2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6724MEDIUM4.8The Generate Images WordPress plugin before 5.2.8 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-7092MEDIUM5.4The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress...
CVE-2024-42373MEDIUM5.4SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading t...
CVE-2024-41734MEDIUM4.3Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker...
CVE-2024-39591MEDIUM5.3SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escala...
CVE-2024-42377MEDIUM4.3SAP shared service framework allows an authenticated non-administrative user to call a remote-enabled function, which wi...
CVE-2024-42376MEDIUM6.5SAP Shared Service Framework does not perform necessary authorization check for an authenticated user, resulting in esca...
CVE-2024-42375MEDIUM4.3SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the ...
CVE-2024-42374HIGH8.2BEx Web Java Runtime Export Web Service does not sufficiently validate an XML document accepted from an untrusted source...
CVE-2024-41737MEDIUM5SAP CRM ABAP (Insights Management) allows an authenticated attacker to enumerate HTTP endpoints in the internal network ...
CVE-2024-41736MEDIUM4.3Under certain conditions SAP Permit to Work allows an authenticated attacker to access information which would otherwise...
CVE-2024-41735MEDIUM5.4SAP Commerce Backoffice does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vul...
CVE-2024-41733MEDIUM5.3In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows...
CVE-2024-41732MEDIUM5.4SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowli...
CVE-2024-41731MEDIUM4.3SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the ne...
CVE-2024-41730CRITICAL9.8In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an u...
CVE-2024-33005MEDIUM6.3Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Appli...
CVE-2024-33003CRITICAL9.1Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, e...
CVE-2024-28166MEDIUM4.3SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the ...
CVE-2024-7388MEDIUM4The WP Bannerize Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via banner alt data in all versio...
CVE-2024-7094CRITICAL9.8The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection lead...
CVE-2024-7709MEDIUM6.9A vulnerability, which was classified as problematic, has been found in OcoMon 4.0RC1/4.0/5.0RC1. This issue affects som...
CVE-2024-7707CRITICAL9.8A vulnerability was found in Tenda FH1206 02.03.01.35 and classified as critical. Affected by this issue is the function...
CVE-2024-7706LOW2.7A vulnerability was found in Fujian mwcms 1.0.0. It has been rated as critical. Affected by this issue is the function u...
CVE-2024-7705MEDIUM5.3A vulnerability was found in Fujian mwcms 1.0.0. It has been declared as critical. Affected by this vulnerability is the...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now