2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53692 | MEDIUM | 5.1 | 0.8% | Mar 7, 2025 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the ... |
| CVE-2024-50405 | MEDIUM | 5.5 | 0.4% | Mar 7, 2025 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP o... |
| CVE-2024-12634 | MEDIUM | 6.1 | 0.2% | Mar 7, 2025 | The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress i... |
| CVE-2024-9458 | MEDIUM | 4.8 | 0.8% | Mar 7, 2025 | The Reservit Hotel WordPress plugin before 3.0 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2024-13857 | MEDIUM | 5.5 | 0.3% | Mar 7, 2025 | The WPGet API – Connect to any external REST API plugin for WordPress is vulnerable to Server-Side Request Forgery in al... |
| CVE-2024-13805 | MEDIUM | 5.4 | 0.2% | Mar 7, 2025 | The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerab... |
| CVE-2024-13635 | MEDIUM | 4.3 | 0.3% | Mar 7, 2025 | The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,... |
| CVE-2024-13552 | MEDIUM | 4.3 | 0.3% | Mar 7, 2025 | The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Objec... |
| CVE-2024-13781 | MEDIUM | 6.5 | 0.3% | Mar 7, 2025 | The Hero Maps Premium plugin for WordPress is vulnerable to SQL Injection via several AJAX actions in all versions up to... |
| CVE-2024-13431 | MEDIUM | 6.1 | 0.3% | Mar 7, 2025 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Ref... |
| CVE-2024-12611 | MEDIUM | 5.3 | 0.3% | Mar 7, 2025 | The School Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ... |
| CVE-2024-12610 | MEDIUM | 5.3 | 0.3% | Mar 7, 2025 | The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a miss... |
| CVE-2024-12609 | MEDIUM | 6.5 | 0.4% | Mar 7, 2025 | The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'view-attendance'... |
| CVE-2024-12607 | MEDIUM | 6.5 | 0.3% | Mar 7, 2025 | The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of... |
| CVE-2024-12576 | MEDIUM | 5.5 | 0.1% | Mar 7, 2025 | Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger a crash of the FW r... |
| CVE-2024-12809 | MEDIUM | 6.4 | 0.3% | Mar 7, 2025 | The Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wishlist_button' shortc... |
| CVE-2024-13526 | MEDIUM | 4.3 | 0.3% | Mar 7, 2025 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data... |
| CVE-2024-57972 | MEDIUM | 6.5 | 2.2% | Mar 6, 2025 | The pairing API request handler in Microsoft HoloLens 1 (Windows Holographic) through 10.0.17763.3046 and HoloLens 2 (Wi... |
| CVE-2024-58086 | MEDIUM | 5.5 | 0.2% | Mar 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Stop active perfmon if it is being destroy... |
| CVE-2024-58085 | MEDIUM | 5.5 | 0.2% | Mar 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: tomoyo: don't emit warning in tomoyo_write_control(... |
| CVE-2024-58084 | MEDIUM | 5.5 | 0.2% | Mar 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: Fix missing read barrier in qc... |
| CVE-2024-58082 | MEDIUM | 5.5 | 0.2% | Mar 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: media: nuvoton: Fix an error check in npcm_video_ec... |
| CVE-2024-58081 | MEDIUM | 5.5 | 0.2% | Mar 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: clk: mmp2: call pm_genpd_init() only after genpd.na... |
| CVE-2024-58080 | MEDIUM | 5.5 | 0.2% | Mar 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: clk: qcom: dispcc-sm6350: Add missing parent_map fo... |
| CVE-2024-58079 | MEDIUM | 5.5 | 0.2% | Mar 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix crash during unbind if gpio un... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now