2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-36376HIGH8.1In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their p...
CVE-2024-36375MEDIUM5.3In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed
CVE-2024-36374MEDIUM5.4In JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possible
CVE-2024-36373MEDIUM5.4In JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possible
CVE-2024-36372MEDIUM6.1In JetBrains TeamCity before 2023.05.6 reflected XSS on the subscriptions page was possible
CVE-2024-36371MEDIUM5.4In JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possible
CVE-2024-36370MEDIUM5.4In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via OAuth connection settings was pos...
CVE-2024-36369MEDIUM5.4In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was pos...
CVE-2024-36368MEDIUM5.4In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration w...
CVE-2024-36367MEDIUM6.1In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible
CVE-2024-36366MEDIUM6.1In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grou...
CVE-2024-36365HIGH8.1In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate...
CVE-2024-36364MEDIUM6.5In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Com...
CVE-2024-36363MEDIUM5.4In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports we...
CVE-2024-36362MEDIUM6.5In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files...
CVE-2024-25975MEDIUM6.5The application implements an up- and downvote function which alters a value within a JSON file. The POST parameters are...
CVE-2024-5185HIGH8.3The EmbedAI application is susceptible to security issues that enable Data Poisoning attacks. This weakness could result...
CVE-2024-5039MEDIUM6.4The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2024-25977HIGH7.3The application does not change the session token when using the login or logout functionality. An attacker can set a se...
CVE-2024-25976MEDIUM6.1When LDAP authentication is activated in the configuration it is possible to obtain reflected XSS execution by creating ...
CVE-2024-27313MEDIUM4.6Zoho ManageEngine PAM360 is vulnerable to Stored XSS vulnerability. This vulnerability is applicable only in the version...
CVE-2024-28826HIGH8.1Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and...
CVE-2024-3412CRITICAL9.1The WP STAGING WordPress Backup Plugin – Migration Backup Restore plugin for WordPress is vulnerable to arbitrary file u...
CVE-2024-5086MEDIUM5.4The Essential Addons for Elementor PRO – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordP...
CVE-2024-36015HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ppdev: Add an error check in register_device In re...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now