2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-56354MEDIUM4.9In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission
CVE-2024-56353MEDIUM6.5In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies
CVE-2024-56352MEDIUM5.4In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page
CVE-2024-56351HIGH8.8In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles
CVE-2024-56350MEDIUM4.3In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects
CVE-2024-56349MEDIUM5.3In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs
CVE-2024-56348MEDIUM4.3In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents
CVE-2024-51466CRITICAL9IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 is vulnerable to an Expression Language (EL)...
CVE-2024-40695HIGH8IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 could be vulnerable to malicious file uplo...
CVE-2024-28767HIGH8.8IBM Security Directory Integrator 7.2.0 through 7.2.0.13 and 10.0.0 through 10.0.3 could allow a remote authenticated at...
CVE-2024-12014LOW2Path Traversal vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow ...
CVE-2024-7726MEDIUM6.8There exists an unauthenticated accessible JTAG port on the Kioxia PM6, PM7 and CM6 devices - On the Kioxia CM6, PM6 and...
CVE-2024-9619MEDIUM6.4The WP SHAPES plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up ...
CVE-2024-9503MEDIUM4.3The Maintenance & Coming Soon Redirect Animation plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2024-12571CRITICAL9.8The Store Locator for WordPress with Google Maps – LotsOfLocales plugin for WordPress is vulnerable to Local File Inclus...
CVE-2024-12509MEDIUM6.4The Embed Twine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embed_twine' shortco...
CVE-2024-12506MEDIUM6.4The NACC WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nacc' shor...
CVE-2024-11893MEDIUM6.4The Spoki – Chat Buttons and WooCommerce Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2024-11878MEDIUM6.4The Category Post Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'category-po...
CVE-2024-11812MEDIUM6.1The Wtyczka SeoPilot dla WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2024-11806MEDIUM6.1The PKT1 Centro de envios plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'success' and 'er...
CVE-2024-11784MEDIUM6.4The Sell Tickets Online – TicketSource Ticket Shop for WordPress plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2024-11783MEDIUM6.4The Financial Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'finance_cal...
CVE-2024-11775MEDIUM6.4The Particle Background plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'particlegrou...
CVE-2024-11774MEDIUM6.4The Outdooractive Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'list2go' sho...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now