2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-26148 | MEDIUM | 6.1 | 0.5% | Feb 21, 2024 | Querybook is a user interface for querying big data. Prior to version 3.31.1, there is a vulnerability in Querybook's ri... |
| CVE-2024-26311 | MEDIUM | 5.7 | 0.5% | Feb 21, 2024 | Archer Platform 6.x before 6.14 P2 HF1 (6.14.0.2.1) contains a reflected XSS vulnerability. A remote authenticated malic... |
| CVE-2024-26310 | MEDIUM | 4.3 | 0.4% | Feb 21, 2024 | Archer Platform 6.8 before 6.14 P2 (6.14.0.2) contains an improper access control vulnerability. A remote authenticated ... |
| CVE-2024-25381 | MEDIUM | 6.1 | 0.4% | Feb 21, 2024 | There is a Stored XSS Vulnerability in Emlog Pro 2.2.8 Article Publishing, due to non-filtering of quoted content. |
| CVE-2024-1707 | MEDIUM | 6.1 | 0.7% | Feb 21, 2024 | A vulnerability, which was classified as problematic, was found in GARO WALLBOX GLB+ T2EV7 0.5. This affects an unknown ... |
| CVE-2024-26145 | MEDIUM | 4.3 | 0.4% | Feb 21, 2024 | Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on Discourse. Uninvited us... |
| CVE-2024-25898 | MEDIUM | 6.1 | 0.4% | Feb 21, 2024 | A XSS vulnerability was found in the ChurchCRM v.5.5.0 functionality, edit your event, where malicious JS or HTML code c... |
| CVE-2024-25896 | MEDIUM | 5.3 | 0.4% | Feb 21, 2024 | ChurchCRM 5.5.0 EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EID POST parameter. |
| CVE-2024-25895 | MEDIUM | 6.1 | 0.4% | Feb 21, 2024 | A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 5.5.0 allows remote attackers to inject arbitrary web ... |
| CVE-2024-1706 | MEDIUM | 5.4 | 0.4% | Feb 21, 2024 | A vulnerability was determined in ZKTeco ZKBio Access IVS up to 3.3.2. This impacts an unknown function of the component... |
| CVE-2024-26138 | MEDIUM | 5.3 | 0.5% | Feb 21, 2024 | The XWiki licensor application, which manages and enforce application licenses for paid extensions, includes the documen... |
| CVE-2024-26133 | MEDIUM | 4.9 | 0.6% | Feb 21, 2024 | EventStoreDB (ESDB) is an operational database built to store events. A vulnerability has been identified in the project... |
| CVE-2024-25288 | MEDIUM | 4.9 | 0.5% | Feb 21, 2024 | SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php. |
| CVE-2024-1703 | MEDIUM | 5.3 | 0.7% | Feb 21, 2024 | A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been classified as problematic. This affects the function... |
| CVE-2024-22220 | MEDIUM | 6.3 | 0.4% | Feb 21, 2024 | An issue was discovered in Terminalfour 7.4 through 7.4.0004 QP3 and 8 through 8.3.19, and Formbank through 2.1.10-FINAL... |
| CVE-2024-1700 | MEDIUM | 5.4 | 0.6% | Feb 21, 2024 | A vulnerability, which was classified as problematic, was found in keerti1924 PHP-MYSQL-User-Login-System 1.0. Affected ... |
| CVE-2024-1474 | MEDIUM | 6.1 | 0.4% | Feb 21, 2024 | In WS_FTP Server versions before 8.8.5, reflected cross-site scripting issues have been identified on various user suppl... |
| CVE-2024-26585 | MEDIUM | 4.7 | 0.2% | Feb 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: tls: fix race between tx work scheduling and socket... |
| CVE-2024-26584 | MEDIUM | 5.5 | 0.2% | Feb 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: tls: handle backlogging of crypto requests Si... |
| CVE-2024-26583 | MEDIUM | 4.7 | 0.2% | Feb 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: tls: fix race between async notify and socket close... |
| CVE-2024-24837 | MEDIUM | 4.3 | 0.3% | Feb 21, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce, Frédéric GILLES FG Drup... |
| CVE-2024-25905 | MEDIUM | 5.4 | 0.2% | Feb 21, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form.This issue affects Multi Step Form: from... |
| CVE-2024-1081 | MEDIUM | 5.4 | 0.3% | Feb 21, 2024 | The 3D FlipBook – PDF Flipbook WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2024-0593 | MEDIUM | 5.3 | 0.9% | Feb 21, 2024 | The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorizatio... |
| CVE-2024-22235 | MEDIUM | 6.7 | 0.2% | Feb 21, 2024 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now