordPress plugin before 1.5.1 does not validate and escape some of its shortcode attribu... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now