2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-55226 | MEDIUM | 5.4 | 0.4% | Jan 9, 2025 | Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via th... |
| CVE-2024-48806 | MEDIUM | 6.8 | 0.3% | Jan 9, 2025 | Buffer Overflow vulnerability in Neat Board NFC v.1.20240620.0015 allows a physically proximate attackers to escalate pr... |
| CVE-2024-13312 | MEDIUM | 5.3 | 0.3% | Jan 9, 2025 | Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from ... |
| CVE-2024-13310 | MEDIUM | 6.5 | 0.4% | Jan 9, 2025 | Vulnerability in Drupal Git Utilities for Drupal.This issue affects Git Utilities for Drupal: *.*. |
| CVE-2024-13309 | MEDIUM | 5.4 | 0.2% | Jan 9, 2025 | Improper Authentication vulnerability in Drupal Login Disable allows Exploiting Incorrectly Configured Access Control Se... |
| CVE-2024-13305 | MEDIUM | 4.8 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Entity Form... |
| CVE-2024-13304 | MEDIUM | 4.5 | 0.2% | Jan 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Minify JS allows Cross Site Request Forgery.This issue affects... |
| CVE-2024-13303 | MEDIUM | 5.3 | 0.3% | Jan 9, 2025 | Missing Authorization vulnerability in Drupal Download All Files allows Forceful Browsing.This issue affects Download Al... |
| CVE-2024-13302 | MEDIUM | 5.3 | 0.3% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal Pages Restriction Access allows Forceful Browsing.This issue affects Pag... |
| CVE-2024-13301 | MEDIUM | 6.1 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal OAuth & Ope... |
| CVE-2024-13300 | MEDIUM | 6.6 | 0.4% | Jan 9, 2025 | Vulnerability in Drupal Print Anything.This issue affects Print Anything: *.*. |
| CVE-2024-13299 | MEDIUM | 6.6 | 0.4% | Jan 9, 2025 | Vulnerability in Drupal Megamenu Framework.This issue affects Megamenu Framework: *.*. |
| CVE-2024-13298 | MEDIUM | 4.8 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Tarte au Ci... |
| CVE-2024-13297 | MEDIUM | 6.6 | 0.4% | Jan 9, 2025 | Deserialization of Untrusted Data vulnerability in Drupal Eloqua allows Object Injection.This issue affects Eloqua: from... |
| CVE-2024-13296 | MEDIUM | 6.6 | 0.4% | Jan 9, 2025 | Deserialization of Untrusted Data vulnerability in Drupal Mailjet allows Object Injection.This issue affects Mailjet: fr... |
| CVE-2024-13295 | MEDIUM | 6.6 | 0.4% | Jan 9, 2025 | Deserialization of Untrusted Data vulnerability in Drupal Node export allows Object Injection.This issue affects Node ex... |
| CVE-2024-13294 | MEDIUM | 5.4 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal POST File a... |
| CVE-2024-13292 | MEDIUM | 4.8 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Tooltip all... |
| CVE-2024-13290 | MEDIUM | 5.3 | 0.3% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal OhDear Integration allows Forceful Browsing.This issue affects OhDear In... |
| CVE-2024-13289 | MEDIUM | 5.4 | 0.3% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Cookiebot +... |
| CVE-2024-13288 | MEDIUM | 4.3 | 0.3% | Jan 9, 2025 | Deserialization of Untrusted Data vulnerability in Drupal Monster Menus allows Object Injection.This issue affects Monst... |
| CVE-2024-56114 | MEDIUM | 6.5 | 0.3% | Jan 9, 2025 | Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit t... |
| CVE-2024-55494 | MEDIUM | 6.1 | 0.4% | Jan 9, 2025 | A PHP Code Injection vulnerability that can lead to Remote Code Execution (RCE) and XSS in Opencode Mobile Collect Call ... |
| CVE-2024-54762 | MEDIUM | 6.3 | 0.3% | Jan 9, 2025 | Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method... |
| CVE-2024-54761 | MEDIUM | 6.3 | 1.7% | Jan 9, 2025 | BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now