2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-12010HIGH7.2A post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the Zyxel AX7501-B1 firmware v...
CVE-2024-12009HIGH7.2A post-authentication command injection vulnerability in the "ZyEE" function of the Zyxel EX5601-T1 firmware version V5....
CVE-2024-11253HIGH7.2A post-authentication command injection vulnerability in the "DNSServer” parameter of the diagnostic function in the Zyx...
CVE-2024-56192HIGH7.8In wl_notify_gscan_event of wl_cfgscan.c, there is a possible out of bounds write due to a missing bounds check. This co...
CVE-2024-56191HIGH8.4In dhd_process_full_gscan_result of dhd_pno.c, there is a possible EoP due to an integer overflow. This could lead to lo...
CVE-2024-54546HIGH7.5The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An app may be able to ca...
CVE-2024-44227HIGH7.5The issue was addressed with improved memory handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An...
CVE-2024-11638HIGH8.8The Gtbabel WordPress plugin before 6.6.9 does not ensure that the URL to perform code analysis upon belongs to the blog...
CVE-2024-43107HIGH7.2Improper Certificate Validation (CWE-295) in the Gallagher Milestone Integration Plugin (MIP) permits unauthenticated me...
CVE-2024-41724HIGH8.7Improper Certificate Validation (CWE-295) in the Gallagher Command Centre SALTO integration allowed an attacker to spoof...
CVE-2024-11640HIGH8.8The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers...
CVE-2024-13882HIGH8.8The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is...
CVE-2024-13908HIGH7.2The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation...
CVE-2024-13890HIGH7.2The Allow PHP Execute plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0...
CVE-2024-13835HIGH7.2The Post Meta Data Manager plugin for WordPress is vulnerable to multisite privilege escalation in all versions up to, a...
CVE-2024-53700HIGH7.2A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote ...
CVE-2024-53699HIGH7.2An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, t...
CVE-2024-53697HIGH7.2An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, t...
CVE-2024-53694HIGH8.6A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. ...
CVE-2024-53693HIGH7.1An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP o...
CVE-2024-50394HIGH8.8An improper certificate validation vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability c...
CVE-2024-38638HIGH7.2An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, t...
CVE-2024-13086HIGH7.5An exposure of sensitive information vulnerability has been reported to affect product. If exploited, the vulnerability ...
CVE-2024-13668HIGH7.1The WordPress Activity O Meter WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting i...
CVE-2024-9658HIGH8.8The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeov...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now