2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53695 | CRITICAL | 9.1 | 0.5% | Mar 7, 2025 | A buffer overflow vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability co... |
| CVE-2024-53694 | HIGH | 8.6 | 0.1% | Mar 7, 2025 | A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. ... |
| CVE-2024-53693 | HIGH | 7.1 | 0.4% | Mar 7, 2025 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP o... |
| CVE-2024-53692 | MEDIUM | 5.1 | 0.8% | Mar 7, 2025 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the ... |
| CVE-2024-50405 | MEDIUM | 5.5 | 0.4% | Mar 7, 2025 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP o... |
| CVE-2024-50394 | HIGH | 8.8 | 0.3% | Mar 7, 2025 | An improper certificate validation vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability c... |
| CVE-2024-50390 | CRITICAL | 9.8 | 1.1% | Mar 7, 2025 | A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote ... |
| CVE-2024-48864 | CRITICAL | 9.1 | 0.5% | Mar 7, 2025 | A files or directories accessible to external parties vulnerability has been reported to affect File Station 5. If explo... |
| CVE-2024-38638 | HIGH | 7.2 | 0.5% | Mar 7, 2025 | An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, t... |
| CVE-2024-13086 | HIGH | 7.5 | 0.4% | Mar 7, 2025 | An exposure of sensitive information vulnerability has been reported to affect product. If exploited, the vulnerability ... |
| CVE-2024-12975 | LOW | 1 | 0.2% | Mar 7, 2025 | A buffer overread can occur in the CPC application when operating in full duplex SPI upon receiving an invalid packet ov... |
| CVE-2024-12634 | MEDIUM | 6.1 | 0.2% | Mar 7, 2025 | The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress i... |
| CVE-2024-9458 | MEDIUM | 4.8 | 0.8% | Mar 7, 2025 | The Reservit Hotel WordPress plugin before 3.0 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2024-13857 | MEDIUM | 5.5 | 0.3% | Mar 7, 2025 | The WPGet API – Connect to any external REST API plugin for WordPress is vulnerable to Server-Side Request Forgery in al... |
| CVE-2024-13805 | MEDIUM | 5.4 | 0.2% | Mar 7, 2025 | The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerab... |
| CVE-2024-13668 | HIGH | 7.1 | 0.3% | Mar 7, 2025 | The WordPress Activity O Meter WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting i... |
| CVE-2024-13635 | MEDIUM | 4.3 | 0.3% | Mar 7, 2025 | The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,... |
| CVE-2024-13552 | MEDIUM | 4.3 | 0.3% | Mar 7, 2025 | The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Objec... |
| CVE-2024-9658 | HIGH | 8.8 | 0.3% | Mar 7, 2025 | The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeov... |
| CVE-2024-13904 | CRITICAL | 9.1 | 0.4% | Mar 7, 2025 | The Platform.ly for WooCommerce plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions ... |
| CVE-2024-13781 | MEDIUM | 6.5 | 0.3% | Mar 7, 2025 | The Hero Maps Premium plugin for WordPress is vulnerable to SQL Injection via several AJAX actions in all versions up to... |
| CVE-2024-13431 | MEDIUM | 6.1 | 0.3% | Mar 7, 2025 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Ref... |
| CVE-2024-12876 | CRITICAL | 9.8 | 0.4% | Mar 7, 2025 | The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeo... |
| CVE-2024-12611 | MEDIUM | 5.3 | 0.3% | Mar 7, 2025 | The School Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ... |
| CVE-2024-12610 | MEDIUM | 5.3 | 0.3% | Mar 7, 2025 | The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a miss... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now