2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-20685MEDIUM5.9Azure Private 5G Core Denial of Service Vulnerability
CVE-2024-20669MEDIUM6.7Secure Boot Security Feature Bypass Vulnerability
CVE-2024-20665MEDIUM6.7BitLocker Security Feature Bypass Vulnerability
CVE-2024-31868MEDIUM6.1Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and expo...
CVE-2024-31865MEDIUM6.5Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or im...
CVE-2024-28235MEDIUM6.5Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, w...
CVE-2024-31487MEDIUM6.5A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox ...
CVE-2024-28234MEDIUM4.7Contao is an open source content management system. Starting in version 2.0.0 and prior to versions 4.13.40 and 5.3.4, i...
CVE-2024-28191MEDIUM5.4Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, it...
CVE-2024-28190MEDIUM5.4Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, us...
CVE-2024-31544MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Computer Laboratory Management System v1.0 allows attackers to exec...
CVE-2024-31863MEDIUM5.3Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apa...
CVE-2024-31862MEDIUM5.3Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affect...
CVE-2024-31860MEDIUM6.5Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can s...
CVE-2024-31369MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4....
CVE-2024-31368MEDIUM6.5Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2.
CVE-2024-30190MEDIUM6.1A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0T...
CVE-2024-30189MEDIUM6.1A vulnerability has been identified in SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0) (All versions), SCALANCE W721-1 RJ45 (6...
CVE-2024-26277MEDIUM4.8A vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Pa...
CVE-2024-26276MEDIUM5.5A vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Pa...
CVE-2024-1664MEDIUM6.1The Responsive Gallery Grid WordPress plugin before 2.3.11 does not sanitise and escape some of its settings, which coul...
CVE-2024-30218MEDIUM6.5The ABAP Application Server of SAP NetWeaver as well as ABAP Platform allows an attacker to prevent legitimate users fro...
CVE-2024-30217MEDIUM4.3Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in ...
CVE-2024-30216MEDIUM4.3Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in ...
CVE-2024-30215MEDIUM4.8The Resource Settings page allows a high privilege attacker to load exploitable payload to be stored and reflected whene...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now