NA - CVE-2024-39304 - ChurchCRM is an open-source church management...
ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an authenticated SQL injection due to an improper sanitization of user input....
NA - CVE-2024-38508 - A privilege escalation vulnerability was...
A privilege escalation vulnerability was discovered in the web interface or SSH captive command shell interface of XCC that could allow an authenticated XCC user with elevated privileges to perform...
High - CVE-2024-38509 - A privilege escalation vulnerability was...
A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to execute arbitrary code via a specially crafted IPMI command.
High - CVE-2024-38510 - A privilege escalation vulnerability was...
A privilege escalation vulnerability was discovered in the SSH captive command shell interface that could allow an authenticated XCC user with elevated privileges to perform command injection via...
High - CVE-2024-38511 - A privilege escalation vulnerability was...
A privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via...
High - CVE-2024-38512 - A privilege escalation vulnerability was...
A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted IPMI commands.