2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37180 | MEDIUM | 5.3 | 0.3% | Jul 9, 2024 | Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote... |
| CVE-2024-37175 | MEDIUM | 6.5 | 0.3% | Jul 9, 2024 | SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of p... |
| CVE-2024-37172 | MEDIUM | 5.4 | 0.3% | Jul 9, 2024 | SAP S/4HANA Finance (Advanced Payment Management) does not perform necessary authorization check for an authenticated us... |
| CVE-2024-37171 | MEDIUM | 5 | 0.4% | Jul 9, 2024 | SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a cra... |
| CVE-2024-34692 | MEDIUM | 4.6 | 0.2% | Jul 9, 2024 | Due to missing verification of file type or content, SAP Enable Now allows an authenticated attacker to upload arbitrary... |
| CVE-2024-34689 | MEDIUM | 5 | 0.4% | Jul 9, 2024 | WebFlow Services of SAP Business Workflow allows an authenticated attacker to enumerate accessible HTTP endpoints in the... |
| CVE-2024-6365 | CRITICAL | 9.8 | 1.2% | Jul 9, 2024 | The Product Table by WBW plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includin... |
| CVE-2024-39598 | HIGH | 7.7 | 0.3% | Jul 9, 2024 | SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal... |
| CVE-2024-39597 | HIGH | 7.2 | 0.3% | Jul 9, 2024 | In SAP Commerce, a user can misuse the forgotten password functionality to gain access to a Composable Storefront B2B si... |
| CVE-2024-39593 | MEDIUM | 5.7 | 0.3% | Jul 9, 2024 | SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definitio... |
| CVE-2024-39592 | MEDIUM | 6.5 | 0.4% | Jul 9, 2024 | Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of p... |
| CVE-2024-37174 | MEDIUM | 6.1 | 0.3% | Jul 9, 2024 | Custom CSS support option in SAP CRM WebClient UI does not sufficiently encode user-controlled inputs resulting in Cross... |
| CVE-2024-37173 | MEDIUM | 6.1 | 0.3% | Jul 9, 2024 | Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link whic... |
| CVE-2024-34685 | MEDIUM | 6.1 | 0.3% | Jul 9, 2024 | Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scr... |
| CVE-2024-5974 | HIGH | 7.2 | 0.9% | Jul 9, 2024 | A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management ... |
| CVE-2024-4944 | HIGH | 7.8 | 0.3% | Jul 9, 2024 | A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user t... |
| CVE-2024-5855 | MEDIUM | 4.3 | 0.4% | Jul 9, 2024 | The Media Hygiene: Remove or Delete Unused Images and More! plugin for WordPress is vulnerable to unauthorized loss of d... |
| CVE-2024-5793 | HIGH | 8.8 | 0.5% | Jul 9, 2024 | The Houzez Theme - Functionality plugin for WordPress is vulnerable to SQL Injection via the ‘currency_code’ parameter i... |
| CVE-2024-34786 | MEDIUM | 4.8 | 0.2% | Jul 9, 2024 | UniFi iOS app 10.15.0 introduces a misconfiguration on 2nd Generation UniFi Access Points configured as standalone (not ... |
| CVE-2024-22020 | MEDIUM | 6.5 | 1.1% | Jul 9, 2024 | A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URL... |
| CVE-2024-5569 | MEDIUM | 6.2 | 0.2% | Jul 9, 2024 | A Denial of Service (DoS) vulnerability exists in the jaraco/zipp library, affecting all versions prior to 3.19.1. The v... |
| CVE-2024-5549 | HIGH | 8.1 | 0.3% | Jul 9, 2024 | A CORS misconfiguration in the stitionai/devika repository allows attackers to steal sensitive information such as logs,... |
| CVE-2024-3653 | MEDIUM | 5.3 | 1.9% | Jul 8, 2024 | A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, wh... |
| CVE-2024-28882 | MEDIUM | 4.3 | 0.7% | Jul 8, 2024 | OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which ... |
| CVE-2024-5971 | HIGH | 7.5 | 2.9% | Jul 8, 2024 | A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now