2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-53695CRITICAL9.1A buffer overflow vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability co...
CVE-2024-53694HIGH8.6A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. ...
CVE-2024-53693HIGH7.1An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP o...
CVE-2024-53692MEDIUM5.1A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the ...
CVE-2024-50405MEDIUM5.5An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP o...
CVE-2024-50394HIGH8.8An improper certificate validation vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability c...
CVE-2024-50390CRITICAL9.8A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote ...
CVE-2024-48864CRITICAL9.1A files or directories accessible to external parties vulnerability has been reported to affect File Station 5. If explo...
CVE-2024-38638HIGH7.2An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, t...
CVE-2024-13086HIGH7.5An exposure of sensitive information vulnerability has been reported to affect product. If exploited, the vulnerability ...
CVE-2024-12975LOW1A buffer overread can occur in the CPC application when operating in full duplex SPI upon receiving an invalid packet ov...
CVE-2024-12634MEDIUM6.1The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress i...
CVE-2024-9458MEDIUM4.8The Reservit Hotel WordPress plugin before 3.0 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-13857MEDIUM5.5The WPGet API – Connect to any external REST API plugin for WordPress is vulnerable to Server-Side Request Forgery in al...
CVE-2024-13805MEDIUM5.4The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerab...
CVE-2024-13668HIGH7.1The WordPress Activity O Meter WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting i...
CVE-2024-13635MEDIUM4.3The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
CVE-2024-13552MEDIUM4.3The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Objec...
CVE-2024-9658HIGH8.8The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeov...
CVE-2024-13904CRITICAL9.1The Platform.ly for WooCommerce plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions ...
CVE-2024-13781MEDIUM6.5The Hero Maps Premium plugin for WordPress is vulnerable to SQL Injection via several AJAX actions in all versions up to...
CVE-2024-13431MEDIUM6.1The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Ref...
CVE-2024-12876CRITICAL9.8The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeo...
CVE-2024-12611MEDIUM5.3The School Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ...
CVE-2024-12610MEDIUM5.3The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a miss...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now