2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-30214 | MEDIUM | 4.8 | 0.3% | Apr 9, 2024 | The application allows a high privilege attacker to append a malicious GET query parameter to Service invocations, which... |
| CVE-2024-28167 | MEDIUM | 6.5 | 0.4% | Apr 9, 2024 | SAP Group Reporting Data Collection does not perform necessary authorization checks for an authenticated user, resulting... |
| CVE-2024-27898 | MEDIUM | 5.3 | 0.4% | Apr 9, 2024 | SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vul... |
| CVE-2024-25646 | MEDIUM | 6.5 | 0.4% | Apr 9, 2024 | Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to acce... |
| CVE-2024-23584 | MEDIUM | 6.6 | 0.3% | Apr 8, 2024 | The NMAP Importer service may expose data store credentials to authorized users of the Windows Registry. |
| CVE-2024-23079 | MEDIUM | 6.2 | 0.2% | Apr 8, 2024 | JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDou... |
| CVE-2024-0083 | MEDIUM | 6.5 | 0.6% | Apr 8, 2024 | NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause a cross-site scripting error ... |
| CVE-2024-27631 | MEDIUM | 6 | 0.4% | Apr 8, 2024 | Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges... |
| CVE-2024-3463 | MEDIUM | 5.4 | 0.5% | Apr 8, 2024 | A vulnerability has been found in SourceCodester Laundry Management System 1.0 and classified as problematic. This vulne... |
| CVE-2024-28224 | MEDIUM | 6.6 | 0.3% | Apr 8, 2024 | Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, there... |
| CVE-2024-31447 | MEDIUM | 5.3 | 0.5% | Apr 8, 2024 | Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Starting in version 6.3.5.0 and prior to ver... |
| CVE-2024-3444 | MEDIUM | 4.7 | 0.5% | Apr 8, 2024 | A vulnerability was found in Wangshen SecGate 3600 up to 20240408. It has been classified as critical. This affects an u... |
| CVE-2024-3443 | MEDIUM | 5.4 | 0.5% | Apr 8, 2024 | A vulnerability classified as problematic was found in SourceCodester Prison Management System 1.0. This vulnerability a... |
| CVE-2024-31221 | MEDIUM | 5.9 | 0.5% | Apr 8, 2024 | Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after ... |
| CVE-2024-31205 | MEDIUM | 5.4 | 0.2% | Apr 8, 2024 | Saleor is an e-commerce platform. Starting in version 3.10.0 and prior to versions 3.14.64, 3.15.39, 3.16.39, 3.17.35, 3... |
| CVE-2024-30269 | MEDIUM | 5.3 | 16.0% | Apr 8, 2024 | DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnera... |
| CVE-2024-2511 | MEDIUM | 5.9 | 54.0% | Apr 8, 2024 | Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sess... |
| CVE-2024-31812 | MEDIUM | 6.5 | 0.3% | Apr 8, 2024 | In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the... |
| CVE-2024-31806 | MEDIUM | 6.5 | 0.4% | Apr 8, 2024 | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSys... |
| CVE-2024-31805 | MEDIUM | 6.5 | 0.5% | Apr 8, 2024 | TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_... |
| CVE-2024-26811 | MEDIUM | 5.5 | 0.3% | Apr 8, 2024 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate payload size in ipc response If in... |
| CVE-2024-31375 | MEDIUM | 5.4 | 0.4% | Apr 8, 2024 | Missing Authorization vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads.This issue affects WP2LEADS: from n/a ... |
| CVE-2024-31357 | MEDIUM | 6.5 | 0.4% | Apr 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Ultimate ... |
| CVE-2024-23192 | MEDIUM | 6.1 | 0.5% | Apr 8, 2024 | RSS feeds that contain malicious data- attributes could be abused to inject script code to a users browser session when ... |
| CVE-2024-23191 | MEDIUM | 5.4 | 0.5% | Apr 8, 2024 | Upsell advertisement information of an account can be manipulated to execute script code in the context of the users bro... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now