2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37171 | MEDIUM | 5 | 0.4% | Jul 9, 2024 | SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a cra... |
| CVE-2024-34692 | MEDIUM | 4.6 | 0.2% | Jul 9, 2024 | Due to missing verification of file type or content, SAP Enable Now allows an authenticated attacker to upload arbitrary... |
| CVE-2024-34689 | MEDIUM | 5 | 0.4% | Jul 9, 2024 | WebFlow Services of SAP Business Workflow allows an authenticated attacker to enumerate accessible HTTP endpoints in the... |
| CVE-2024-39593 | MEDIUM | 5.7 | 0.3% | Jul 9, 2024 | SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definitio... |
| CVE-2024-39592 | MEDIUM | 6.5 | 0.4% | Jul 9, 2024 | Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of p... |
| CVE-2024-37174 | MEDIUM | 6.1 | 0.3% | Jul 9, 2024 | Custom CSS support option in SAP CRM WebClient UI does not sufficiently encode user-controlled inputs resulting in Cross... |
| CVE-2024-37173 | MEDIUM | 6.1 | 0.3% | Jul 9, 2024 | Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link whic... |
| CVE-2024-34685 | MEDIUM | 6.1 | 0.3% | Jul 9, 2024 | Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scr... |
| CVE-2024-5855 | MEDIUM | 4.3 | 0.4% | Jul 9, 2024 | The Media Hygiene: Remove or Delete Unused Images and More! plugin for WordPress is vulnerable to unauthorized loss of d... |
| CVE-2024-34786 | MEDIUM | 4.8 | 0.2% | Jul 9, 2024 | UniFi iOS app 10.15.0 introduces a misconfiguration on 2nd Generation UniFi Access Points configured as standalone (not ... |
| CVE-2024-22020 | MEDIUM | 6.5 | 1.1% | Jul 9, 2024 | A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URL... |
| CVE-2024-5569 | MEDIUM | 6.2 | 0.2% | Jul 9, 2024 | A Denial of Service (DoS) vulnerability exists in the jaraco/zipp library, affecting all versions prior to 3.19.1. The v... |
| CVE-2024-3653 | MEDIUM | 5.3 | 1.9% | Jul 8, 2024 | A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, wh... |
| CVE-2024-28882 | MEDIUM | 4.3 | 0.7% | Jul 8, 2024 | OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which ... |
| CVE-2024-6580 | MEDIUM | 6.5 | 0.1% | Jul 8, 2024 | The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path re... |
| CVE-2024-4882 | MEDIUM | 5.3 | 0.4% | Jul 8, 2024 | The user may be redirected to an arbitrary site in Sitefinity 15.1.8321.0 and previous versions. |
| CVE-2024-39896 | MEDIUM | 5.3 | 0.5% | Jul 8, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. When relying on SSO providers in combin... |
| CVE-2024-39895 | MEDIUM | 6.5 | 0.8% | Jul 8, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. A denial of service (DoS) attack by fie... |
| CVE-2024-39312 | MEDIUM | 5.3 | 0.3% | Jul 8, 2024 | Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier o... |
| CVE-2024-34702 | MEDIUM | 5.3 | 0.8% | Jul 8, 2024 | Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier o... |
| CVE-2024-6564 | MEDIUM | 6.7 | 0.2% | Jul 8, 2024 | Buffer overflow in "rcar_dev_init" due to using due to using untrusted data (rcar_image_number) as a loop counter befor... |
| CVE-2024-6563 | MEDIUM | 6.7 | 0.2% | Jul 8, 2024 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Renesas arm-trusted-firmware all... |
| CVE-2024-39699 | MEDIUM | 5 | 0.4% | Jul 8, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. There was already a reported SSRF vulne... |
| CVE-2024-39695 | MEDIUM | 6.5 | 0.6% | Jul 8, 2024 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file... |
| CVE-2024-39203 | MEDIUM | 6.1 | 0.7% | Jul 8, 2024 | A cross-site scripting (XSS) vulnerability in the Backend Theme Management module of Z-BlogPHP v1.7.3 allows attackers t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now