2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12842 | MEDIUM | 6.1 | 0.4% | Dec 20, 2024 | A vulnerability was found in Emlog Pro up to 2.4.1. It has been declared as problematic. This vulnerability affects unkn... |
| CVE-2024-55342 | MEDIUM | 4.7 | 0.5% | Dec 20, 2024 | A file upload functionality in Piranha CMS 11.1 allows authenticated remote attackers to upload a crafted PDF file to /m... |
| CVE-2024-12841 | MEDIUM | 6.1 | 0.4% | Dec 20, 2024 | A vulnerability was found in Emlog Pro up to 2.4.1. It has been classified as problematic. This affects an unknown part ... |
| CVE-2024-55471 | MEDIUM | 6.5 | 0.3% | Dec 20, 2024 | Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This all... |
| CVE-2024-55186 | MEDIUM | 4.3 | 0.3% | Dec 20, 2024 | An IDOR (Insecure Direct Object Reference) vulnerability exists in oqtane Framework 6.0.0, allowing a logged-in user to ... |
| CVE-2024-56355 | MEDIUM | 5.4 | 0.8% | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS |
| CVE-2024-56354 | MEDIUM | 4.9 | 0.3% | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission |
| CVE-2024-56353 | MEDIUM | 6.5 | 0.3% | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies |
| CVE-2024-56352 | MEDIUM | 5.4 | 0.8% | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page |
| CVE-2024-56350 | MEDIUM | 4.3 | 0.3% | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects |
| CVE-2024-56349 | MEDIUM | 5.3 | 0.3% | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs |
| CVE-2024-56348 | MEDIUM | 4.3 | 0.3% | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents |
| CVE-2024-7726 | MEDIUM | 6.8 | 0.4% | Dec 20, 2024 | There exists an unauthenticated accessible JTAG port on the Kioxia PM6, PM7 and CM6 devices - On the Kioxia CM6, PM6 and... |
| CVE-2024-9619 | MEDIUM | 6.4 | 0.3% | Dec 20, 2024 | The WP SHAPES plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up ... |
| CVE-2024-9503 | MEDIUM | 4.3 | 0.3% | Dec 20, 2024 | The Maintenance & Coming Soon Redirect Animation plugin for WordPress is vulnerable to unauthorized modification of data... |
| CVE-2024-12509 | MEDIUM | 6.4 | 0.3% | Dec 20, 2024 | The Embed Twine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embed_twine' shortco... |
| CVE-2024-12506 | MEDIUM | 6.4 | 0.4% | Dec 20, 2024 | The NACC WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nacc' shor... |
| CVE-2024-11893 | MEDIUM | 6.4 | 0.4% | Dec 20, 2024 | The Spoki – Chat Buttons and WooCommerce Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2024-11878 | MEDIUM | 6.4 | 0.3% | Dec 20, 2024 | The Category Post Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'category-po... |
| CVE-2024-11812 | MEDIUM | 6.1 | 0.2% | Dec 20, 2024 | The Wtyczka SeoPilot dla WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
| CVE-2024-11806 | MEDIUM | 6.1 | 0.3% | Dec 20, 2024 | The PKT1 Centro de envios plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'success' and 'er... |
| CVE-2024-11784 | MEDIUM | 6.4 | 0.3% | Dec 20, 2024 | The Sell Tickets Online – TicketSource Ticket Shop for WordPress plugin for WordPress is vulnerable to Stored Cross-Site... |
| CVE-2024-11783 | MEDIUM | 6.4 | 0.3% | Dec 20, 2024 | The Financial Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'finance_cal... |
| CVE-2024-11775 | MEDIUM | 6.4 | 0.3% | Dec 20, 2024 | The Particle Background plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'particlegrou... |
| CVE-2024-11774 | MEDIUM | 6.4 | 0.3% | Dec 20, 2024 | The Outdooractive Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'list2go' sho... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now