2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-38760MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in David Maucher Send Users Email allows Access...
CVE-2024-38756MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Weblizar Coming Soon allows Accessing Functi...
CVE-2024-38752MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zoho Campai...
CVE-2024-38742MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in MBE Worldwide S.P.A. MBE eShip allows Access...
CVE-2024-2259MEDIUM6.4This vulnerability exists in InstaRISPACS software due to insufficient validation of user supplied input for the loginTo...
CVE-2024-41978MEDIUM6.5A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM...
CVE-2024-41941MEDIUM4.3A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enfor...
CVE-2024-41907MEDIUM5.4A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected a...
CVE-2024-41906MEDIUM6.5A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected a...
CVE-2024-41905MEDIUM6.5A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected a...
CVE-2024-41683MEDIUM5.3A vulnerability has been identified in Location Intelligence family (All versions < V4.4). Affected products do not prop...
CVE-2024-41682MEDIUM5.3A vulnerability has been identified in Location Intelligence family (All versions < V4.4). Affected products do not prop...
CVE-2024-39922MEDIUM5.1A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD0...
CVE-2024-7715MEDIUM6.3** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-...
CVE-2024-7247MEDIUM5.4The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W...
CVE-2024-6724MEDIUM4.8The Generate Images WordPress plugin before 5.2.8 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-7092MEDIUM5.4The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress...
CVE-2024-42373MEDIUM5.4SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading t...
CVE-2024-41734MEDIUM4.3Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker...
CVE-2024-39591MEDIUM5.3SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escala...
CVE-2024-42377MEDIUM4.3SAP shared service framework allows an authenticated non-administrative user to call a remote-enabled function, which wi...
CVE-2024-42376MEDIUM6.5SAP Shared Service Framework does not perform necessary authorization check for an authenticated user, resulting in esca...
CVE-2024-42375MEDIUM4.3SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the ...
CVE-2024-41737MEDIUM5SAP CRM ABAP (Insights Management) allows an authenticated attacker to enumerate HTTP endpoints in the internal network ...
CVE-2024-41736MEDIUM4.3Under certain conditions SAP Permit to Work allows an authenticated attacker to access information which would otherwise...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now