2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25124 | CRITICAL | 9.8 | 0.7% | Feb 21, 2024 | Fiber is a web framework written in go. Prior to version 2.52.1, the CORS middleware allows for insecure configurations ... |
| CVE-2024-23654 | HIGH | 7.2 | 0.4% | Feb 21, 2024 | discourse-ai is the AI plugin for the open-source discussion platform Discourse. Prior to commit 94ba0dadc2cf38e8f81c393... |
| CVE-2024-26311 | MEDIUM | 5.7 | 0.5% | Feb 21, 2024 | Archer Platform 6.x before 6.14 P2 HF1 (6.14.0.2.1) contains a reflected XSS vulnerability. A remote authenticated malic... |
| CVE-2024-26310 | MEDIUM | 4.3 | 0.4% | Feb 21, 2024 | Archer Platform 6.8 before 6.14 P2 (6.14.0.2) contains an improper access control vulnerability. A remote authenticated ... |
| CVE-2024-25461 | HIGH | 7.5 | 1.0% | Feb 21, 2024 | Directory Traversal vulnerability in Terrasoft, Creatio Terrasoft CRM v.7.18.4.1532 allows a remote attacker to obtain s... |
| CVE-2024-25249 | CRITICAL | 9.8 | 1.5% | Feb 21, 2024 | An issue in He3 App for macOS version 2.0.17, allows remote attackers to execute arbitrary code via the RunAsNode and en... |
| CVE-2024-25381 | MEDIUM | 6.1 | 0.4% | Feb 21, 2024 | There is a Stored XSS Vulnerability in Emlog Pro 2.2.8 Article Publishing, due to non-filtering of quoted content. |
| CVE-2024-24479 | HIGH | 7.5 | 1.3% | Feb 21, 2024 | A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.... |
| CVE-2024-24476 | HIGH | 7.5 | 1.3% | Feb 21, 2024 | A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resol... |
| CVE-2024-22473 | HIGH | 7.5 | 0.4% | Feb 21, 2024 | TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. T... |
| CVE-2024-1707 | MEDIUM | 6.1 | 0.7% | Feb 21, 2024 | A vulnerability, which was classified as problematic, was found in GARO WALLBOX GLB+ T2EV7 0.5. This affects an unknown ... |
| CVE-2024-26145 | MEDIUM | 4.3 | 0.4% | Feb 21, 2024 | Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on Discourse. Uninvited us... |
| CVE-2024-25898 | MEDIUM | 6.1 | 0.4% | Feb 21, 2024 | A XSS vulnerability was found in the ChurchCRM v.5.5.0 functionality, edit your event, where malicious JS or HTML code c... |
| CVE-2024-25897 | CRITICAL | 9.8 | 1.6% | Feb 21, 2024 | ChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter. |
| CVE-2024-25896 | MEDIUM | 5.3 | 0.4% | Feb 21, 2024 | ChurchCRM 5.5.0 EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EID POST parameter. |
| CVE-2024-25895 | MEDIUM | 6.1 | 0.4% | Feb 21, 2024 | A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 5.5.0 allows remote attackers to inject arbitrary web ... |
| CVE-2024-25894 | CRITICAL | 9.8 | 0.7% | Feb 21, 2024 | ChurchCRM 5.5.0 /EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EventCount POST parameter. |
| CVE-2024-25893 | CRITICAL | 9.1 | 0.4% | Feb 21, 2024 | ChurchCRM 5.5.0 FRCertificates.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET param... |
| CVE-2024-25892 | HIGH | 8.1 | 0.6% | Feb 21, 2024 | ChurchCRM 5.5.0 ConfirmReport.php is vulnerable to Blind SQL Injection (Time-based) via the familyId GET parameter. |
| CVE-2024-25891 | HIGH | 7.5 | 0.6% | Feb 21, 2024 | ChurchCRM 5.5.0 FRBidSheets.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET paramete... |
| CVE-2024-1706 | MEDIUM | 5.4 | 0.4% | Feb 21, 2024 | A vulnerability was determined in ZKTeco ZKBio Access IVS up to 3.3.2. This impacts an unknown function of the component... |
| CVE-2024-1705 | HIGH | 8.1 | 0.6% | Feb 21, 2024 | A vulnerability was found in Shopwind up to 4.6. It has been rated as critical. This issue affects the function actionCr... |
| CVE-2024-1704 | HIGH | 8.1 | 0.6% | Feb 21, 2024 | A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been declared as critical. This vulnerability affects the... |
| CVE-2024-1212 | CRITICAL | 9.8 | 95.4% | Feb 21, 2024 | Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary s... |
| CVE-2024-26138 | MEDIUM | 5.3 | 0.5% | Feb 21, 2024 | The XWiki licensor application, which manages and enforce application licenses for paid extensions, includes the documen... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now