2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-33498MEDIUM6.9A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC ...
CVE-2024-33497MEDIUM6.3A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC ...
CVE-2024-33496MEDIUM6.3A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC ...
CVE-2024-33494MEDIUM6.9A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC ...
CVE-2024-33009MEDIUM4.2SAP Global Label Management is vulnerable to SQL injection. On exploitation the attacker can use specially crafted input...
CVE-2024-33008MEDIUM4.9SAP Replication Server allows an attacker to use gateway for executing some commands to RSSD. This could result in crash...
CVE-2024-33004MEDIUM4.3SAP Business Objects Business Intelligence Platform is vulnerable to Insecure Storage as dynamic web pages are getting c...
CVE-2024-33002MEDIUM6.1Document Service handler (obsolete) in Data Provisioning Service does not sufficiently encode user-controlled inputs, re...
CVE-2024-32733MEDIUM6.1 Due to missing input validation and output encoding of untrusted data, SAP NetWeaver Application Server ABAP and ABAP P...
CVE-2024-32731MEDIUM5.5 SAP My Travel Requests does not perform necessary authorization checks for an authenticated user, resulting in escalati...
CVE-2024-32637MEDIUM5.5A vulnerability has been identified in JT2Go (All versions < V2312.0005), Teamcenter Visualization V14.2 (All versions <...
CVE-2024-32354MEDIUM6TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'timeout' pa...
CVE-2024-32349MEDIUM6TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulner...
CVE-2024-32077MEDIUM5.4Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the...
CVE-2024-31486MEDIUM6A vulnerability has been identified in OPUPI0 AMQP/MQTT (All versions < V5.30). The affected devices stores MQTT client ...
CVE-2024-30208MEDIUM6.3A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC ...
CVE-2024-28135MEDIUM5A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code executi...
CVE-2024-27947MEDIUM5.3A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems could allow log me...
CVE-2024-27946MEDIUM6.5A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). Downloading files overwrites files with...
CVE-2024-26367MEDIUM6.1Cross Site Scripting vulnerability in Evertz microsystems MViP-II Firmware 8.6.5, XPS-EDGE-* Build 1467, evEDGE-EO-* Bui...
CVE-2024-25970MEDIUM6.5Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an improper input validation vulnerability. A low privileg...
CVE-2024-25969MEDIUM5.5Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an allocation of resources without limits or throttling vu...
CVE-2024-25967MEDIUM6.7Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an execution with unnecessary privileges vulnerability. A ...
CVE-2024-25965MEDIUM4.4Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an external control of file name or path vulnerability. A ...
CVE-2024-22270MEDIUM6VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) func...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now