Horizoncloud's vulnerability footprint centers on CaterEase, a restaurant and hospitality management platform that occupies a prominent but specialized niche in point-of-sale and operational software. Vulnerabilities affecting this vendor skew strongly toward critical severity and recur through high-impact weakness classes including OS command injection, SQL injection, authentication bypass, and cleartext transmission of sensitive data—flaws that reflect the application's role handling payment systems and business-critical operational data. Defenders deploying this platform should treat patching as urgent and verify segmentation controls around payment and customer-data flows; live severity and exploitation details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Horizoncloud over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-38883CRITICAL An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Drop Encryption Level attack | Aug 2, 2024 | 9.1 | 30 | NO | NO |
CVE-2024-38887CRITICAL An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating syst | Aug 2, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-38889CRITICAL An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper | Aug 2, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-38882CRITICAL An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform command line execution through | Aug 2, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-38886CRITICAL An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Traffic Injection attack due | Aug 2, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-38891HIGH An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic att | Aug 2, 2024 | 7.5 | 24 | NO | NO |
CVE-2024-38884HIGH An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform an Authentication Bypass attack | Aug 2, 2024 | 7.8 | 24 | NO | NO |
CVE-2024-38881HIGH An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Rainbow Table Password crack | Aug 2, 2024 | 7.5 | 24 | NO | NO |
CVE-2024-38885HIGH An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform unauthorized access using know | Aug 2, 2024 | 7.5 | 23 | NO | NO |
CVE-2024-38888MEDIUM An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform a Password Brute Forcing attack | Aug 2, 2024 | 6.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Horizoncloud.
Media articles that mention a CVE ID that affects a product developed by Horizoncloud — matched by CVE ID, not by vendor name.