2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-30214MEDIUM4.8The application allows a high privilege attacker to append a malicious GET query parameter to Service invocations, which...
CVE-2024-28167MEDIUM6.5SAP Group Reporting Data Collection does not perform necessary authorization checks for an authenticated user, resulting...
CVE-2024-27898MEDIUM5.3SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vul...
CVE-2024-25646MEDIUM6.5Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to acce...
CVE-2024-23584MEDIUM6.6The NMAP Importer service​ may expose data store credentials to authorized users of the Windows Registry.
CVE-2024-23079MEDIUM6.2JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDou...
CVE-2024-0083MEDIUM6.5NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause a cross-site scripting error ...
CVE-2024-27631MEDIUM6Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges...
CVE-2024-3463MEDIUM5.4A vulnerability has been found in SourceCodester Laundry Management System 1.0 and classified as problematic. This vulne...
CVE-2024-28224MEDIUM6.6Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, there...
CVE-2024-31447MEDIUM5.3Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Starting in version 6.3.5.0 and prior to ver...
CVE-2024-3444MEDIUM4.7A vulnerability was found in Wangshen SecGate 3600 up to 20240408. It has been classified as critical. This affects an u...
CVE-2024-3443MEDIUM5.4A vulnerability classified as problematic was found in SourceCodester Prison Management System 1.0. This vulnerability a...
CVE-2024-31221MEDIUM5.9Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after ...
CVE-2024-31205MEDIUM5.4Saleor is an e-commerce platform. Starting in version 3.10.0 and prior to versions 3.14.64, 3.15.39, 3.16.39, 3.17.35, 3...
CVE-2024-30269MEDIUM5.3DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnera...
CVE-2024-2511MEDIUM5.9Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sess...
CVE-2024-31812MEDIUM6.5In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the...
CVE-2024-31806MEDIUM6.5TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSys...
CVE-2024-31805MEDIUM6.5TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_...
CVE-2024-26811MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate payload size in ipc response If in...
CVE-2024-31375MEDIUM5.4Missing Authorization vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads.This issue affects WP2LEADS: from n/a ...
CVE-2024-31357MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Ultimate ...
CVE-2024-23192MEDIUM6.1RSS feeds that contain malicious data- attributes could be abused to inject script code to a users browser session when ...
CVE-2024-23191MEDIUM5.4Upsell advertisement information of an account can be manipulated to execute script code in the context of the users bro...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now