2024 CVE Vulnerabilities

39,239 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-38640MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If exploited, the vulnerability...
CVE-2024-32771LOW2.4An improper restriction of excessive authentication attempts vulnerability has been reported to affect several QNAP oper...
CVE-2024-32763HIGH8.8A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver...
CVE-2024-32762MEDIUM6.1A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability cou...
CVE-2024-27126MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability ...
CVE-2024-27125MEDIUM4.8A cross-site scripting (XSS) vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could a...
CVE-2024-27122MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability ...
CVE-2024-21906MEDIUM4.7An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...
CVE-2024-21904MEDIUM6.5A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vul...
CVE-2024-21903MEDIUM4.7An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...
CVE-2024-21898HIGH8.8An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...
CVE-2024-21897MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploi...
CVE-2024-8517CRITICAL9.8SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacke...
CVE-2024-8509HIGH7.5A vulnerability was found in Forklift Controller.  There is no verification against the authorization header except to e...
CVE-2024-45758CRITICAL9.1H2O.ai H2O through 3.46.0.4 allows attackers to arbitrarily set the JDBC URL, leading to deserialization attacks, file r...
CVE-2024-45294HIGH8.6The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator)...
CVE-2024-44408HIGH7.5D-Link DIR-823G v1.0.2B05_20181207 is vulnerable to Information Disclosure. The device allows unauthorized configuration...
CVE-2024-44402CRITICAL9.8D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.
CVE-2024-44401CRITICAL9.8D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file
CVE-2024-25584MEDIUM5.3Dovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This...
CVE-2024-8428HIGH8.8The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Di...
CVE-2024-7622MEDIUM4.3The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing cap...
CVE-2024-7611MEDIUM5.4The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scrip...
CVE-2024-7599MEDIUM5.4The Advanced Sermons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sermon_video_embed’ para...
CVE-2024-7493CRITICAL9.8The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2....

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now