2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-36368 | MEDIUM | 5.4 | 0.3% | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration w... |
| CVE-2024-36367 | MEDIUM | 6.1 | 0.3% | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible |
| CVE-2024-36366 | MEDIUM | 6.1 | 0.3% | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grou... |
| CVE-2024-36364 | MEDIUM | 6.5 | 0.3% | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Com... |
| CVE-2024-36363 | MEDIUM | 5.4 | 0.3% | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports we... |
| CVE-2024-36362 | MEDIUM | 6.5 | 0.5% | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files... |
| CVE-2024-25975 | MEDIUM | 6.5 | 0.6% | May 29, 2024 | The application implements an up- and downvote function which alters a value within a JSON file. The POST parameters are... |
| CVE-2024-5039 | MEDIUM | 6.4 | 0.3% | May 29, 2024 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripti... |
| CVE-2024-25976 | MEDIUM | 6.1 | 0.6% | May 29, 2024 | When LDAP authentication is activated in the configuration it is possible to obtain reflected XSS execution by creating ... |
| CVE-2024-27313 | MEDIUM | 4.6 | 1.3% | May 29, 2024 | Zoho ManageEngine PAM360 is vulnerable to Stored XSS vulnerability. This vulnerability is applicable only in the version... |
| CVE-2024-5086 | MEDIUM | 5.4 | 0.3% | May 29, 2024 | The Essential Addons for Elementor PRO – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordP... |
| CVE-2024-36014 | MEDIUM | 5.5 | 0.2% | May 29, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/arm/malidp: fix a possible null pointer derefer... |
| CVE-2024-4419 | MEDIUM | 4 | 0.2% | May 29, 2024 | The Fetch JFT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to... |
| CVE-2024-3937 | MEDIUM | 4.8 | 0.3% | May 29, 2024 | The Playlist for Youtube WordPress plugin through 1.32 does not sanitise and escape some of its settings, which could al... |
| CVE-2024-3921 | MEDIUM | 4.8 | 0.4% | May 29, 2024 | The Gianism WordPress plugin through 5.1.0 does not sanitise and escape some of its settings, which could allow high pri... |
| CVE-2024-0434 | MEDIUM | 5.3 | 0.4% | May 29, 2024 | The WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly plugin for WordPress is vulnerable to unauthoriz... |
| CVE-2024-5437 | MEDIUM | 6.1 | 0.4% | May 29, 2024 | A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as problematic. Aff... |
| CVE-2024-36112 | MEDIUM | 6.5 | 0.4% | May 28, 2024 | Nautobot is a Network Source of Truth and Network Automation Platform. A user with permissions to view Dynamic Group rec... |
| CVE-2024-23580 | MEDIUM | 6.5 | 0.1% | May 28, 2024 | HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of One-Time Passwords (OTPs). This could allow an at... |
| CVE-2024-23579 | MEDIUM | 6.5 | 0.1% | May 28, 2024 | HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of security questions. This could allow an attacker ... |
| CVE-2024-35548 | MEDIUM | 5.4 | 0.4% | May 28, 2024 | A SQL injection vulnerability in Mybatis plus versions below 3.5.6 allows remote attackers to obtain database informatio... |
| CVE-2024-35511 | MEDIUM | 4.7 | 0.4% | May 28, 2024 | phpgurukul Men Salon Management System v2.0 is vulnerable to SQL Injection via the "username" parameter of /msms/admin/i... |
| CVE-2024-35240 | MEDIUM | 5.4 | 0.3% | May 28, 2024 | Umbraco Commerce is an open source dotnet ecommerce solution. In affected versions there exists a stored Cross-site scri... |
| CVE-2024-35239 | MEDIUM | 5.4 | 0.3% | May 28, 2024 | Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access... |
| CVE-2024-35583 | MEDIUM | 6.1 | 0.5% | May 28, 2024 | A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execu... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now