2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43107 | HIGH | 7.2 | 0.2% | Mar 10, 2025 | Improper Certificate Validation (CWE-295) in the Gallagher Milestone Integration Plugin (MIP) permits unauthenticated me... |
| CVE-2024-41724 | HIGH | 8.7 | 0.2% | Mar 10, 2025 | Improper Certificate Validation (CWE-295) in the Gallagher Command Centre SALTO integration allowed an attacker to spoof... |
| CVE-2024-11640 | HIGH | 8.8 | 0.3% | Mar 8, 2025 | The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers... |
| CVE-2024-13882 | HIGH | 8.8 | 0.7% | Mar 8, 2025 | The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is... |
| CVE-2024-13908 | HIGH | 7.2 | 0.8% | Mar 8, 2025 | The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation... |
| CVE-2024-13890 | HIGH | 7.2 | 0.4% | Mar 8, 2025 | The Allow PHP Execute plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0... |
| CVE-2024-13835 | HIGH | 7.2 | 0.4% | Mar 8, 2025 | The Post Meta Data Manager plugin for WordPress is vulnerable to multisite privilege escalation in all versions up to, a... |
| CVE-2024-53700 | HIGH | 7.2 | 1.2% | Mar 7, 2025 | A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote ... |
| CVE-2024-53699 | HIGH | 7.2 | 0.5% | Mar 7, 2025 | An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, t... |
| CVE-2024-53697 | HIGH | 7.2 | 0.5% | Mar 7, 2025 | An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, t... |
| CVE-2024-53694 | HIGH | 8.6 | 0.1% | Mar 7, 2025 | A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. ... |
| CVE-2024-53693 | HIGH | 7.1 | 0.4% | Mar 7, 2025 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP o... |
| CVE-2024-50394 | HIGH | 8.8 | 0.3% | Mar 7, 2025 | An improper certificate validation vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability c... |
| CVE-2024-38638 | HIGH | 7.2 | 0.5% | Mar 7, 2025 | An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, t... |
| CVE-2024-13086 | HIGH | 7.5 | 0.4% | Mar 7, 2025 | An exposure of sensitive information vulnerability has been reported to affect product. If exploited, the vulnerability ... |
| CVE-2024-13668 | HIGH | 7.1 | 0.3% | Mar 7, 2025 | The WordPress Activity O Meter WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting i... |
| CVE-2024-9658 | HIGH | 8.8 | 0.3% | Mar 7, 2025 | The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeov... |
| CVE-2024-12036 | HIGH | 7.5 | 0.3% | Mar 7, 2025 | The CS Framework plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.9 via... |
| CVE-2024-12035 | HIGH | 8.8 | 0.8% | Mar 7, 2025 | The CS Framework plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation ... |
| CVE-2024-10804 | HIGH | 7.5 | 0.8% | Mar 7, 2025 | The Ultimate Video Player WordPress & WooCommerce Plugin plugin for WordPress is vulnerable to Directory Traversal in al... |
| CVE-2024-13906 | HIGH | 7.2 | 0.7% | Mar 7, 2025 | The Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress plugin for WordPress is vulnerable to ... |
| CVE-2024-12837 | HIGH | 7.8 | 0.2% | Mar 7, 2025 | Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory. |
| CVE-2024-13655 | HIGH | 8.1 | 0.3% | Mar 7, 2025 | The Flex Mag - Responsive WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data th... |
| CVE-2024-13320 | HIGH | 7.5 | 0.4% | Mar 7, 2025 | The CURCY - WooCommerce Multi Currency - Currency Switcher plugin for WordPress is vulnerable to SQL Injection via the '... |
| CVE-2024-50600 | HIGH | 7.5 | 0.4% | Mar 6, 2025 | An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now