Vulnerabilities (CVE)

Total 398401 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-25895 1 Churchcrm 1 Churchcrm 2026-06-17 N/A 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 5.5.0 allows remote attackers to inject arbitrary web script or HTML via the type parameter of /EventAttendance.php
CVE-2024-25894 1 Churchcrm 1 Churchcrm 2026-06-17 N/A 9.8 CRITICAL
ChurchCRM 5.5.0 /EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EventCount POST parameter.
CVE-2024-25893 1 Churchcrm 1 Churchcrm 2026-06-17 N/A 9.1 CRITICAL
ChurchCRM 5.5.0 FRCertificates.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.
CVE-2024-25892 1 Churchcrm 1 Churchcrm 2026-06-17 N/A 8.1 HIGH
ChurchCRM 5.5.0 ConfirmReport.php is vulnerable to Blind SQL Injection (Time-based) via the familyId GET parameter.
CVE-2024-25891 1 Churchcrm 1 Churchcrm 2026-06-17 N/A 7.5 HIGH
ChurchCRM 5.5.0 FRBidSheets.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.
CVE-2024-25883 2026-06-17 N/A 5.3 MEDIUM
The mstatus register in RSD commit 3d13a updates incorrectly, leading to processing errors.
CVE-2024-25876 1 Enhavo 1 Enhavo 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the Header module of Enhavo CMS v0.13.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title text field.
CVE-2024-25875 1 Enhavo 1 Enhavo 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the Header module of Enhavo CMS v0.13.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Undertitle text field.
CVE-2024-25874 1 Enhavo 1 Enhavo 2026-06-17 N/A 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in the New/Edit Article module of Enhavo CMS v0.13.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Create Tag text field.
CVE-2024-25873 1 Enhavo 1 Enhavo 2026-06-17 N/A 5.4 MEDIUM
Enhavo v0.13.1 was discovered to contain an HTML injection vulnerability in the Author text field under the Blockquote module. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
CVE-2024-25869 1 Codeastro 1 Membership Management System 2026-06-17 N/A 8.8 HIGH
An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via upload of a crafted php file in the settings.php component.
CVE-2024-25868 1 Codeastro 1 Membership Management System 2026-06-17 N/A 6.1 MEDIUM
A Cross Site Scripting (XSS) vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via the membershipType parameter in the add_type.php component.
CVE-2024-25867 1 Codeastro 1 Membership Management System 2026-06-17 N/A 9.1 CRITICAL
A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the membershipType and membershipAmount parameters in the add_type.php component.
CVE-2024-25866 1 Codeastro 1 Membership Management System 2026-06-17 N/A 8.8 HIGH
A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the email parameter in the index.php component.
CVE-2024-25865 1 Anzhiyu-c 1 Hexo-theme-anzhiyu 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in hexo-theme-anzhiyu v1.6.12, allows remote attackers to execute arbitrary code via the algolia search function.
CVE-2024-25864 2026-06-17 N/A 9.1 CRITICAL
Server Side Request Forgery (SSRF) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain sensitive information via the fpostit.php component.
CVE-2024-25859 1 Phillipsdata 1 Blesta 2026-06-17 N/A 7.1 HIGH
A path traversal vulnerability in the /path/to/uploads/ directory of Blesta before v5.9.2 allows attackers to takeover user accounts and execute arbitrary code.
CVE-2024-25858 1 Foxit 2 Pdf Editor, Pdf Reader 2026-06-17 N/A 8.4 HIGH
In Foxit PDF Reader before 2024.1 and PDF Editor before 2024.1, code execution via JavaScript could occur because of an unoptimized prompt message for users to review parameters of commands.
CVE-2024-25854 1 Munyweki 1 Insurance Management System 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in Sourcecodester Insurance Management System 1.0 allows attackers to run arbitrary code via the Subject and Description fields when submitting a support ticket.
CVE-2024-25852 1 Linksys 2 Re7000, Re7000 Firmware 2026-06-17 N/A 8.8 HIGH
Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use the vulnerability to obtain device administrator rights.