2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6724 | MEDIUM | 4.8 | 0.4% | Aug 13, 2024 | The Generate Images WordPress plugin before 5.2.8 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-7092 | MEDIUM | 5.4 | 0.4% | Aug 13, 2024 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress... |
| CVE-2024-42373 | MEDIUM | 5.4 | 0.3% | Aug 13, 2024 | SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading t... |
| CVE-2024-41734 | MEDIUM | 4.3 | 0.3% | Aug 13, 2024 | Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker... |
| CVE-2024-39591 | MEDIUM | 5.3 | 0.3% | Aug 13, 2024 | SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escala... |
| CVE-2024-42377 | MEDIUM | 4.3 | 0.2% | Aug 13, 2024 | SAP shared service framework allows an authenticated non-administrative user to call a remote-enabled function, which wi... |
| CVE-2024-42376 | MEDIUM | 6.5 | 0.3% | Aug 13, 2024 | SAP Shared Service Framework does not perform necessary authorization check for an authenticated user, resulting in esca... |
| CVE-2024-42375 | MEDIUM | 4.3 | 0.4% | Aug 13, 2024 | SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the ... |
| CVE-2024-42374 | HIGH | 8.2 | 0.5% | Aug 13, 2024 | BEx Web Java Runtime Export Web Service does not sufficiently validate an XML document accepted from an untrusted source... |
| CVE-2024-41737 | MEDIUM | 5 | 0.3% | Aug 13, 2024 | SAP CRM ABAP (Insights Management) allows an authenticated attacker to enumerate HTTP endpoints in the internal network ... |
| CVE-2024-41736 | MEDIUM | 4.3 | 0.3% | Aug 13, 2024 | Under certain conditions SAP Permit to Work allows an authenticated attacker to access information which would otherwise... |
| CVE-2024-41735 | MEDIUM | 5.4 | 0.2% | Aug 13, 2024 | SAP Commerce Backoffice does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vul... |
| CVE-2024-41733 | MEDIUM | 5.3 | 0.3% | Aug 13, 2024 | In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows... |
| CVE-2024-41732 | MEDIUM | 5.4 | 0.3% | Aug 13, 2024 | SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowli... |
| CVE-2024-41731 | MEDIUM | 4.3 | 0.4% | Aug 13, 2024 | SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the ne... |
| CVE-2024-41730 | CRITICAL | 9.8 | 75.6% | Aug 13, 2024 | In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an u... |
| CVE-2024-33005 | MEDIUM | 6.3 | 0.2% | Aug 13, 2024 | Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Appli... |
| CVE-2024-33003 | CRITICAL | 9.1 | 0.5% | Aug 13, 2024 | Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, e... |
| CVE-2024-28166 | MEDIUM | 4.3 | 0.3% | Aug 13, 2024 | SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the ... |
| CVE-2024-7388 | MEDIUM | 4 | 0.2% | Aug 13, 2024 | The WP Bannerize Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via banner alt data in all versio... |
| CVE-2024-7094 | CRITICAL | 9.8 | 37.5% | Aug 13, 2024 | The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection lead... |
| CVE-2024-7709 | MEDIUM | 6.9 | 0.4% | Aug 13, 2024 | A vulnerability, which was classified as problematic, has been found in OcoMon 4.0RC1/4.0/5.0RC1. This issue affects som... |
| CVE-2024-7707 | CRITICAL | 9.8 | 1.3% | Aug 13, 2024 | A vulnerability was found in Tenda FH1206 02.03.01.35 and classified as critical. Affected by this issue is the function... |
| CVE-2024-7706 | LOW | 2.7 | 0.4% | Aug 12, 2024 | A vulnerability was found in Fujian mwcms 1.0.0. It has been rated as critical. Affected by this issue is the function u... |
| CVE-2024-7705 | MEDIUM | 5.3 | 0.3% | Aug 12, 2024 | A vulnerability was found in Fujian mwcms 1.0.0. It has been declared as critical. Affected by this vulnerability is the... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now