2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7784 | MEDIUM | 6.1 | 0.2% | Sep 10, 2024 | During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device t... |
| CVE-2024-6979 | HIGH | 7.5 | 0.3% | Sep 10, 2024 | Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-pri... |
| CVE-2024-6509 | MEDIUM | 6.5 | 0.4% | Sep 10, 2024 | Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API alwaysmulti.cgi was vulnerable for fil... |
| CVE-2024-6173 | MEDIUM | 6.5 | 0.4% | Sep 10, 2024 | 51l3nc3, member of the AXIS OS Bug Bounty Program, has found that a Guard Tour VAPIX API parameter allowed the use of ar... |
| CVE-2024-45504 | MEDIUM | 6.5 | 0.3% | Sep 10, 2024 | Cross-site request forgery (CSRF) vulnerability in multiple Alps System Integration products and the OEM products allow ... |
| CVE-2024-45285 | MEDIUM | 5.4 | 0.3% | Sep 10, 2024 | The RFC enabled function module allows a low privileged user to perform denial of service on any user and also change or... |
| CVE-2024-45284 | LOW | 2.4 | 0.2% | Sep 10, 2024 | An authenticated attacker with high privilege can use functions of SLCM transactions to which access should be restricte... |
| CVE-2024-45283 | MEDIUM | 6 | 0.2% | Sep 10, 2024 | SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The attacker could obtain the u... |
| CVE-2024-45281 | MEDIUM | 5.8 | 0.2% | Sep 10, 2024 | SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even ... |
| CVE-2024-45280 | MEDIUM | 4.8 | 0.2% | Sep 10, 2024 | Due to insufficient encoding of user-controlled inputs, SAP NetWeaver AS Java allows malicious scripts to be executed in... |
| CVE-2024-45279 | MEDIUM | 6.1 | 0.3% | Sep 10, 2024 | Due to insufficient input validation, CRM Blueprint Application Builder Panel of SAP NetWeaver Application Server for AB... |
| CVE-2024-44121 | MEDIUM | 4.3 | 0.3% | Sep 10, 2024 | Under certain conditions Statutory Reports in SAP S/4 HANA allows an attacker with basic privileges to access informatio... |
| CVE-2024-44120 | MEDIUM | 4.7 | 0.2% | Sep 10, 2024 | SAP NetWeaver Enterprise Portal is vulnerable to reflected cross site scripting due to insufficient encoding of user-con... |
| CVE-2024-44117 | MEDIUM | 5.4 | 0.3% | Sep 10, 2024 | The RFC enabled function module allows a low privileged user to perform various actions, such as modifying the URLs of a... |
| CVE-2024-21528 | MEDIUM | 5.9 | 0.6% | Sep 10, 2024 | All versions of the package node-gettext are vulnerable to Prototype Pollution via the addTranslations() function in get... |
| CVE-2024-0067 | MEDIUM | 4.3 | 0.4% | Sep 10, 2024 | Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API ledlimit.cgi was vulnerable for path t... |
| CVE-2024-45286 | MEDIUM | 6.5 | 0.3% | Sep 10, 2024 | Due to lack of proper authorization checks when calling user, a function module in obsolete Tobin interface in SAP Produ... |
| CVE-2024-44112 | MEDIUM | 4.3 | 0.3% | Sep 10, 2024 | Due to missing authorization check in SAP for Oil & Gas (Transportation and Distribution), an attacker authenticated as ... |
| CVE-2024-41728 | LOW | 2.7 | 0.3% | Sep 10, 2024 | Due to missing authorization check, SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker logge... |
| CVE-2024-8478 | HIGH | 7.3 | 0.6% | Sep 10, 2024 | The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up... |
| CVE-2024-8268 | HIGH | 8.8 | 0.7% | Sep 10, 2024 | The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering o... |
| CVE-2024-44116 | MEDIUM | 4.3 | 0.3% | Sep 10, 2024 | The RFC enabled function module allows a low privileged user to add any workbook to any user's workplace favourites. Thi... |
| CVE-2024-44115 | MEDIUM | 4.3 | 0.3% | Sep 10, 2024 | The RFC enabled function module allows a low privileged user to add URLs to any user's workplace favourites. This vulner... |
| CVE-2024-44114 | LOW | 2.7 | 0.2% | Sep 10, 2024 | SAP NetWeaver Application Server for ABAP and ABAP Platform allow users with high privileges to execute a program that r... |
| CVE-2024-44113 | MEDIUM | 4.3 | 0.3% | Sep 10, 2024 | Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access in... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now