2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-53692MEDIUM5.1A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the ...
CVE-2024-50405MEDIUM5.5An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP o...
CVE-2024-12634MEDIUM6.1The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress i...
CVE-2024-9458MEDIUM4.8The Reservit Hotel WordPress plugin before 3.0 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-13857MEDIUM5.5The WPGet API – Connect to any external REST API plugin for WordPress is vulnerable to Server-Side Request Forgery in al...
CVE-2024-13805MEDIUM5.4The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerab...
CVE-2024-13635MEDIUM4.3The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
CVE-2024-13552MEDIUM4.3The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Objec...
CVE-2024-13781MEDIUM6.5The Hero Maps Premium plugin for WordPress is vulnerable to SQL Injection via several AJAX actions in all versions up to...
CVE-2024-13431MEDIUM6.1The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Ref...
CVE-2024-12611MEDIUM5.3The School Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ...
CVE-2024-12610MEDIUM5.3The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a miss...
CVE-2024-12609MEDIUM6.5The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'view-attendance'...
CVE-2024-12607MEDIUM6.5The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of...
CVE-2024-12576MEDIUM5.5Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger a crash of the FW r...
CVE-2024-12809MEDIUM6.4The Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wishlist_button' shortc...
CVE-2024-13526MEDIUM4.3The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data...
CVE-2024-57972MEDIUM6.5The pairing API request handler in Microsoft HoloLens 1 (Windows Holographic) through 10.0.17763.3046 and HoloLens 2 (Wi...
CVE-2024-58086MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Stop active perfmon if it is being destroy...
CVE-2024-58085MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tomoyo: don't emit warning in tomoyo_write_control(...
CVE-2024-58084MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: Fix missing read barrier in qc...
CVE-2024-58082MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: nuvoton: Fix an error check in npcm_video_ec...
CVE-2024-58081MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: clk: mmp2: call pm_genpd_init() only after genpd.na...
CVE-2024-58080MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: clk: qcom: dispcc-sm6350: Add missing parent_map fo...
CVE-2024-58079MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix crash during unbind if gpio un...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now