CVE Feed

    Dashboard / CVE

    8.7
    High

    CVE-2023-51364

    Last Modified: 10 Dec 2025

    A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later

    Published: 26 Apr 2024
    8.7
    High

    CVE-2023-51365

    Last Modified: 10 Dec 2025

    A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later

    Published: 26 Apr 2024
    6.5
    Medium

    CVE-2024-21905

    Last Modified: 5 Dec 2025

    An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTScloud c5.1.5.2651 and later

    Published: 26 Apr 2024
    7.5
    High

    CVE-2024-27124

    Last Modified: 5 Dec 2025

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later

    Published: 26 Apr 2024
    9.9
    Critical

    CVE-2024-32764

    Last Modified: 10 Dec 2025

    A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited, the vulnerability could allow users with the privilege level of some functionality via a network. We have already fixed the vulnerability in the following version: myQNAPcloud Link 2.4.51 and later

    Published: 26 Apr 2024
    10
    Critical

    CVE-2024-32766

    Last Modified: 10 Dec 2025

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later

    Published: 26 Apr 2024
    5.4
    Medium

    CVE-2022-40975

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Aazztech Post Slider.This issue affects Post Slider: from n/a through 1.6.7.

    Published: 26 Apr 2024
    3.8
    Low

    CVE-2024-3076

    Last Modified: 10 Jun 2025

    The MM-email2image WordPress plugin through 0.2.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

    Published: 26 Apr 2024
    5.9
    Medium

    CVE-2024-4234

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sayful Islam Filterable Portfolio allows Stored XSS.This issue affects Filterable Portfolio: from n/a through 1.6.4.

    Published: 26 Apr 2024
    4.3
    Medium

    CVE-2024-33688

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes Teluro.This issue affects Teluro: from n/a through 1.0.31.

    Published: 26 Apr 2024
    4.3
    Medium

    CVE-2024-33689

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Tony Zeoli Radio Station radio-station.This issue affects Radio Station: from n/a through <= 2.5.7.

    Published: 26 Apr 2024
    4.3
    Medium

    CVE-2024-33690

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Jegstudio Financio.This issue affects Financio: from n/a through 1.1.3.

    Published: 26 Apr 2024
    4.3
    Medium

    CVE-2024-33691

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in OptinMonster Popup Builder Team OptinMonster.This issue affects OptinMonster: from n/a through 2.15.3.

    Published: 26 Apr 2024
    5.9
    Medium

    CVE-2024-33692

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Satrya Smart Recent Posts Widget allows Stored XSS.This issue affects Smart Recent Posts Widget: from n/a through 1.0.3.

    Published: 26 Apr 2024
    5.9
    Medium

    CVE-2024-33693

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Meks Meks Smart Social Widget allows Stored XSS.This issue affects Meks Smart Social Widget: from n/a through 1.6.4.

    Published: 26 Apr 2024
    5.9
    Medium

    CVE-2024-33694

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Meks Meks ThemeForest Smart Widget allows Stored XSS.This issue affects Meks ThemeForest Smart Widget: from n/a through 1.5.

    Published: 26 Apr 2024
    5.9
    Medium

    CVE-2024-33695

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeNcode Fan Page Widget by ThemeNcode allows Stored XSS.This issue affects Fan Page Widget by ThemeNcode: from n/a through 2.0.

    Published: 26 Apr 2024
    5.9
    Medium

    CVE-2024-33696

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Broadstreet XPRESS WordPress Ad Widget allows Stored XSS.This issue affects WordPress Ad Widget: from n/a through 2.20.0.

    Published: 26 Apr 2024
    5.9
    Medium

    CVE-2024-33697

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rimes Gold CF7 File Download – File Download for CF7 allows Stored XSS.This issue affects CF7 File Download – File Download for CF7: from n/a through 2.0.

    Published: 26 Apr 2024
    4.3
    Medium

    CVE-2024-32822

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in impleCode Reviews Plus.This issue affects Reviews Plus: from n/a through 1.3.4.

    Published: 26 Apr 2024
    5.3
    Medium

    CVE-2024-32826

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Vektor,Inc. VK Block Patterns.This issue affects VK Block Patterns: from n/a through 1.31.0.

    Published: 26 Apr 2024
    4.3
    Medium

    CVE-2024-32828

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Octolize Flexible Shipping.This issue affects Flexible Shipping: from n/a through 4.24.15.

    Published: 26 Apr 2024
    4.3
    Medium

    CVE-2024-32829

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Supsystic Data Tables Generator by Supsystic.This issue affects Data Tables Generator by Supsystic: from n/a through 1.10.31.

    Published: 26 Apr 2024
    4.7
    Medium

    CVE-2024-32957

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.38.

    Published: 26 Apr 2024
    4.3
    Medium

    CVE-2024-33677

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Renzo Johnson Contact Form 7 Extension For Mailchimp.This issue affects Contact Form 7 Extension For Mailchimp: from n/a through 0.5.70.

    Published: 26 Apr 2024
    4.3
    Medium

    CVE-2024-33678

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in eranfl ClickCease Click Fraud Protection clickcease-click-fraud-protection.This issue affects ClickCease Click Fraud Protection: from n/a through <= 3.2.7.

    Published: 26 Apr 2024
    4.3
    Medium

    CVE-2024-33679

    Last Modified: 15 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in FameThemes FameTheme Demo Importer.This issue affects FameTheme Demo Importer: from n/a through 1.1.5.

    Published: 26 Apr 2024
    5.4
    Medium

    CVE-2024-33680

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in MainWP MainWP Child Reports.This issue affects MainWP Child Reports: from n/a through 2.1.1.

    Published: 26 Apr 2024
    5.4
    Medium

    CVE-2024-33682

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Cookie Information A/S WP GDPR Compliance.This issue affects WP GDPR Compliance: from n/a through 2.0.23.

    Published: 26 Apr 2024
    4.3
    Medium

    CVE-2024-33683

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WP Republic Hide Dashboard Notifications.This issue affects Hide Dashboard Notifications: from n/a through 1.2.3.

    Published: 26 Apr 2024
    5.3
    Medium

    CVE-2024-3682

    Last Modified: 15 Apr 2026

    The WP STAGING and WP STAGING Pro plugins for WordPress are vulnerable to Sensitive Information Exposure in versions up to, and including, 3.4.3, and versions up to, and including, 5.4.3, respectively, via the ajaxSendReport function. This makes it possible for unauthenticated attackers to extract sensitive data from a log file, including system information and (in the Pro version) license keys. Successful exploitation requires an administrator to have used the 'Contact Us' functionality along with the "Enable this option to automatically submit the log files." option.

    Published: 26 Apr 2024
    7.2
    High

    CVE-2024-1789

    Last Modified: 15 Apr 2026

    The WP SMTP plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in versions 1.2 to 1.2.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 26 Apr 2024
    9.8
    Critical

    CVE-2024-3962

    Last Modified: 8 Apr 2026

    The Product Addons & Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ppom_upload_file function in all versions up to, and including, 32.0.18. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Successful exploitation requires the PPOM Pro plugin to be installed along with a WooCommerce product that contains a file upload field to retrieve the correct nonce.

    Published: 26 Apr 2024
    5.3
    Medium

    CVE-2024-2920

    Last Modified: 15 Apr 2026

    The WP-Members Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.4.9.3 due to the plugin uploading user supplied files to a publicly accessible directory in wp-content without any restrictions. This makes it possible for unauthenticated attackers to view files uploaded by other users which may contain sensitive information.

    Published: 26 Apr 2024
    5.3
    Medium

    CVE-2024-3678

    Last Modified: 8 Apr 2026

    The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.4.2. This makes it possible for unauthenticated attackers to view limited information from password protected posts.

    Published: 26 Apr 2024
    6.4
    Medium

    CVE-2024-3890

    Last Modified: 8 Apr 2026

    The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Calendly widget in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 26 Apr 2024
    8.9
    High

    CVE-2023-6116

    Last Modified: 15 Apr 2026

    Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the camera. An attacker could inject malicious into http request packets to execute arbitrary code. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.

    Published: 26 Apr 2024
    5.9
    Medium

    CVE-2024-33642

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EkoJR Advanced Post List allows Stored XSS.This issue affects Advanced Post List: from n/a through 0.5.6.1.

    Published: 26 Apr 2024
    5.9
    Medium

    CVE-2024-33639

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AccessAlly PopupAlly allows Stored XSS.This issue affects PopupAlly: from n/a through 2.1.1.

    Published: 26 Apr 2024
    5.9
    Medium

    CVE-2024-33598

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Twinpictures Annual Archive allows Stored XSS.This issue affects Annual Archive: from n/a through 1.6.0.

    Published: 26 Apr 2024
    7.4
    High

    CVE-2023-6096

    Last Modified: 15 Apr 2026

    Vladimir Kononovich, a Security Researcher has found a flaw that using a inappropriate encryption logic on the DVR. firmware encryption is broken and allows to decrypt. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.

    Published: 26 Apr 2024
    5.4
    Medium

    CVE-2024-33638

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Brijesh Kothari Smart Maintenance Mode.This issue affects Smart Maintenance Mode: from n/a through 1.4.4.

    Published: 26 Apr 2024
    4.3
    Medium

    CVE-2024-33650

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Cryout Creations Serious Slider.This issue affects Serious Slider: from n/a through 1.2.4.

    Published: 26 Apr 2024
    5.4
    Medium

    CVE-2024-33651

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Matthew Fries MF Gig Calendar.This issue affects MF Gig Calendar : from n/a through 1.2.1.

    Published: 26 Apr 2024
    8.9
    High

    CVE-2023-6095

    Last Modified: 15 Apr 2026

    Vladimir Kononovich, a Security Researcher has found a flaw that allows for a remote code execution on the DVR. An attacker could inject malicious HTTP headers into request packets to execute arbitrary code. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.

    Published: 26 Apr 2024
    7.5
    High

    CVE-2024-4056

    Last Modified: 23 Feb 2026

    Denial of service condition in M-Files Server in versions before 24.4.13592.4 and after 23.11 (excluding 24.2 LTS) allows unauthenticated user to consume computing resources.

    Published: 26 Apr 2024
    9.8
    Critical

    CVE-2024-0740

    Last Modified: 3 Feb 2025

    Eclipse Target Management: Terminal and Remote System Explorer (RSE) version <= 4.5.400 has a remote code execution vulnerability that does not require authentication. The fixed version is included in Eclipse IDE 2024-03

    Published: 26 Apr 2024
    6.3
    Medium

    CVE-2024-3188

    Last Modified: 14 May 2025

    The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

    Published: 26 Apr 2024
    8.1
    High

    CVE-2024-3075

    Last Modified: 10 Jun 2025

    The MM-email2image WordPress plugin through 0.2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

    Published: 26 Apr 2024
    4.5
    Medium

    CVE-2024-3060

    Last Modified: 7 May 2025

    The ENL Newsletter WordPress plugin through 1.0.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admin+ to perform SQL injection attacks

    Published: 26 Apr 2024