2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-10469MEDIUM6.5VINCE versions before 3.0.9 is vulnerable to exposure of User information to authenticated users.
CVE-2024-48291MEDIUM6.3dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=editAdm...
CVE-2024-50443MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPXPO PostX ultima...
CVE-2024-48191MEDIUM6.3dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.p...
CVE-2024-34537MEDIUM4.9TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an ...
CVE-2024-10448MEDIUM6.5A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank Management System 1.0. ...
CVE-2024-50582MEDIUM5.4In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements
CVE-2024-50581MEDIUM5.4In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag
CVE-2024-50580MEDIUM5.4In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom renderi...
CVE-2024-50579MEDIUM6.1In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible
CVE-2024-50578MEDIUM5.4In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page
CVE-2024-50577MEDIUM5.4In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings
CVE-2024-50576MEDIUM5.4In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest
CVE-2024-50575MEDIUM6.1In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API
CVE-2024-50573MEDIUM5.4In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized...
CVE-2024-50502MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CozyThemes Cozy Bl...
CVE-2024-50501MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Climax Themes Kata...
CVE-2024-50472MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in martindrapeau Amil...
CVE-2024-50471MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in checklistcom Trip ...
CVE-2024-50470MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themes4WP Themes4W...
CVE-2024-50465MEDIUM6.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP SEO – Calin Vin...
CVE-2024-50463MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-phot...
CVE-2024-50307MEDIUM5.5Use of potentially dangerous function issue exists in Chatwork Desktop Application (Windows) versions prior to 2.9.2. If...
CVE-2024-48936MEDIUM5SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit a...
CVE-2024-10435MEDIUM6.3A vulnerability was found in didi Super-Jacoco 1.0. It has been declared as critical. This vulnerability affects unknown...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now