2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-37180MEDIUM5.3Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote...
CVE-2024-37175MEDIUM6.5SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of p...
CVE-2024-37172MEDIUM5.4SAP S/4HANA Finance (Advanced Payment Management) does not perform necessary authorization check for an authenticated us...
CVE-2024-37171MEDIUM5SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a cra...
CVE-2024-34692MEDIUM4.6Due to missing verification of file type or content, SAP Enable Now allows an authenticated attacker to upload arbitrary...
CVE-2024-34689MEDIUM5WebFlow Services of SAP Business Workflow allows an authenticated attacker to enumerate accessible HTTP endpoints in the...
CVE-2024-6365CRITICAL9.8The Product Table by WBW plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includin...
CVE-2024-39598HIGH7.7SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal...
CVE-2024-39597HIGH7.2In SAP Commerce, a user can misuse the forgotten password functionality to gain access to a Composable Storefront B2B si...
CVE-2024-39593MEDIUM5.7SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definitio...
CVE-2024-39592MEDIUM6.5Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of p...
CVE-2024-37174MEDIUM6.1Custom CSS support option in SAP CRM WebClient UI does not sufficiently encode user-controlled inputs resulting in Cross...
CVE-2024-37173MEDIUM6.1Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link whic...
CVE-2024-34685MEDIUM6.1Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scr...
CVE-2024-5974HIGH7.2A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management ...
CVE-2024-4944HIGH7.8A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user t...
CVE-2024-5855MEDIUM4.3The Media Hygiene: Remove or Delete Unused Images and More! plugin for WordPress is vulnerable to unauthorized loss of d...
CVE-2024-5793HIGH8.8The Houzez Theme - Functionality plugin for WordPress is vulnerable to SQL Injection via the ‘currency_code’ parameter i...
CVE-2024-34786MEDIUM4.8UniFi iOS app 10.15.0 introduces a misconfiguration on 2nd Generation UniFi Access Points configured as standalone (not ...
CVE-2024-22020MEDIUM6.5A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URL...
CVE-2024-5569MEDIUM6.2A Denial of Service (DoS) vulnerability exists in the jaraco/zipp library, affecting all versions prior to 3.19.1. The v...
CVE-2024-5549HIGH8.1A CORS misconfiguration in the stitionai/devika repository allows attackers to steal sensitive information such as logs,...
CVE-2024-3653MEDIUM5.3A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, wh...
CVE-2024-28882MEDIUM4.3OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which ...
CVE-2024-5971HIGH7.5A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now