2024 CVE Vulnerabilities

39,233 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-50581MEDIUM5.4In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag
CVE-2024-50580MEDIUM5.4In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom renderi...
CVE-2024-50579MEDIUM6.1In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible
CVE-2024-50578MEDIUM5.4In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page
CVE-2024-50577MEDIUM5.4In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings
CVE-2024-50576MEDIUM5.4In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest
CVE-2024-50575MEDIUM6.1In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API
CVE-2024-50574HIGH7.5In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk func...
CVE-2024-50573MEDIUM5.4In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized...
CVE-2024-50502MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CozyThemes Cozy Bl...
CVE-2024-50501MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Climax Themes Kata...
CVE-2024-50497CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-50491CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MicahBlu RSVP ME r...
CVE-2024-50488HIGH8.8Authentication Bypass Using an Alternate Path or Channel vulnerability in yespbs Token Login token-login allows Authenti...
CVE-2024-50483CRITICAL9.8Authorization Bypass Through User-Controlled Key vulnerability in Tareq Hasan Meetup meetup allows Privilege Escalation....
CVE-2024-50479CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chenyenming Woocom...
CVE-2024-50478CRITICAL9.8Authentication Bypass by Primary Weakness vulnerability in Swoop 1-Click Login: Passwordless Authentication allows Authe...
CVE-2024-50472MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in martindrapeau Amil...
CVE-2024-50471MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in checklistcom Trip ...
CVE-2024-50470MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themes4WP Themes4W...
CVE-2024-50465MEDIUM6.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP SEO – Calin Vin...
CVE-2024-50463MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-phot...
CVE-2024-10447HIGH8.8A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. Affected by this vul...
CVE-2024-50498CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Ajit Bohra WP Query Console wp-query-console ...
CVE-2024-50492CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart scottcart allows Cod...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now