2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-33004MEDIUM4.3SAP Business Objects Business Intelligence Platform is vulnerable to Insecure Storage as dynamic web pages are getting c...
CVE-2024-33002MEDIUM6.1Document Service handler (obsolete) in Data Provisioning Service does not sufficiently encode user-controlled inputs, re...
CVE-2024-33000LOW3.5SAP Bank Account Management does not perform necessary authorization check for an authorized user, resulting in escalati...
CVE-2024-32977CRITICAL9.4OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10....
CVE-2024-32742HIGH7.6A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains an unrestrict...
CVE-2024-32741CRITICAL10A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded pa...
CVE-2024-32740CRITICAL9.8A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains undocumented ...
CVE-2024-32733MEDIUM6.1 Due to missing input validation and output encoding of untrusted data, SAP NetWeaver Application Server ABAP and ABAP P...
CVE-2024-32731MEDIUM5.5 SAP My Travel Requests does not perform necessary authorization checks for an authenticated user, resulting in escalati...
CVE-2024-32639HIGH7.8A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0011). The affected appli...
CVE-2024-32637MEDIUM5.5A vulnerability has been identified in JT2Go (All versions < V2312.0005), Teamcenter Visualization V14.2 (All versions <...
CVE-2024-32636HIGH7.8A vulnerability has been identified in JT2Go (All versions < V2312.0005), Teamcenter Visualization V14.2 (All versions <...
CVE-2024-32635HIGH7.8A vulnerability has been identified in JT2Go (All versions < V2312.0005), Teamcenter Visualization V14.2 (All versions <...
CVE-2024-32355HIGH8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'password' p...
CVE-2024-32354MEDIUM6TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'timeout' pa...
CVE-2024-32353CRITICAL9.8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'port' param...
CVE-2024-32352HIGH8.8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulner...
CVE-2024-32351HIGH8.8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulner...
CVE-2024-32350HIGH8.8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulner...
CVE-2024-32349MEDIUM6TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulner...
CVE-2024-32077MEDIUM5.4Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the...
CVE-2024-32066HIGH7.8A vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain an out ...
CVE-2024-32065HIGH7.8A vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain an out ...
CVE-2024-32064HIGH7.8A vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain an out ...
CVE-2024-32063HIGH7.8A vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected application contains a type ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now