2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7784MEDIUM6.1During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device t...
CVE-2024-6979HIGH7.5Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-pri...
CVE-2024-6509MEDIUM6.5Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API alwaysmulti.cgi was vulnerable for fil...
CVE-2024-6173MEDIUM6.551l3nc3, member of the AXIS OS Bug Bounty Program, has found that a Guard Tour VAPIX API parameter allowed the use of ar...
CVE-2024-45504MEDIUM6.5Cross-site request forgery (CSRF) vulnerability in multiple Alps System Integration products and the OEM products allow ...
CVE-2024-45285MEDIUM5.4The RFC enabled function module allows a low privileged user to perform denial of service on any user and also change or...
CVE-2024-45284LOW2.4An authenticated attacker with high privilege can use functions of SLCM transactions to which access should be restricte...
CVE-2024-45283MEDIUM6SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The attacker could obtain the u...
CVE-2024-45281MEDIUM5.8SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even ...
CVE-2024-45280MEDIUM4.8Due to insufficient encoding of user-controlled inputs, SAP NetWeaver AS Java allows malicious scripts to be executed in...
CVE-2024-45279MEDIUM6.1Due to insufficient input validation, CRM Blueprint Application Builder Panel of SAP NetWeaver Application Server for AB...
CVE-2024-44121MEDIUM4.3Under certain conditions Statutory Reports in SAP S/4 HANA allows an attacker with basic privileges to access informatio...
CVE-2024-44120MEDIUM4.7SAP NetWeaver Enterprise Portal is vulnerable to reflected cross site scripting due to insufficient encoding of user-con...
CVE-2024-44117MEDIUM5.4The RFC enabled function module allows a low privileged user to perform various actions, such as modifying the URLs of a...
CVE-2024-21528MEDIUM5.9All versions of the package node-gettext are vulnerable to Prototype Pollution via the addTranslations() function in get...
CVE-2024-0067MEDIUM4.3Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API ledlimit.cgi was vulnerable for path t...
CVE-2024-45286MEDIUM6.5Due to lack of proper authorization checks when calling user, a function module in obsolete Tobin interface in SAP Produ...
CVE-2024-44112MEDIUM4.3Due to missing authorization check in SAP for Oil & Gas (Transportation and Distribution), an attacker authenticated as ...
CVE-2024-41728LOW2.7Due to missing authorization check, SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker logge...
CVE-2024-8478HIGH7.3The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up...
CVE-2024-8268HIGH8.8The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering o...
CVE-2024-44116MEDIUM4.3The RFC enabled function module allows a low privileged user to add any workbook to any user's workplace favourites. Thi...
CVE-2024-44115MEDIUM4.3The RFC enabled function module allows a low privileged user to add URLs to any user's workplace favourites. This vulner...
CVE-2024-44114LOW2.7SAP NetWeaver Application Server for ABAP and ABAP Platform allow users with high privileges to execute a program that r...
CVE-2024-44113MEDIUM4.3Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access in...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now