2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-56331 | MEDIUM | 6.8 | 1.8% | Dec 20, 2024 | Uptime Kuma is an open source, self-hosted monitoring tool. An **Improper URL Handling Vulnerability** allows an attacke... |
| CVE-2024-56330 | CRITICAL | 9.3 | 0.5% | Dec 20, 2024 | Stardust is a platform for streaming isolated desktop containers. With this exploit, inter container communication (ICC)... |
| CVE-2024-56329 | HIGH | 8.9 | 0.5% | Dec 20, 2024 | Socialstream is a third-party package for Laravel Jetstream. It replaces the published authentication and profile scaffo... |
| CVE-2024-55341 | MEDIUM | 4.7 | 0.4% | Dec 20, 2024 | A stored cross-site scripting (XSS) vulnerability in Piranha CMS 11.1 allows remote attackers to execute arbitrary JavaS... |
| CVE-2024-12867 | HIGH | 8.8 | 0.5% | Dec 20, 2024 | Server-Side Request Forgery in URL Mapper in Arctic Security's Arctic Hub versions 3.0.1764-5.6.1877 allows an unauthent... |
| CVE-2024-12842 | MEDIUM | 6.1 | 0.4% | Dec 20, 2024 | A vulnerability was found in Emlog Pro up to 2.4.1. It has been declared as problematic. This vulnerability affects unkn... |
| CVE-2024-55342 | MEDIUM | 4.7 | 0.5% | Dec 20, 2024 | A file upload functionality in Piranha CMS 11.1 allows authenticated remote attackers to upload a crafted PDF file to /m... |
| CVE-2024-37758 | HIGH | 8.8 | 0.3% | Dec 20, 2024 | Improper access control in the endpoint /RoleMenuMapping/AddRoleMenu of Digiteam v4.21.0.0 allows authenticated attacker... |
| CVE-2024-12841 | MEDIUM | 6.1 | 0.4% | Dec 20, 2024 | A vulnerability was found in Emlog Pro up to 2.4.1. It has been classified as problematic. This affects an unknown part ... |
| CVE-2024-12677 | HIGH | 8.5 | 0.3% | Dec 20, 2024 | Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code. |
| CVE-2024-56337 | CRITICAL | 9.8 | 8.9% | Dec 20, 2024 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: fro... |
| CVE-2024-55471 | MEDIUM | 6.5 | 0.3% | Dec 20, 2024 | Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This all... |
| CVE-2024-55470 | HIGH | 7.5 | 0.4% | Dec 20, 2024 | Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can ... |
| CVE-2024-55186 | MEDIUM | 4.3 | 0.3% | Dec 20, 2024 | An IDOR (Insecure Direct Object Reference) vulnerability exists in oqtane Framework 6.0.0, allowing a logged-in user to ... |
| CVE-2024-12840 | — | — | — | Dec 20, 2024 | Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. The problem described ... |
| CVE-2024-10385 | HIGH | 8.6 | 0.6% | Dec 20, 2024 | Ticket management system in DirectAdmin Evolution Skin is vulnerable to XSS (Cross-site Scripting), which allows a low-p... |
| CVE-2024-56356 | HIGH | 7.1 | 0.2% | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack |
| CVE-2024-56355 | MEDIUM | 5.4 | 0.8% | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS |
| CVE-2024-56354 | MEDIUM | 4.9 | 0.3% | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission |
| CVE-2024-56353 | MEDIUM | 6.5 | 0.3% | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies |
| CVE-2024-56352 | MEDIUM | 5.4 | 0.8% | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page |
| CVE-2024-56351 | HIGH | 8.8 | 0.3% | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles |
| CVE-2024-56350 | MEDIUM | 4.3 | 0.3% | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects |
| CVE-2024-56349 | MEDIUM | 5.3 | 0.3% | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs |
| CVE-2024-56348 | MEDIUM | 4.3 | 0.3% | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now