2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-25643MEDIUM4.3The SAP Fiori app (My Overtime Request) - version 605, does not perform the necessary authorization checks for an authen...
CVE-2024-24741MEDIUM4.3SAP Master Data Governance for Material Data - versions 618, 619, 620, 621, 622, 800, 801, 802, 803, 804, does not perfo...
CVE-2024-24742MEDIUM4.1SAP CRM WebClient UI - version S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, WEBCUIF 701, WEBCUIF 731, WEBCUIF ...
CVE-2024-24740MEDIUM5.3SAP NetWeaver Application Server (ABAP) - versions KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERN...
CVE-2024-24739MEDIUM6.3SAP Bank Account Management (BAM) allows an authenticated user with restricted access to use functions which can result ...
CVE-2024-22132MEDIUM6.3SAP IDES ECC-systems contain code that permits the execution of arbitrary program code of user's choice.An attacker can ...
CVE-2024-22130MEDIUM5.4Print preview option in SAP CRM WebClient UI - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107...
CVE-2024-22128MEDIUM6.1SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702...
CVE-2024-22126MEDIUM6.1The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes ...
CVE-2024-25112MEDIUM5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2024-24826MEDIUM5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2024-1459MEDIUM5.3A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-craft...
CVE-2024-1250MEDIUM6.5An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assign...
CVE-2024-22230MEDIUM5.4 Dell Unity, versions prior to 5.4, contains a Cross-site scripting vulnerability. An authenticated attacker could poten...
CVE-2024-22226MEDIUM6.5 Dell Unity, versions prior to 5.4, contain a path traversal vulnerability in its svc_supportassist utility. An authenti...
CVE-2024-22221MEDIUM6.5 Dell Unity, versions prior to 5.4, contains SQL Injection vulnerability. An authenticated attacker could potentially ex...
CVE-2024-0169MEDIUM5.4Dell Unity, version(s) 5.3 and prior, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-...
CVE-2024-25360MEDIUM5.3A hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component ...
CVE-2024-0421MEDIUM5.3The MapPress Maps for WordPress plugin before 2.88.16 is affected by an IDOR as it does not ensure that posts to be retr...
CVE-2024-0420MEDIUM5.4The MapPress Maps for WordPress plugin before 2.88.15 does not sanitize and escape the map title when outputting it back...
CVE-2024-0250MEDIUM6.1The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to i...
CVE-2024-0248MEDIUM4.3The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4...
CVE-2024-1062MEDIUM5.5A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than ...
CVE-2024-24889MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Geek Code Lab All ...
CVE-2024-24933MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prasidhda Malla Ho...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now