2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-36376 | HIGH | 8.1 | 0.3% | May 29, 2024 | In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their p... |
| CVE-2024-36375 | MEDIUM | 5.3 | 0.3% | May 29, 2024 | In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed |
| CVE-2024-36374 | MEDIUM | 5.4 | 0.3% | May 29, 2024 | In JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possible |
| CVE-2024-36373 | MEDIUM | 5.4 | 0.3% | May 29, 2024 | In JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possible |
| CVE-2024-36372 | MEDIUM | 6.1 | 0.3% | May 29, 2024 | In JetBrains TeamCity before 2023.05.6 reflected XSS on the subscriptions page was possible |
| CVE-2024-36371 | MEDIUM | 5.4 | 0.3% | May 29, 2024 | In JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possible |
| CVE-2024-36370 | MEDIUM | 5.4 | 0.3% | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via OAuth connection settings was pos... |
| CVE-2024-36369 | MEDIUM | 5.4 | 0.3% | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was pos... |
| CVE-2024-36368 | MEDIUM | 5.4 | 0.3% | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration w... |
| CVE-2024-36367 | MEDIUM | 6.1 | 0.3% | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible |
| CVE-2024-36366 | MEDIUM | 6.1 | 0.3% | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grou... |
| CVE-2024-36365 | HIGH | 8.1 | 0.3% | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate... |
| CVE-2024-36364 | MEDIUM | 6.5 | 0.3% | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Com... |
| CVE-2024-36363 | MEDIUM | 5.4 | 0.3% | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports we... |
| CVE-2024-36362 | MEDIUM | 6.5 | 0.5% | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files... |
| CVE-2024-25975 | MEDIUM | 6.5 | 0.6% | May 29, 2024 | The application implements an up- and downvote function which alters a value within a JSON file. The POST parameters are... |
| CVE-2024-5185 | HIGH | 8.3 | 0.2% | May 29, 2024 | The EmbedAI application is susceptible to security issues that enable Data Poisoning attacks. This weakness could result... |
| CVE-2024-5039 | MEDIUM | 6.4 | 0.3% | May 29, 2024 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripti... |
| CVE-2024-25977 | HIGH | 7.3 | 0.6% | May 29, 2024 | The application does not change the session token when using the login or logout functionality. An attacker can set a se... |
| CVE-2024-25976 | MEDIUM | 6.1 | 0.6% | May 29, 2024 | When LDAP authentication is activated in the configuration it is possible to obtain reflected XSS execution by creating ... |
| CVE-2024-27313 | MEDIUM | 4.6 | 1.3% | May 29, 2024 | Zoho ManageEngine PAM360 is vulnerable to Stored XSS vulnerability. This vulnerability is applicable only in the version... |
| CVE-2024-28826 | HIGH | 8.1 | 0.5% | May 29, 2024 | Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and... |
| CVE-2024-3412 | CRITICAL | 9.1 | 0.8% | May 29, 2024 | The WP STAGING WordPress Backup Plugin – Migration Backup Restore plugin for WordPress is vulnerable to arbitrary file u... |
| CVE-2024-5086 | MEDIUM | 5.4 | 0.3% | May 29, 2024 | The Essential Addons for Elementor PRO – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordP... |
| CVE-2024-36015 | HIGH | 7.8 | 0.3% | May 29, 2024 | In the Linux kernel, the following vulnerability has been resolved: ppdev: Add an error check in register_device In re... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now