2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-30684 | — | — | — | Apr 9, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-1664 | MEDIUM | 6.1 | 0.5% | Apr 9, 2024 | The Responsive Gallery Grid WordPress plugin before 2.3.11 does not sanitise and escape some of its settings, which coul... |
| CVE-2024-30683 | — | — | — | Apr 9, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-30681 | — | — | — | Apr 9, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-30680 | — | — | — | Apr 9, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-30679 | — | — | — | Apr 9, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-30678 | — | — | — | Apr 9, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-30676 | — | — | — | Apr 9, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-30218 | MEDIUM | 6.5 | 0.5% | Apr 9, 2024 | The ABAP Application Server of SAP NetWeaver as well as ABAP Platform allows an attacker to prevent legitimate users fro... |
| CVE-2024-30217 | MEDIUM | 4.3 | 0.3% | Apr 9, 2024 | Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in ... |
| CVE-2024-30216 | MEDIUM | 4.3 | 0.3% | Apr 9, 2024 | Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in ... |
| CVE-2024-30215 | MEDIUM | 4.8 | 0.3% | Apr 9, 2024 | The Resource Settings page allows a high privilege attacker to load exploitable payload to be stored and reflected whene... |
| CVE-2024-30214 | MEDIUM | 4.8 | 0.3% | Apr 9, 2024 | The application allows a high privilege attacker to append a malicious GET query parameter to Service invocations, which... |
| CVE-2024-2975 | HIGH | 7.5 | 0.4% | Apr 9, 2024 | A race condition was identified through which privilege escalation was possible in certain configurations. |
| CVE-2024-28167 | MEDIUM | 6.5 | 0.4% | Apr 9, 2024 | SAP Group Reporting Data Collection does not perform necessary authorization checks for an authenticated user, resulting... |
| CVE-2024-27983 | HIGH | 8.2 | 87.2% | Apr 9, 2024 | An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets... |
| CVE-2024-27901 | HIGH | 7.2 | 0.7% | Apr 9, 2024 | SAP Asset Accounting could allow a high privileged attacker to exploit insufficient validation of path information provi... |
| CVE-2024-27899 | HIGH | 8.8 | 0.4% | Apr 9, 2024 | Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper sec... |
| CVE-2024-27898 | MEDIUM | 5.3 | 0.4% | Apr 9, 2024 | SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vul... |
| CVE-2024-25646 | MEDIUM | 6.5 | 0.4% | Apr 9, 2024 | Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to acce... |
| CVE-2024-31047 | LOW | 3.3 | 0.2% | Apr 8, 2024 | An issue in Academy Software Foundation openexr v.3.2.3 and before allows a local attacker to cause a denial of service ... |
| CVE-2024-23584 | MEDIUM | 6.6 | 0.3% | Apr 8, 2024 | The NMAP Importer service may expose data store credentials to authorized users of the Windows Registry. |
| CVE-2024-23084 | HIGH | 7.5 | 0.8% | Apr 8, 2024 | Apfloat v1.10.1 was discovered to contain an ArrayIndexOutOfBoundsException via the component org.apfloat.internal.Doubl... |
| CVE-2024-23081 | LOW | 3.3 | 0.3% | Apr 8, 2024 | ThreeTen Backport v1.6.8 was discovered to contain a NullPointerException via the component org.threeten.bp.LocalDate::c... |
| CVE-2024-23079 | MEDIUM | 6.2 | 0.2% | Apr 8, 2024 | JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDou... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now