2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-26521MEDIUM4.8HTML Injection vulnerability in CE Phoenix v1.0.8.20 and before allows a remote attacker to execute arbitrary code, esca...
CVE-2024-28163MEDIUM5.3Under certain conditions, Support Web Pages of SAP NetWeaver Process Integration (PI) - versions 7.50, allows an attacke...
CVE-2024-27902MEDIUM6.1Applications based on SAP GUI for HTML in SAP NetWeaver AS ABAP - versions 7.89, 7.93, do not sufficiently encode user-c...
CVE-2024-27900MEDIUM5.3Due to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can cha...
CVE-2024-25645MEDIUM5.3Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which ...
CVE-2024-25644MEDIUM5.3Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwi...
CVE-2024-22133MEDIUM6.5SAP Fiori Front End Server - version 605, allows altering of approver details on the read-only field when sending leave ...
CVE-2024-28199MEDIUM6.1phlex is an open source framework for building object-oriented views in Ruby. There is a potential cross-site scripting ...
CVE-2024-27938MEDIUM5.3Postal is an open source SMTP server. Postal versions less than 3.0.0 are vulnerable to SMTP Smuggling attacks which may...
CVE-2024-27297MEDIUM5.9Nix is a package manager for Linux and other Unix systems. A fixed-output derivations on Linux can send file descriptors...
CVE-2024-25854MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Sourcecodester Insurance Management System 1.0 allows attackers to run arbit...
CVE-2024-25114MEDIUM5.3Collabora Online is a collaborative online office suite based on LibreOffice technology. Each document in Collabora Onli...
CVE-2024-1645MEDIUM4.3The Mollie Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on ...
CVE-2024-1400MEDIUM4.3The Mollie Forms plugin for WordPress is vulnerable to unauthorized post or page duplication due to a missing capability...
CVE-2024-2357MEDIUM6.5The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a...
CVE-2024-27237MEDIUM5.5In wipe_ns_memory of nsmemwipe.c, there is a possible incorrect size calculation due to a logic error in the code. This ...
CVE-2024-27235MEDIUM5.5In plugin_extern_func of , there is a possible out of bounds read due to a missing bounds check. This could lead to loca...
CVE-2024-27234MEDIUM5.9In fvp_set_target of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to loc...
CVE-2024-27230MEDIUM5.1In ProtocolPsKeepAliveStatusAdapter::getCode() of protocolpsadapter.cpp, there is a possible out of bounds read due to a...
CVE-2024-27225MEDIUM4.4In sendHciCommand of bluetooth_hci.cc, there is a possible out of bounds read due to a heap buffer overflow. This could ...
CVE-2024-27223MEDIUM5.1In EUTRAN_LCS_DecodeFacilityInformationElement of LPP_LcsManagement.c, there is a possible out of bounds read due to a m...
CVE-2024-27218MEDIUM5.5In update_freq_data of , there is a possible out of bounds read due to a missing bounds check. This could lead to local ...
CVE-2024-25990MEDIUM6.4In pktproc_perftest_gen_rx_packet_sktbuf_mode of link_rx_pktproc.c, there is a possible out of bounds write due to a rac...
CVE-2024-25989MEDIUM5.9In gpu_slc_liveness_update of pixel_gpu_slc.c, there is a possible out of bounds read due to a missing bounds check. Thi...
CVE-2024-25987MEDIUM6.7In pt_sysctl_command of pt.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now