2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11945MEDIUM6.4The Email Reminders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all vers...
CVE-2024-8256MEDIUM5.9In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices running on versions 1....
CVE-2024-45709MEDIUM5.5SolarWinds Web Help Desk was susceptible to a local file read vulnerability. This vulnerability requires the software b...
CVE-2024-11940MEDIUM6.4The Property Hive Mortgage Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘price’ ...
CVE-2024-47946HIGH7.2If the attacker has access to a valid Poweruser session, remote code execution is possible because specially crafted val...
CVE-2024-28138HIGH7.3An unauthenticated attacker with network access to the affected device's web interface can execute any system command vi...
CVE-2024-11107MEDIUM6.1The System Dashboard WordPress plugin before 2.8.15 does not sanitise and escape some parameters when outputting them in...
CVE-2024-10708MEDIUM4.9The System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path, which could allow high ...
CVE-2024-21542HIGH8.6Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due ...
CVE-2024-11205MEDIUM6.5The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on...
CVE-2024-37144MEDIUM6.7Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8....
CVE-2024-37143CRITICAL9.8Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8....
CVE-2024-53919HIGH7.6An injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core models, running firmwar...
CVE-2024-53552CRITICAL9.8CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.
CVE-2024-54198HIGH8.5In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function...
CVE-2024-54197HIGH7.2SAP NetWeaver Administrator(System Overview) allows an authenticated attacker to enumerate accessible HTTP endpoints in ...
CVE-2024-47585MEDIUM4.3SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to gain higher access level...
CVE-2024-47582MEDIUM5.3Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which lead...
CVE-2024-47581MEDIUM4.3SAP HCM Approve Timesheets Version 4 application does not perform necessary authorization checks for an authenticated us...
CVE-2024-47580MEDIUM6.8An attacker authenticated as an administrator can use an exposed webservice to create a PDF with an embedded attachment....
CVE-2024-47579MEDIUM6.8An attacker authenticated as an administrator can use an exposed webservice to upload or download a custom PDF font file...
CVE-2024-47578CRITICAL9.1Adobe Document Service allows an attacker with administrator privileges to send a crafted request from a vulnerable web ...
CVE-2024-47577LOW2.7Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information disclosure vulnerability....
CVE-2024-47576LOW3.3SAP Product Lifecycle Costing Client (versions below 4.7.1) application loads on demand a DLL that is available with Win...
CVE-2024-32732MEDIUM5.3Under certain conditions SAP BusinessObjects Business Intelligence platform allows an attacker to access information whi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now