2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-30684Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-1664MEDIUM6.1The Responsive Gallery Grid WordPress plugin before 2.3.11 does not sanitise and escape some of its settings, which coul...
CVE-2024-30683Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-30681Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-30680Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-30679Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-30678Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-30676Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-30218MEDIUM6.5The ABAP Application Server of SAP NetWeaver as well as ABAP Platform allows an attacker to prevent legitimate users fro...
CVE-2024-30217MEDIUM4.3Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in ...
CVE-2024-30216MEDIUM4.3Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in ...
CVE-2024-30215MEDIUM4.8The Resource Settings page allows a high privilege attacker to load exploitable payload to be stored and reflected whene...
CVE-2024-30214MEDIUM4.8The application allows a high privilege attacker to append a malicious GET query parameter to Service invocations, which...
CVE-2024-2975HIGH7.5A race condition was identified through which privilege escalation was possible in certain configurations.
CVE-2024-28167MEDIUM6.5SAP Group Reporting Data Collection does not perform necessary authorization checks for an authenticated user, resulting...
CVE-2024-27983HIGH8.2An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets...
CVE-2024-27901HIGH7.2SAP Asset Accounting could allow a high privileged attacker to exploit insufficient validation of path information provi...
CVE-2024-27899HIGH8.8Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper sec...
CVE-2024-27898MEDIUM5.3SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vul...
CVE-2024-25646MEDIUM6.5Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to acce...
CVE-2024-31047LOW3.3An issue in Academy Software Foundation openexr v.3.2.3 and before allows a local attacker to cause a denial of service ...
CVE-2024-23584MEDIUM6.6The NMAP Importer service​ may expose data store credentials to authorized users of the Windows Registry.
CVE-2024-23084HIGH7.5Apfloat v1.10.1 was discovered to contain an ArrayIndexOutOfBoundsException via the component org.apfloat.internal.Doubl...
CVE-2024-23081LOW3.3ThreeTen Backport v1.6.8 was discovered to contain a NullPointerException via the component org.threeten.bp.LocalDate::c...
CVE-2024-23079MEDIUM6.2JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDou...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now