2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-47565MEDIUM4.3A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not...
CVE-2024-47563MEDIUM5.3A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not...
CVE-2024-46887MEDIUM6.9The web server of affected devices do not properly authenticate user request to the '/ClientArea/RuntimeInfoData.mwsl' e...
CVE-2024-46886MEDIUM5.1The web server of affected devices does not properly validate input that is used for a user redirection. This could allo...
CVE-2024-8964MEDIUM5.4The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG Fi...
CVE-2024-47095MEDIUM5.1Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run...
CVE-2024-34671MEDIUM5.5Use of implicit intent for sensitive communication in translation혻in Samsung Internet prior to version 26.0.3.1 allows l...
CVE-2024-34670MEDIUM5.5Use of implicit intent for sensitive communication in Sound Assistant prior to version 6.1.0.9 allows local attackers to...
CVE-2024-34663MEDIUM5.5Integer overflow in libSEF.quram.so prior to SMR Oct-2024 Release 1 allows local attackers to write out-of-bounds memory...
CVE-2024-9292MEDIUM6.4The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortcode in versions...
CVE-2024-9021MEDIUM5.4In the process of testing the Relevanssi WordPress plugin before 4.23.1, a vulnerability was found that allows you to i...
CVE-2024-8983MEDIUM4.8Custom Twitter Feeds WordPress plugin before 2.2.3 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-21533MEDIUM6.5All versions of the package ggit are vulnerable to Arbitrary Argument Injection via the clone() API, which allows specif...
CVE-2024-8925MEDIUM5.3In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data ...
CVE-2024-47594MEDIUM5.4SAP NetWeaver Enterprise Portal (KMC) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scrip...
CVE-2024-45382MEDIUM5.5in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through out-of-bounds write.
CVE-2024-45282MEDIUM5.3Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified b...
CVE-2024-45278MEDIUM5.4SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vul...
CVE-2024-45277MEDIUM4.3The SAP HANA Node.js client package versions from 2.0.0 before 2.21.31 is impacted by Prototype Pollution vulnerability ...
CVE-2024-43697MEDIUM5.5in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through improper input.
CVE-2024-43696MEDIUM5.5in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS by memory leak.
CVE-2024-39831MEDIUM6.7in OpenHarmony v4.1.0 allow a local attacker with high privileges arbitrary code execution in pre-installed apps through...
CVE-2024-39806MEDIUM5.5in OpenHarmony v4.1.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
CVE-2024-37179MEDIUM6.5SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to t...
CVE-2024-47969MEDIUM6.2Improper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially enable denial...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now