2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-36368MEDIUM5.4In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration w...
CVE-2024-36367MEDIUM6.1In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible
CVE-2024-36366MEDIUM6.1In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grou...
CVE-2024-36364MEDIUM6.5In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Com...
CVE-2024-36363MEDIUM5.4In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports we...
CVE-2024-36362MEDIUM6.5In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files...
CVE-2024-25975MEDIUM6.5The application implements an up- and downvote function which alters a value within a JSON file. The POST parameters are...
CVE-2024-5039MEDIUM6.4The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2024-25976MEDIUM6.1When LDAP authentication is activated in the configuration it is possible to obtain reflected XSS execution by creating ...
CVE-2024-27313MEDIUM4.6Zoho ManageEngine PAM360 is vulnerable to Stored XSS vulnerability. This vulnerability is applicable only in the version...
CVE-2024-5086MEDIUM5.4The Essential Addons for Elementor PRO – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordP...
CVE-2024-36014MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/arm/malidp: fix a possible null pointer derefer...
CVE-2024-4419MEDIUM4The Fetch JFT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to...
CVE-2024-3937MEDIUM4.8The Playlist for Youtube WordPress plugin through 1.32 does not sanitise and escape some of its settings, which could al...
CVE-2024-3921MEDIUM4.8The Gianism WordPress plugin through 5.1.0 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2024-0434MEDIUM5.3The WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly plugin for WordPress is vulnerable to unauthoriz...
CVE-2024-5437MEDIUM6.1A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as problematic. Aff...
CVE-2024-36112MEDIUM6.5Nautobot is a Network Source of Truth and Network Automation Platform. A user with permissions to view Dynamic Group rec...
CVE-2024-23580MEDIUM6.5HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of One-Time Passwords (OTPs). This could allow an at...
CVE-2024-23579MEDIUM6.5HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of security questions. This could allow an attacker ...
CVE-2024-35548MEDIUM5.4A SQL injection vulnerability in Mybatis plus versions below 3.5.6 allows remote attackers to obtain database informatio...
CVE-2024-35511MEDIUM4.7phpgurukul Men Salon Management System v2.0 is vulnerable to SQL Injection via the "username" parameter of /msms/admin/i...
CVE-2024-35240MEDIUM5.4Umbraco Commerce is an open source dotnet ecommerce solution. In affected versions there exists a stored Cross-site scri...
CVE-2024-35239MEDIUM5.4Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access...
CVE-2024-35583MEDIUM6.1A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now