2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-26003HIGH7.5An unauthenticated remote attacker can DoS the control agent due to a out-of-bounds read which may prevent or disrupt th...
CVE-2024-26002HIGH7.8An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by c...
CVE-2024-26001CRITICAL9.8An unauthenticated remote attacker can write memory out of bounds due to improper input validation in the MQTT stack. Th...
CVE-2024-26000HIGH7.5An unauthenticated remote attacker can read memory out of bounds due to improper input validation in the MQTT stack. The...
CVE-2024-25999HIGH7.8An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent ...
CVE-2024-25998HIGH7.3An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to im...
CVE-2024-25997MEDIUM5.3An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file...
CVE-2024-25996CRITICAL9.8An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is ...
CVE-2024-25995CRITICAL9.8An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or per...
CVE-2024-25994MEDIUM5.3An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload desti...
CVE-2024-1328MEDIUM5.4The Newsletter2Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ parameter in all ver...
CVE-2024-0906MEDIUM5.3The f(x) Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in...
CVE-2024-27121HIGH7.2Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Seri...
CVE-2024-25325HIGH7.1SQL injection vulnerability in Employee Management System v.1.0 allows a local attacker to obtain sensitive information ...
CVE-2024-24964MEDIUM6.3Improper access control vulnerability exists in the resident process of SKYSEA Client View versions from Ver.11.220 prio...
CVE-2024-21805HIGH7.8Improper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior...
CVE-2024-21584MEDIUM6.1Pleasanter 1.3.49.0 and earlier contains a cross-site scripting vulnerability. If an attacker tricks the user to access ...
CVE-2024-25331CRITICAL9.3DIR-822 Rev. B Firmware v2.02KRB09 and DIR-822-CA Rev. B Firmware v2.03WWb01 suffer from a LAN-Side Unauthenticated Remo...
CVE-2024-26521MEDIUM4.8HTML Injection vulnerability in CE Phoenix v1.0.8.20 and before allows a remote attacker to execute arbitrary code, esca...
CVE-2024-28163MEDIUM5.3Under certain conditions, Support Web Pages of SAP NetWeaver Process Integration (PI) - versions 7.50, allows an attacke...
CVE-2024-27902MEDIUM6.1Applications based on SAP GUI for HTML in SAP NetWeaver AS ABAP - versions 7.89, 7.93, do not sufficiently encode user-c...
CVE-2024-27900MEDIUM5.3Due to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can cha...
CVE-2024-25645MEDIUM5.3Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which ...
CVE-2024-25644MEDIUM5.3Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwi...
CVE-2024-22133MEDIUM6.5SAP Fiori Front End Server - version 605, allows altering of approver details on the read-only field when sending leave ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now