2

CVSS4.0

CVE-2024-14026 - QTS, QuTS hero

A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the…

📅 Published: March 11, 2026, 8:02 a.m. 🔄 Last Modified: March 11, 2026, 8:02 a.m.

0.1

CVSS4.0

CVE-2024-14025 - Video Station

An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the follow…

📅 Published: March 11, 2026, 8:02 a.m. 🔄 Last Modified: March 11, 2026, 8:02 a.m.

0.1

CVSS4.0

CVE-2024-14024 - Video Station

An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerabi…

📅 Published: March 11, 2026, 8:02 a.m. 🔄 Last Modified: March 11, 2026, 8:02 a.m.

5.4

CVSS3.1

CVE-2026-2917 - Happy Addons for Elementor <= 3.21.0 - Insecure Direct Object Reference to Authenticated (Contribut…

The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_duplicate_thing` admin action handler. This is due to the `can_clone()` method only checking `current_user_can('edit_posts')` (a general cap…

📅 Published: March 11, 2026, 7:36 a.m. 🔄 Last Modified: March 11, 2026, 7:36 a.m.

4.3

CVSS3.1

CVE-2026-3903 - Modular Connector <= 2.5.1 - Cross-Site Request Forgery via postConfirmOauth

The Modular DS: Monitor, update, and backup multiple websites plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.1. This is due to missing nonce validation on the postConfirmOauth() function. This makes it possible for unauthenticated attacker…

📅 Published: March 11, 2026, 7:36 a.m. 🔄 Last Modified: March 11, 2026, 7:36 a.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri Çilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genç

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali İltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here