2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50441 | MEDIUM | 5.4 | 0.3% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CozyThemes Cozy Bl... |
| CVE-2024-50440 | MEDIUM | 5.4 | 0.2% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Coyier CodeP... |
| CVE-2024-50439 | MEDIUM | 5.4 | 0.2% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force A... |
| CVE-2024-50438 | MEDIUM | 6.1 | 0.3% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andy_moyle Church ... |
| CVE-2024-49771 | MEDIUM | 5.3 | 0.5% | Oct 28, 2024 | MPXJ is an open source library to read and write project plans from a variety of file formats and databases. The patch f... |
| CVE-2024-47827 | MEDIUM | 4.8 | 0.3% | Oct 28, 2024 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Due to ... |
| CVE-2024-10469 | MEDIUM | 6.5 | 0.2% | Oct 28, 2024 | VINCE versions before 3.0.9 is vulnerable to exposure of User information to authenticated users. |
| CVE-2024-48291 | MEDIUM | 6.3 | 0.2% | Oct 28, 2024 | dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=editAdm... |
| CVE-2024-50443 | MEDIUM | 5.4 | 0.3% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPXPO PostX ultima... |
| CVE-2024-48191 | MEDIUM | 6.3 | 0.2% | Oct 28, 2024 | dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.p... |
| CVE-2024-34537 | MEDIUM | 4.9 | 0.7% | Oct 28, 2024 | TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an ... |
| CVE-2024-10448 | MEDIUM | 6.5 | 0.4% | Oct 28, 2024 | A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank Management System 1.0. ... |
| CVE-2024-50582 | MEDIUM | 5.4 | 0.3% | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements |
| CVE-2024-50581 | MEDIUM | 5.4 | 0.3% | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag |
| CVE-2024-50580 | MEDIUM | 5.4 | 0.3% | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom renderi... |
| CVE-2024-50579 | MEDIUM | 6.1 | 0.3% | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible |
| CVE-2024-50578 | MEDIUM | 5.4 | 0.3% | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page |
| CVE-2024-50577 | MEDIUM | 5.4 | 0.3% | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings |
| CVE-2024-50576 | MEDIUM | 5.4 | 0.3% | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest |
| CVE-2024-50575 | MEDIUM | 6.1 | 0.3% | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API |
| CVE-2024-50573 | MEDIUM | 5.4 | 0.2% | Oct 28, 2024 | In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized... |
| CVE-2024-50502 | MEDIUM | 5.4 | 0.2% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CozyThemes Cozy Bl... |
| CVE-2024-50501 | MEDIUM | 5.4 | 0.2% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Climax Themes Kata... |
| CVE-2024-50472 | MEDIUM | 5.4 | 0.2% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in martindrapeau Amil... |
| CVE-2024-50471 | MEDIUM | 5.4 | 0.2% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in checklistcom Trip ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now