2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-42380MEDIUM4.3The RFC enabled function module allows a low privileged user to read any user's workplace favourites and user menu along...
CVE-2024-42378MEDIUM6.1Due to weak encoding of user-controlled inputs, eProcurement on SAP S/4HANA allows malicious scripts to be executed in t...
CVE-2024-42371MEDIUM5.4The RFC enabled function module allows a low privileged user to delete the workplace favourites of any user. This vulner...
CVE-2024-41729MEDIUM4.3Due to missing authorization checks, SAP BEx Analyzer allows an authenticated attacker to access information over the ne...
CVE-2024-6342CRITICAL9.8**UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versi...
CVE-2024-38270MEDIUM6.5An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authe...
CVE-2024-8611CRITICAL9.8A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulne...
CVE-2024-8610MEDIUM5.4A vulnerability classified as problematic has been found in SourceCodester Best House Rental Management System 1.0. Affe...
CVE-2024-44411CRITICAL9.8D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.
CVE-2024-44410CRITICAL9.8D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.
CVE-2024-27365MEDIUM5.5An issue was discovered in Samsung Mobile Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380...
CVE-2024-6796CRITICAL9.1In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that c...
CVE-2024-6795CRITICAL9.8In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an un...
CVE-2024-44902CRITICAL9.8A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
CVE-2024-44725HIGH7.2AutoCMS v5.4 was discovered to contain a SQL injection vulnerability via the sidebar parameter at /admin/robot.php.
CVE-2024-44724HIGH7.2AutoCMS v5.4 was discovered to contain a PHP code injection vulnerability via the txtsite_url parameter at /admin/site_a...
CVE-2024-44085MEDIUM6.1ONLYOFFICE Docs before 8.1.0 allows XSS via a GeneratorFunction Object attack against a macro. This is related to use of...
CVE-2024-42500CRITICAL9.3HPE has identified a denial of service vulnerability in HPE HP-UX System's Network File System (NFSv4) services.
CVE-2024-27387HIGH7.8An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. I...
CVE-2024-27383HIGH7.8An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. I...
CVE-2024-27368MEDIUM5.5An issue was discovered in Samsung Mobile Processor Exynos Mobile Processor, Wearable Processor Exynos 980, Exynos 850, ...
CVE-2024-27367MEDIUM5.5An issue was discovered in Samsung Mobile Processor Exynos Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exyno...
CVE-2024-27366MEDIUM5.5An issue was discovered in Samsung Mobile Processor, Wearable Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exyn...
CVE-2024-27364MEDIUM5.5An issue was discovered in Mobile Processor, Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos...
CVE-2024-7341HIGH7.1A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now