2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25643 | MEDIUM | 4.3 | 0.3% | Feb 13, 2024 | The SAP Fiori app (My Overtime Request) - version 605, does not perform the necessary authorization checks for an authen... |
| CVE-2024-24741 | MEDIUM | 4.3 | 0.3% | Feb 13, 2024 | SAP Master Data Governance for Material Data - versions 618, 619, 620, 621, 622, 800, 801, 802, 803, 804, does not perfo... |
| CVE-2024-24742 | MEDIUM | 4.1 | 0.3% | Feb 13, 2024 | SAP CRM WebClient UI - version S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, WEBCUIF 701, WEBCUIF 731, WEBCUIF ... |
| CVE-2024-24740 | MEDIUM | 5.3 | 0.4% | Feb 13, 2024 | SAP NetWeaver Application Server (ABAP) - versions KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERN... |
| CVE-2024-24739 | MEDIUM | 6.3 | 0.3% | Feb 13, 2024 | SAP Bank Account Management (BAM) allows an authenticated user with restricted access to use functions which can result ... |
| CVE-2024-22132 | MEDIUM | 6.3 | 0.5% | Feb 13, 2024 | SAP IDES ECC-systems contain code that permits the execution of arbitrary program code of user's choice.An attacker can ... |
| CVE-2024-22130 | MEDIUM | 5.4 | 0.3% | Feb 13, 2024 | Print preview option in SAP CRM WebClient UI - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107... |
| CVE-2024-22128 | MEDIUM | 6.1 | 0.4% | Feb 13, 2024 | SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702... |
| CVE-2024-22126 | MEDIUM | 6.1 | 0.5% | Feb 13, 2024 | The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes ... |
| CVE-2024-25112 | MEDIUM | 5 | 0.2% | Feb 12, 2024 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file... |
| CVE-2024-24826 | MEDIUM | 5 | 0.2% | Feb 12, 2024 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file... |
| CVE-2024-1459 | MEDIUM | 5.3 | 1.7% | Feb 12, 2024 | A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-craft... |
| CVE-2024-1250 | MEDIUM | 6.5 | 0.5% | Feb 12, 2024 | An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assign... |
| CVE-2024-22230 | MEDIUM | 5.4 | 0.3% | Feb 12, 2024 | Dell Unity, versions prior to 5.4, contains a Cross-site scripting vulnerability. An authenticated attacker could poten... |
| CVE-2024-22226 | MEDIUM | 6.5 | 0.4% | Feb 12, 2024 | Dell Unity, versions prior to 5.4, contain a path traversal vulnerability in its svc_supportassist utility. An authenti... |
| CVE-2024-22221 | MEDIUM | 6.5 | 0.4% | Feb 12, 2024 | Dell Unity, versions prior to 5.4, contains SQL Injection vulnerability. An authenticated attacker could potentially ex... |
| CVE-2024-0169 | MEDIUM | 5.4 | 0.3% | Feb 12, 2024 | Dell Unity, version(s) 5.3 and prior, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-... |
| CVE-2024-25360 | MEDIUM | 5.3 | 0.4% | Feb 12, 2024 | A hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component ... |
| CVE-2024-0421 | MEDIUM | 5.3 | 0.6% | Feb 12, 2024 | The MapPress Maps for WordPress plugin before 2.88.16 is affected by an IDOR as it does not ensure that posts to be retr... |
| CVE-2024-0420 | MEDIUM | 5.4 | 0.5% | Feb 12, 2024 | The MapPress Maps for WordPress plugin before 2.88.15 does not sanitize and escape the map title when outputting it back... |
| CVE-2024-0250 | MEDIUM | 6.1 | 1.3% | Feb 12, 2024 | The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to i... |
| CVE-2024-0248 | MEDIUM | 4.3 | 0.4% | Feb 12, 2024 | The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4... |
| CVE-2024-1062 | MEDIUM | 5.5 | 0.3% | Feb 12, 2024 | A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than ... |
| CVE-2024-24889 | MEDIUM | 6.1 | 0.3% | Feb 12, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Geek Code Lab All ... |
| CVE-2024-24933 | MEDIUM | 6.1 | 0.3% | Feb 12, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prasidhda Malla Ho... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now