2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-37171MEDIUM5SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a cra...
CVE-2024-34692MEDIUM4.6Due to missing verification of file type or content, SAP Enable Now allows an authenticated attacker to upload arbitrary...
CVE-2024-34689MEDIUM5WebFlow Services of SAP Business Workflow allows an authenticated attacker to enumerate accessible HTTP endpoints in the...
CVE-2024-39593MEDIUM5.7SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definitio...
CVE-2024-39592MEDIUM6.5Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of p...
CVE-2024-37174MEDIUM6.1Custom CSS support option in SAP CRM WebClient UI does not sufficiently encode user-controlled inputs resulting in Cross...
CVE-2024-37173MEDIUM6.1Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link whic...
CVE-2024-34685MEDIUM6.1Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scr...
CVE-2024-5855MEDIUM4.3The Media Hygiene: Remove or Delete Unused Images and More! plugin for WordPress is vulnerable to unauthorized loss of d...
CVE-2024-34786MEDIUM4.8UniFi iOS app 10.15.0 introduces a misconfiguration on 2nd Generation UniFi Access Points configured as standalone (not ...
CVE-2024-22020MEDIUM6.5A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URL...
CVE-2024-5569MEDIUM6.2A Denial of Service (DoS) vulnerability exists in the jaraco/zipp library, affecting all versions prior to 3.19.1. The v...
CVE-2024-3653MEDIUM5.3A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, wh...
CVE-2024-28882MEDIUM4.3OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which ...
CVE-2024-6580MEDIUM6.5The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path re...
CVE-2024-4882MEDIUM5.3The user may be redirected to an arbitrary site in Sitefinity 15.1.8321.0 and previous versions.
CVE-2024-39896MEDIUM5.3Directus is a real-time API and App dashboard for managing SQL database content. When relying on SSO providers in combin...
CVE-2024-39895MEDIUM6.5Directus is a real-time API and App dashboard for managing SQL database content. A denial of service (DoS) attack by fie...
CVE-2024-39312MEDIUM5.3Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier o...
CVE-2024-34702MEDIUM5.3Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier o...
CVE-2024-6564MEDIUM6.7Buffer overflow in "rcar_dev_init" due to using due to using untrusted data (rcar_image_number) as a loop counter befor...
CVE-2024-6563MEDIUM6.7Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Renesas arm-trusted-firmware all...
CVE-2024-39699MEDIUM5Directus is a real-time API and App dashboard for managing SQL database content. There was already a reported SSRF vulne...
CVE-2024-39695MEDIUM6.5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2024-39203MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Backend Theme Management module of Z-BlogPHP v1.7.3 allows attackers t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now