2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-22131HIGH7.2In SAP ABA (Application Basis) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75I, an attacker authenticated as...
CVE-2024-22130MEDIUM5.4Print preview option in SAP CRM WebClient UI - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107...
CVE-2024-22128MEDIUM6.1SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702...
CVE-2024-22126MEDIUM6.1The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes ...
CVE-2024-25407HIGH7.5SteVe v3.6.0 was discovered to use predictable transaction ID's when receiving a StartTransaction request. This vulnerab...
CVE-2024-25112MEDIUM5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2024-24826MEDIUM5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2024-1454LOW3.4The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment pr...
CVE-2024-24337HIGH8CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management S...
CVE-2024-23763CRITICAL9.8SQL Injection vulnerability in Gambio through 4.9.2.0 allows attackers to run arbitrary SQL commands via crafted GET req...
CVE-2024-23762HIGH7.8Unrestricted File Upload vulnerability in Content Manager feature in Gambio 4.9.2.0 allows attackers to execute arbitrar...
CVE-2024-23761CRITICAL9.8Server Side Template Injection in Gambio 4.9.2.0 allows attackers to run arbitrary code via crafted smarty email templat...
CVE-2024-23760LOW2.7Cleartext Storage of Sensitive Information in Gambio 4.9.2.0 allows attackers to obtain sensitive information via error-...
CVE-2024-23759CRITICAL9.8Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" paramete...
CVE-2024-23833HIGH7.5OpenRefine is a free, open source power tool for working with messy data and improving it. A jdbc attack vulnerability e...
CVE-2024-1459MEDIUM5.3A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-craft...
CVE-2024-1250MEDIUM6.5An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assign...
CVE-2024-25110HIGH8.1The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocati...
CVE-2024-25108HIGH8.8Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficien...
CVE-2024-22230MEDIUM5.4 Dell Unity, versions prior to 5.4, contains a Cross-site scripting vulnerability. An authenticated attacker could poten...
CVE-2024-22228HIGH7.8 Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cifssupport utility. An au...
CVE-2024-22227HIGH7.8 Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_dc utility. An authenticat...
CVE-2024-22226MEDIUM6.5 Dell Unity, versions prior to 5.4, contain a path traversal vulnerability in its svc_supportassist utility. An authenti...
CVE-2024-22225HIGH7.8 Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_supportassist utility. An ...
CVE-2024-22224HIGH7.8 Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_nas utility. An authentica...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now