2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-25124CRITICAL9.8Fiber is a web framework written in go. Prior to version 2.52.1, the CORS middleware allows for insecure configurations ...
CVE-2024-23654HIGH7.2discourse-ai is the AI plugin for the open-source discussion platform Discourse. Prior to commit 94ba0dadc2cf38e8f81c393...
CVE-2024-26311MEDIUM5.7Archer Platform 6.x before 6.14 P2 HF1 (6.14.0.2.1) contains a reflected XSS vulnerability. A remote authenticated malic...
CVE-2024-26310MEDIUM4.3Archer Platform 6.8 before 6.14 P2 (6.14.0.2) contains an improper access control vulnerability. A remote authenticated ...
CVE-2024-25461HIGH7.5Directory Traversal vulnerability in Terrasoft, Creatio Terrasoft CRM v.7.18.4.1532 allows a remote attacker to obtain s...
CVE-2024-25249CRITICAL9.8An issue in He3 App for macOS version 2.0.17, allows remote attackers to execute arbitrary code via the RunAsNode and en...
CVE-2024-25381MEDIUM6.1There is a Stored XSS Vulnerability in Emlog Pro 2.2.8 Article Publishing, due to non-filtering of quoted content.
CVE-2024-24479HIGH7.5A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str....
CVE-2024-24476HIGH7.5A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resol...
CVE-2024-22473HIGH7.5TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. T...
CVE-2024-1707MEDIUM6.1A vulnerability, which was classified as problematic, was found in GARO WALLBOX GLB+ T2EV7 0.5. This affects an unknown ...
CVE-2024-26145MEDIUM4.3Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on Discourse. Uninvited us...
CVE-2024-25898MEDIUM6.1A XSS vulnerability was found in the ChurchCRM v.5.5.0 functionality, edit your event, where malicious JS or HTML code c...
CVE-2024-25897CRITICAL9.8ChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.
CVE-2024-25896MEDIUM5.3ChurchCRM 5.5.0 EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EID POST parameter.
CVE-2024-25895MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 5.5.0 allows remote attackers to inject arbitrary web ...
CVE-2024-25894CRITICAL9.8ChurchCRM 5.5.0 /EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EventCount POST parameter.
CVE-2024-25893CRITICAL9.1ChurchCRM 5.5.0 FRCertificates.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET param...
CVE-2024-25892HIGH8.1ChurchCRM 5.5.0 ConfirmReport.php is vulnerable to Blind SQL Injection (Time-based) via the familyId GET parameter.
CVE-2024-25891HIGH7.5ChurchCRM 5.5.0 FRBidSheets.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET paramete...
CVE-2024-1706MEDIUM5.4A vulnerability was determined in ZKTeco ZKBio Access IVS up to 3.3.2. This impacts an unknown function of the component...
CVE-2024-1705HIGH8.1A vulnerability was found in Shopwind up to 4.6. It has been rated as critical. This issue affects the function actionCr...
CVE-2024-1704HIGH8.1A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been declared as critical. This vulnerability affects the...
CVE-2024-1212CRITICAL9.8Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary s...
CVE-2024-26138MEDIUM5.3The XWiki licensor application, which manages and enforce application licenses for paid extensions, includes the documen...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now