2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-43107HIGH7.2Improper Certificate Validation (CWE-295) in the Gallagher Milestone Integration Plugin (MIP) permits unauthenticated me...
CVE-2024-41724HIGH8.7Improper Certificate Validation (CWE-295) in the Gallagher Command Centre SALTO integration allowed an attacker to spoof...
CVE-2024-11640HIGH8.8The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers...
CVE-2024-13882HIGH8.8The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is...
CVE-2024-13908HIGH7.2The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation...
CVE-2024-13890HIGH7.2The Allow PHP Execute plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0...
CVE-2024-13835HIGH7.2The Post Meta Data Manager plugin for WordPress is vulnerable to multisite privilege escalation in all versions up to, a...
CVE-2024-53700HIGH7.2A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote ...
CVE-2024-53699HIGH7.2An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, t...
CVE-2024-53697HIGH7.2An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, t...
CVE-2024-53694HIGH8.6A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. ...
CVE-2024-53693HIGH7.1An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP o...
CVE-2024-50394HIGH8.8An improper certificate validation vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability c...
CVE-2024-38638HIGH7.2An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, t...
CVE-2024-13086HIGH7.5An exposure of sensitive information vulnerability has been reported to affect product. If exploited, the vulnerability ...
CVE-2024-13668HIGH7.1The WordPress Activity O Meter WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting i...
CVE-2024-9658HIGH8.8The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeov...
CVE-2024-12036HIGH7.5The CS Framework plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.9 via...
CVE-2024-12035HIGH8.8The CS Framework plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation ...
CVE-2024-10804HIGH7.5The Ultimate Video Player WordPress & WooCommerce Plugin plugin for WordPress is vulnerable to Directory Traversal in al...
CVE-2024-13906HIGH7.2The Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress plugin for WordPress is vulnerable to ...
CVE-2024-12837HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory.
CVE-2024-13655HIGH8.1The Flex Mag - Responsive WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data th...
CVE-2024-13320HIGH7.5The CURCY - WooCommerce Multi Currency - Currency Switcher plugin for WordPress is vulnerable to SQL Injection via the '...
CVE-2024-50600HIGH7.5An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now