2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22131 | HIGH | 7.2 | 1.1% | Feb 13, 2024 | In SAP ABA (Application Basis) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75I, an attacker authenticated as... |
| CVE-2024-22130 | MEDIUM | 5.4 | 0.3% | Feb 13, 2024 | Print preview option in SAP CRM WebClient UI - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107... |
| CVE-2024-22128 | MEDIUM | 6.1 | 0.4% | Feb 13, 2024 | SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702... |
| CVE-2024-22126 | MEDIUM | 6.1 | 0.5% | Feb 13, 2024 | The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes ... |
| CVE-2024-25407 | HIGH | 7.5 | 0.6% | Feb 13, 2024 | SteVe v3.6.0 was discovered to use predictable transaction ID's when receiving a StartTransaction request. This vulnerab... |
| CVE-2024-25112 | MEDIUM | 5 | 0.2% | Feb 12, 2024 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file... |
| CVE-2024-24826 | MEDIUM | 5 | 0.2% | Feb 12, 2024 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file... |
| CVE-2024-1454 | LOW | 3.4 | 0.4% | Feb 12, 2024 | The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment pr... |
| CVE-2024-24337 | HIGH | 8 | 0.8% | Feb 12, 2024 | CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management S... |
| CVE-2024-23763 | CRITICAL | 9.8 | 0.6% | Feb 12, 2024 | SQL Injection vulnerability in Gambio through 4.9.2.0 allows attackers to run arbitrary SQL commands via crafted GET req... |
| CVE-2024-23762 | HIGH | 7.8 | 0.3% | Feb 12, 2024 | Unrestricted File Upload vulnerability in Content Manager feature in Gambio 4.9.2.0 allows attackers to execute arbitrar... |
| CVE-2024-23761 | CRITICAL | 9.8 | 0.7% | Feb 12, 2024 | Server Side Template Injection in Gambio 4.9.2.0 allows attackers to run arbitrary code via crafted smarty email templat... |
| CVE-2024-23760 | LOW | 2.7 | 0.4% | Feb 12, 2024 | Cleartext Storage of Sensitive Information in Gambio 4.9.2.0 allows attackers to obtain sensitive information via error-... |
| CVE-2024-23759 | CRITICAL | 9.8 | 47.8% | Feb 12, 2024 | Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" paramete... |
| CVE-2024-23833 | HIGH | 7.5 | 1.0% | Feb 12, 2024 | OpenRefine is a free, open source power tool for working with messy data and improving it. A jdbc attack vulnerability e... |
| CVE-2024-1459 | MEDIUM | 5.3 | 1.7% | Feb 12, 2024 | A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-craft... |
| CVE-2024-1250 | MEDIUM | 6.5 | 0.5% | Feb 12, 2024 | An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assign... |
| CVE-2024-25110 | HIGH | 8.1 | 6.6% | Feb 12, 2024 | The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocati... |
| CVE-2024-25108 | HIGH | 8.8 | 0.7% | Feb 12, 2024 | Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficien... |
| CVE-2024-22230 | MEDIUM | 5.4 | 0.3% | Feb 12, 2024 | Dell Unity, versions prior to 5.4, contains a Cross-site scripting vulnerability. An authenticated attacker could poten... |
| CVE-2024-22228 | HIGH | 7.8 | 0.6% | Feb 12, 2024 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cifssupport utility. An au... |
| CVE-2024-22227 | HIGH | 7.8 | 0.6% | Feb 12, 2024 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_dc utility. An authenticat... |
| CVE-2024-22226 | MEDIUM | 6.5 | 0.4% | Feb 12, 2024 | Dell Unity, versions prior to 5.4, contain a path traversal vulnerability in its svc_supportassist utility. An authenti... |
| CVE-2024-22225 | HIGH | 7.8 | 1.0% | Feb 12, 2024 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_supportassist utility. An ... |
| CVE-2024-22224 | HIGH | 7.8 | 0.9% | Feb 12, 2024 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_nas utility. An authentica... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now