2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-56331MEDIUM6.8Uptime Kuma is an open source, self-hosted monitoring tool. An **Improper URL Handling Vulnerability** allows an attacke...
CVE-2024-56330CRITICAL9.3Stardust is a platform for streaming isolated desktop containers. With this exploit, inter container communication (ICC)...
CVE-2024-56329HIGH8.9Socialstream is a third-party package for Laravel Jetstream. It replaces the published authentication and profile scaffo...
CVE-2024-55341MEDIUM4.7A stored cross-site scripting (XSS) vulnerability in Piranha CMS 11.1 allows remote attackers to execute arbitrary JavaS...
CVE-2024-12867HIGH8.8Server-Side Request Forgery in URL Mapper in Arctic Security's Arctic Hub versions 3.0.1764-5.6.1877 allows an unauthent...
CVE-2024-12842MEDIUM6.1A vulnerability was found in Emlog Pro up to 2.4.1. It has been declared as problematic. This vulnerability affects unkn...
CVE-2024-55342MEDIUM4.7A file upload functionality in Piranha CMS 11.1 allows authenticated remote attackers to upload a crafted PDF file to /m...
CVE-2024-37758HIGH8.8Improper access control in the endpoint /RoleMenuMapping/AddRoleMenu of Digiteam v4.21.0.0 allows authenticated attacker...
CVE-2024-12841MEDIUM6.1A vulnerability was found in Emlog Pro up to 2.4.1. It has been classified as problematic. This affects an unknown part ...
CVE-2024-12677HIGH8.5Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code.
CVE-2024-56337CRITICAL9.8Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: fro...
CVE-2024-55471MEDIUM6.5Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This all...
CVE-2024-55470HIGH7.5Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can ...
CVE-2024-55186MEDIUM4.3An IDOR (Insecure Direct Object Reference) vulnerability exists in oqtane Framework 6.0.0, allowing a logged-in user to ...
CVE-2024-12840Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. The problem described ...
CVE-2024-10385HIGH8.6Ticket management system in DirectAdmin Evolution Skin is vulnerable to XSS (Cross-site Scripting), which allows a low-p...
CVE-2024-56356HIGH7.1In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack
CVE-2024-56355MEDIUM5.4In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS
CVE-2024-56354MEDIUM4.9In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission
CVE-2024-56353MEDIUM6.5In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies
CVE-2024-56352MEDIUM5.4In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page
CVE-2024-56351HIGH8.8In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles
CVE-2024-56350MEDIUM4.3In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects
CVE-2024-56349MEDIUM5.3In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs
CVE-2024-56348MEDIUM4.3In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now