2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-44113 | MEDIUM | 4.3 | 0.3% | Sep 10, 2024 | Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access in... |
| CVE-2024-42380 | MEDIUM | 4.3 | 0.3% | Sep 10, 2024 | The RFC enabled function module allows a low privileged user to read any user's workplace favourites and user menu along... |
| CVE-2024-42378 | MEDIUM | 6.1 | 0.2% | Sep 10, 2024 | Due to weak encoding of user-controlled inputs, eProcurement on SAP S/4HANA allows malicious scripts to be executed in t... |
| CVE-2024-42371 | MEDIUM | 5.4 | 0.3% | Sep 10, 2024 | The RFC enabled function module allows a low privileged user to delete the workplace favourites of any user. This vulner... |
| CVE-2024-41729 | MEDIUM | 4.3 | 0.3% | Sep 10, 2024 | Due to missing authorization checks, SAP BEx Analyzer allows an authenticated attacker to access information over the ne... |
| CVE-2024-38270 | MEDIUM | 6.5 | 0.2% | Sep 10, 2024 | An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authe... |
| CVE-2024-8610 | MEDIUM | 5.4 | 0.4% | Sep 9, 2024 | A vulnerability classified as problematic has been found in SourceCodester Best House Rental Management System 1.0. Affe... |
| CVE-2024-27365 | MEDIUM | 5.5 | 0.2% | Sep 9, 2024 | An issue was discovered in Samsung Mobile Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380... |
| CVE-2024-44085 | MEDIUM | 6.1 | 0.5% | Sep 9, 2024 | ONLYOFFICE Docs before 8.1.0 allows XSS via a GeneratorFunction Object attack against a macro. This is related to use of... |
| CVE-2024-27368 | MEDIUM | 5.5 | 0.2% | Sep 9, 2024 | An issue was discovered in Samsung Mobile Processor Exynos Mobile Processor, Wearable Processor Exynos 980, Exynos 850, ... |
| CVE-2024-27367 | MEDIUM | 5.5 | 0.2% | Sep 9, 2024 | An issue was discovered in Samsung Mobile Processor Exynos Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exyno... |
| CVE-2024-27366 | MEDIUM | 5.5 | 0.2% | Sep 9, 2024 | An issue was discovered in Samsung Mobile Processor, Wearable Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exyn... |
| CVE-2024-27364 | MEDIUM | 5.5 | 0.2% | Sep 9, 2024 | An issue was discovered in Mobile Processor, Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos... |
| CVE-2024-7318 | MEDIUM | 4.8 | 0.4% | Sep 9, 2024 | A vulnerability was found in Keycloak. Expired OTP codes are still usable when using FreeOTP when the OTP token period i... |
| CVE-2024-7260 | MEDIUM | 6.1 | 0.5% | Sep 9, 2024 | An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and ... |
| CVE-2024-42759 | MEDIUM | 6.3 | 0.4% | Sep 9, 2024 | An issue in Ellevo v.6.2.0.38160 allows a remote attacker to escalate privileges via the /api/usuario/cadastrodesuplente... |
| CVE-2024-24510 | MEDIUM | 6.1 | 0.5% | Sep 9, 2024 | Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via t... |
| CVE-2024-45406 | MEDIUM | 4.8 | 0.3% | Sep 9, 2024 | Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fie... |
| CVE-2024-8605 | MEDIUM | 5.4 | 0.5% | Sep 9, 2024 | A vulnerability classified as problematic was found in code-projects Inventory Management 1.0. This vulnerability affect... |
| CVE-2024-8604 | MEDIUM | 6.1 | 0.5% | Sep 9, 2024 | A vulnerability classified as problematic has been found in SourceCodester Online Food Ordering System 2.0. This affects... |
| CVE-2024-8373 | MEDIUM | 4.3 | 0.6% | Sep 9, 2024 | Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to ... |
| CVE-2024-8372 | MEDIUM | 4.3 | 0.6% | Sep 9, 2024 | Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source... |
| CVE-2024-8601 | MEDIUM | 6.5 | 0.5% | Sep 9, 2024 | This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on c... |
| CVE-2024-45203 | MEDIUM | 4.3 | 0.3% | Sep 9, 2024 | Improper authorization in handler for custom URL scheme issue in "@cosme" App for Android versions prior 5.69.0 and "@co... |
| CVE-2024-7918 | MEDIUM | 4.8 | 0.3% | Sep 9, 2024 | The Pocket Widget WordPress plugin through 0.1.3 does not sanitise and escape some of its settings, which could allow hi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now