2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-56353MEDIUM6.5In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies
CVE-2024-56352MEDIUM5.4In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page
CVE-2024-56350MEDIUM4.3In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects
CVE-2024-56349MEDIUM5.3In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs
CVE-2024-56348MEDIUM4.3In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents
CVE-2024-7726MEDIUM6.8There exists an unauthenticated accessible JTAG port on the Kioxia PM6, PM7 and CM6 devices - On the Kioxia CM6, PM6 and...
CVE-2024-9619MEDIUM6.4The WP SHAPES plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up ...
CVE-2024-9503MEDIUM4.3The Maintenance & Coming Soon Redirect Animation plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2024-12509MEDIUM6.4The Embed Twine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embed_twine' shortco...
CVE-2024-12506MEDIUM6.4The NACC WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nacc' shor...
CVE-2024-11893MEDIUM6.4The Spoki – Chat Buttons and WooCommerce Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2024-11878MEDIUM6.4The Category Post Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'category-po...
CVE-2024-11812MEDIUM6.1The Wtyczka SeoPilot dla WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2024-11806MEDIUM6.1The PKT1 Centro de envios plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'success' and 'er...
CVE-2024-11784MEDIUM6.4The Sell Tickets Online – TicketSource Ticket Shop for WordPress plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2024-11783MEDIUM6.4The Financial Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'finance_cal...
CVE-2024-11775MEDIUM6.4The Particle Background plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'particlegrou...
CVE-2024-11774MEDIUM6.4The Outdooractive Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'list2go' sho...
CVE-2024-11411MEDIUM6.4The Spotlightr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spotlightr-v' shortco...
CVE-2024-11331MEDIUM6.1The استخراج محصولات ووکامرس برای آیسی plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the us...
CVE-2024-8968MEDIUM4.7The WordPress Button Plugin MaxButtons WordPress plugin before 9.8.1 does not sanitise and escape some of its settings, ...
CVE-2024-5955MEDIUM5.4Cross-site scripting vulnerability in Trellix ePolicy Orchestrator prior to ePO 5.10 Service Pack 1 Update 3 allows a re...
CVE-2024-11108MEDIUM5.4The Serious Slider WordPress plugin before 1.2.7 does not validate and escape some of its shortcode attributes before ou...
CVE-2024-10706MEDIUM4.8The Download Manager WordPress plugin before 3.3.03 does not sanitise and escape some of its settings, which could allow...
CVE-2024-10555MEDIUM4.8The WordPress Button Plugin MaxButtons WordPress plugin before 9.8.1 does not sanitise and escape some of its settings, ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now