2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-26148MEDIUM6.1Querybook is a user interface for querying big data. Prior to version 3.31.1, there is a vulnerability in Querybook's ri...
CVE-2024-26311MEDIUM5.7Archer Platform 6.x before 6.14 P2 HF1 (6.14.0.2.1) contains a reflected XSS vulnerability. A remote authenticated malic...
CVE-2024-26310MEDIUM4.3Archer Platform 6.8 before 6.14 P2 (6.14.0.2) contains an improper access control vulnerability. A remote authenticated ...
CVE-2024-25381MEDIUM6.1There is a Stored XSS Vulnerability in Emlog Pro 2.2.8 Article Publishing, due to non-filtering of quoted content.
CVE-2024-1707MEDIUM6.1A vulnerability, which was classified as problematic, was found in GARO WALLBOX GLB+ T2EV7 0.5. This affects an unknown ...
CVE-2024-26145MEDIUM4.3Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on Discourse. Uninvited us...
CVE-2024-25898MEDIUM6.1A XSS vulnerability was found in the ChurchCRM v.5.5.0 functionality, edit your event, where malicious JS or HTML code c...
CVE-2024-25896MEDIUM5.3ChurchCRM 5.5.0 EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EID POST parameter.
CVE-2024-25895MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 5.5.0 allows remote attackers to inject arbitrary web ...
CVE-2024-1706MEDIUM5.4A vulnerability was determined in ZKTeco ZKBio Access IVS up to 3.3.2. This impacts an unknown function of the component...
CVE-2024-26138MEDIUM5.3The XWiki licensor application, which manages and enforce application licenses for paid extensions, includes the documen...
CVE-2024-26133MEDIUM4.9EventStoreDB (ESDB) is an operational database built to store events. A vulnerability has been identified in the project...
CVE-2024-25288MEDIUM4.9SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php.
CVE-2024-1703MEDIUM5.3A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been classified as problematic. This affects the function...
CVE-2024-22220MEDIUM6.3An issue was discovered in Terminalfour 7.4 through 7.4.0004 QP3 and 8 through 8.3.19, and Formbank through 2.1.10-FINAL...
CVE-2024-1700MEDIUM5.4A vulnerability, which was classified as problematic, was found in keerti1924 PHP-MYSQL-User-Login-System 1.0. Affected ...
CVE-2024-1474MEDIUM6.1In WS_FTP Server versions before 8.8.5, reflected cross-site scripting issues have been identified on various user suppl...
CVE-2024-26585MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: tls: fix race between tx work scheduling and socket...
CVE-2024-26584MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: tls: handle backlogging of crypto requests Si...
CVE-2024-26583MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: tls: fix race between async notify and socket close...
CVE-2024-24837MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce, Frédéric GILLES FG Drup...
CVE-2024-25905MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form.This issue affects Multi Step Form: from...
CVE-2024-1081MEDIUM5.4The 3D FlipBook – PDF Flipbook WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-0593MEDIUM5.3The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorizatio...
CVE-2024-22235MEDIUM6.7VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now