2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-7734MEDIUM5.3An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing ...
CVE-2024-7655MEDIUM4.8The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to ...
CVE-2024-7618MEDIUM4.8The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to ...
CVE-2024-42424MEDIUM6Dell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Improper Input Validation vulnerability. A hig...
CVE-2024-44072MEDIUM5.7OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in ...
CVE-2024-7955MEDIUM4.8The Starbox WordPress plugin before 3.5.2 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2024-7891MEDIUM4.8The Floating Contact Button WordPress plugin before 2.8 does not sanitise and escape some of its settings, which could a...
CVE-2024-7784MEDIUM6.1During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device t...
CVE-2024-6509MEDIUM6.5Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API alwaysmulti.cgi was vulnerable for fil...
CVE-2024-6173MEDIUM6.551l3nc3, member of the AXIS OS Bug Bounty Program, has found that a Guard Tour VAPIX API parameter allowed the use of ar...
CVE-2024-45504MEDIUM6.5Cross-site request forgery (CSRF) vulnerability in multiple Alps System Integration products and the OEM products allow ...
CVE-2024-45285MEDIUM5.4The RFC enabled function module allows a low privileged user to perform denial of service on any user and also change or...
CVE-2024-45283MEDIUM6SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The attacker could obtain the u...
CVE-2024-45281MEDIUM5.8SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even ...
CVE-2024-45280MEDIUM4.8Due to insufficient encoding of user-controlled inputs, SAP NetWeaver AS Java allows malicious scripts to be executed in...
CVE-2024-45279MEDIUM6.1Due to insufficient input validation, CRM Blueprint Application Builder Panel of SAP NetWeaver Application Server for AB...
CVE-2024-44121MEDIUM4.3Under certain conditions Statutory Reports in SAP S/4 HANA allows an attacker with basic privileges to access informatio...
CVE-2024-44120MEDIUM4.7SAP NetWeaver Enterprise Portal is vulnerable to reflected cross site scripting due to insufficient encoding of user-con...
CVE-2024-44117MEDIUM5.4The RFC enabled function module allows a low privileged user to perform various actions, such as modifying the URLs of a...
CVE-2024-21528MEDIUM5.9All versions of the package node-gettext are vulnerable to Prototype Pollution via the addTranslations() function in get...
CVE-2024-0067MEDIUM4.3Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API ledlimit.cgi was vulnerable for path t...
CVE-2024-45286MEDIUM6.5Due to lack of proper authorization checks when calling user, a function module in obsolete Tobin interface in SAP Produ...
CVE-2024-44112MEDIUM4.3Due to missing authorization check in SAP for Oil & Gas (Transportation and Distribution), an attacker authenticated as ...
CVE-2024-44116MEDIUM4.3The RFC enabled function module allows a low privileged user to add any workbook to any user's workplace favourites. Thi...
CVE-2024-44115MEDIUM4.3The RFC enabled function module allows a low privileged user to add URLs to any user's workplace favourites. This vulner...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now