2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-44113MEDIUM4.3Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access in...
CVE-2024-42380MEDIUM4.3The RFC enabled function module allows a low privileged user to read any user's workplace favourites and user menu along...
CVE-2024-42378MEDIUM6.1Due to weak encoding of user-controlled inputs, eProcurement on SAP S/4HANA allows malicious scripts to be executed in t...
CVE-2024-42371MEDIUM5.4The RFC enabled function module allows a low privileged user to delete the workplace favourites of any user. This vulner...
CVE-2024-41729MEDIUM4.3Due to missing authorization checks, SAP BEx Analyzer allows an authenticated attacker to access information over the ne...
CVE-2024-38270MEDIUM6.5An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authe...
CVE-2024-8610MEDIUM5.4A vulnerability classified as problematic has been found in SourceCodester Best House Rental Management System 1.0. Affe...
CVE-2024-27365MEDIUM5.5An issue was discovered in Samsung Mobile Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380...
CVE-2024-44085MEDIUM6.1ONLYOFFICE Docs before 8.1.0 allows XSS via a GeneratorFunction Object attack against a macro. This is related to use of...
CVE-2024-27368MEDIUM5.5An issue was discovered in Samsung Mobile Processor Exynos Mobile Processor, Wearable Processor Exynos 980, Exynos 850, ...
CVE-2024-27367MEDIUM5.5An issue was discovered in Samsung Mobile Processor Exynos Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exyno...
CVE-2024-27366MEDIUM5.5An issue was discovered in Samsung Mobile Processor, Wearable Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exyn...
CVE-2024-27364MEDIUM5.5An issue was discovered in Mobile Processor, Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos...
CVE-2024-7318MEDIUM4.8A vulnerability was found in Keycloak. Expired OTP codes are still usable when using FreeOTP when the OTP token period i...
CVE-2024-7260MEDIUM6.1An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and ...
CVE-2024-42759MEDIUM6.3An issue in Ellevo v.6.2.0.38160 allows a remote attacker to escalate privileges via the /api/usuario/cadastrodesuplente...
CVE-2024-24510MEDIUM6.1Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via t...
CVE-2024-45406MEDIUM4.8Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fie...
CVE-2024-8605MEDIUM5.4A vulnerability classified as problematic was found in code-projects Inventory Management 1.0. This vulnerability affect...
CVE-2024-8604MEDIUM6.1A vulnerability classified as problematic has been found in SourceCodester Online Food Ordering System 2.0. This affects...
CVE-2024-8373MEDIUM4.3Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to ...
CVE-2024-8372MEDIUM4.3Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source...
CVE-2024-8601MEDIUM6.5This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on c...
CVE-2024-45203MEDIUM4.3Improper authorization in handler for custom URL scheme issue in "@cosme" App for Android versions prior 5.69.0 and "@co...
CVE-2024-7918MEDIUM4.8The Pocket Widget WordPress plugin through 0.1.3 does not sanitise and escape some of its settings, which could allow hi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now