2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31404 | MEDIUM | 4.3 | 0.3% | Jun 11, 2024 | Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.5.0 to 6.0.0, which may allow a user w... |
| CVE-2024-31403 | MEDIUM | 5.4 | 0.3% | Jun 11, 2024 | Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 6.0.0 allows a remote authenticated attacker to alter an... |
| CVE-2024-31400 | MEDIUM | 6.5 | 0.3% | Jun 11, 2024 | Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.0. If this vulnerability i... |
| CVE-2024-5090 | MEDIUM | 5.4 | 0.3% | Jun 11, 2024 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's SiteOri... |
| CVE-2024-37176 | MEDIUM | 5.4 | 0.3% | Jun 11, 2024 | SAP BW/4HANA Transformation and Data Transfer Process (DTP) allows an authenticated attacker to gain higher access level... |
| CVE-2024-34691 | MEDIUM | 6.5 | 0.3% | Jun 11, 2024 | Manage Incoming Payment Files (F1680) of SAP S/4HANA does not perform necessary authorization checks for an authenticate... |
| CVE-2024-34690 | MEDIUM | 5.4 | 0.2% | Jun 11, 2024 | SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading t... |
| CVE-2024-34686 | MEDIUM | 6.1 | 0.3% | Jun 11, 2024 | Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which ... |
| CVE-2024-34684 | MEDIUM | 6 | 0.1% | Jun 11, 2024 | On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administr... |
| CVE-2024-34683 | MEDIUM | 6.5 | 0.2% | Jun 11, 2024 | An authenticated attacker can upload malicious file to SAP Document Builder service. When the victim accesses this file,... |
| CVE-2024-33001 | MEDIUM | 6.5 | 0.4% | Jun 11, 2024 | SAP NetWeaver and ABAP platform allows an attacker to impede performance for legitimate users by crashing or flooding th... |
| CVE-2024-2473 | MEDIUM | 5.3 | 1.2% | Jun 11, 2024 | The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9... |
| CVE-2024-28164 | MEDIUM | 5.3 | 0.3% | Jun 11, 2024 | SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about... |
| CVE-2024-0653 | MEDIUM | 4.8 | 0.2% | Jun 11, 2024 | The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve... |
| CVE-2024-0627 | MEDIUM | 5.4 | 0.3% | Jun 11, 2024 | The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fiel... |
| CVE-2024-37178 | MEDIUM | 5 | 0.3% | Jun 11, 2024 | SAP Financial Consolidation does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS)... |
| CVE-2024-22261 | MEDIUM | 5.5 | 0.4% | Jun 11, 2024 | SQL-Injection in Harbor allows priviledge users to leak the task IDs |
| CVE-2024-22244 | MEDIUM | 6.1 | 0.4% | Jun 10, 2024 | Open Redirect in Harbor <=v2.8.4, <=v2.9.2, and <=v2.10.0 may redirect a user to a malicious site. |
| CVE-2024-37169 | MEDIUM | 5.3 | 0.5% | Jun 10, 2024 | @jmondi/url-to-png is a self-hosted URL to PNG utility. Versions prior to 2.0.3 are vulnerable to arbitrary file read if... |
| CVE-2024-37168 | MEDIUM | 5.3 | 0.7% | Jun 10, 2024 | @grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to versions 1.1... |
| CVE-2024-36473 | MEDIUM | 5.3 | 0.2% | Jun 10, 2024 | Trend Micro VPN Proxy One Pro, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite or create attack ... |
| CVE-2024-36419 | MEDIUM | 6.1 | 0.2% | Jun 10, 2024 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability in versions prio... |
| CVE-2024-36359 | MEDIUM | 5.4 | 0.4% | Jun 10, 2024 | A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 could all... |
| CVE-2024-36307 | MEDIUM | 5.5 | 0.8% | Jun 10, 2024 | A security agent link following vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local atta... |
| CVE-2024-36306 | MEDIUM | 5.5 | 0.6% | Jun 10, 2024 | A link following vulnerability in the Trend Micro Apex One and Apex One as a Service Damage Cleanup Engine could allow a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now