2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-31404MEDIUM4.3Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.5.0 to 6.0.0, which may allow a user w...
CVE-2024-31403MEDIUM5.4Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 6.0.0 allows a remote authenticated attacker to alter an...
CVE-2024-31400MEDIUM6.5Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.0. If this vulnerability i...
CVE-2024-5090MEDIUM5.4The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's SiteOri...
CVE-2024-37176MEDIUM5.4SAP BW/4HANA Transformation and Data Transfer Process (DTP) allows an authenticated attacker to gain higher access level...
CVE-2024-34691MEDIUM6.5Manage Incoming Payment Files (F1680) of SAP S/4HANA does not perform necessary authorization checks for an authenticate...
CVE-2024-34690MEDIUM5.4SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading t...
CVE-2024-34686MEDIUM6.1Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which ...
CVE-2024-34684MEDIUM6On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administr...
CVE-2024-34683MEDIUM6.5An authenticated attacker can upload malicious file to SAP Document Builder service. When the victim accesses this file,...
CVE-2024-33001MEDIUM6.5SAP NetWeaver and ABAP platform allows an attacker to impede performance for legitimate users by crashing or flooding th...
CVE-2024-2473MEDIUM5.3The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9...
CVE-2024-28164MEDIUM5.3SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about...
CVE-2024-0653MEDIUM4.8The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve...
CVE-2024-0627MEDIUM5.4The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fiel...
CVE-2024-37178MEDIUM5SAP Financial Consolidation does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS)...
CVE-2024-22261MEDIUM5.5SQL-Injection in Harbor allows priviledge users to leak the task IDs
CVE-2024-22244MEDIUM6.1Open Redirect in Harbor  <=v2.8.4, <=v2.9.2, and <=v2.10.0 may redirect a user to a malicious site.
CVE-2024-37169MEDIUM5.3@jmondi/url-to-png is a self-hosted URL to PNG utility. Versions prior to 2.0.3 are vulnerable to arbitrary file read if...
CVE-2024-37168MEDIUM5.3@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to versions 1.1...
CVE-2024-36473MEDIUM5.3Trend Micro VPN Proxy One Pro, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite or create attack ...
CVE-2024-36419MEDIUM6.1SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability in versions prio...
CVE-2024-36359MEDIUM5.4A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 could all...
CVE-2024-36307MEDIUM5.5A security agent link following vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local atta...
CVE-2024-36306MEDIUM5.5A link following vulnerability in the Trend Micro Apex One and Apex One as a Service Damage Cleanup Engine could allow a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now