2024 CVE Vulnerabilities
39,233 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50581 | MEDIUM | 5.4 | 0.3% | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag |
| CVE-2024-50580 | MEDIUM | 5.4 | 0.3% | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom renderi... |
| CVE-2024-50579 | MEDIUM | 6.1 | 0.3% | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible |
| CVE-2024-50578 | MEDIUM | 5.4 | 0.3% | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page |
| CVE-2024-50577 | MEDIUM | 5.4 | 0.3% | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings |
| CVE-2024-50576 | MEDIUM | 5.4 | 0.3% | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest |
| CVE-2024-50575 | MEDIUM | 6.1 | 0.3% | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API |
| CVE-2024-50574 | HIGH | 7.5 | 0.6% | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk func... |
| CVE-2024-50573 | MEDIUM | 5.4 | 0.2% | Oct 28, 2024 | In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized... |
| CVE-2024-50502 | MEDIUM | 5.4 | 0.2% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CozyThemes Cozy Bl... |
| CVE-2024-50501 | MEDIUM | 5.4 | 0.2% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Climax Themes Kata... |
| CVE-2024-50497 | CRITICAL | 9.8 | 0.5% | Oct 28, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-50491 | CRITICAL | 9.8 | 1.0% | Oct 28, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MicahBlu RSVP ME r... |
| CVE-2024-50488 | HIGH | 8.8 | 0.9% | Oct 28, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in yespbs Token Login token-login allows Authenti... |
| CVE-2024-50483 | CRITICAL | 9.8 | 2.4% | Oct 28, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in Tareq Hasan Meetup meetup allows Privilege Escalation.... |
| CVE-2024-50479 | CRITICAL | 9.8 | 0.5% | Oct 28, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chenyenming Woocom... |
| CVE-2024-50478 | CRITICAL | 9.8 | 1.1% | Oct 28, 2024 | Authentication Bypass by Primary Weakness vulnerability in Swoop 1-Click Login: Passwordless Authentication allows Authe... |
| CVE-2024-50472 | MEDIUM | 5.4 | 0.2% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in martindrapeau Amil... |
| CVE-2024-50471 | MEDIUM | 5.4 | 0.2% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in checklistcom Trip ... |
| CVE-2024-50470 | MEDIUM | 5.4 | 0.2% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themes4WP Themes4W... |
| CVE-2024-50465 | MEDIUM | 6.5 | 0.4% | Oct 28, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP SEO – Calin Vin... |
| CVE-2024-50463 | MEDIUM | 6.1 | 0.3% | Oct 28, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-phot... |
| CVE-2024-10447 | HIGH | 8.8 | 0.5% | Oct 28, 2024 | A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. Affected by this vul... |
| CVE-2024-50498 | CRITICAL | 9.8 | 53.6% | Oct 28, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Ajit Bohra WP Query Console wp-query-console ... |
| CVE-2024-50492 | CRITICAL | 9.8 | 1.4% | Oct 28, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart scottcart allows Cod... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now