2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13292 | MEDIUM | 4.8 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Tooltip all... |
| CVE-2024-13290 | MEDIUM | 5.3 | 0.3% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal OhDear Integration allows Forceful Browsing.This issue affects OhDear In... |
| CVE-2024-13289 | MEDIUM | 5.4 | 0.3% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Cookiebot +... |
| CVE-2024-13288 | MEDIUM | 4.3 | 0.3% | Jan 9, 2025 | Deserialization of Untrusted Data vulnerability in Drupal Monster Menus allows Object Injection.This issue affects Monst... |
| CVE-2024-56114 | MEDIUM | 6.5 | 0.3% | Jan 9, 2025 | Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit t... |
| CVE-2024-55494 | MEDIUM | 6.1 | 0.4% | Jan 9, 2025 | A PHP Code Injection vulnerability that can lead to Remote Code Execution (RCE) and XSS in Opencode Mobile Collect Call ... |
| CVE-2024-54762 | MEDIUM | 6.3 | 0.3% | Jan 9, 2025 | Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method... |
| CVE-2024-54761 | MEDIUM | 6.3 | 1.7% | Jan 9, 2025 | BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter. |
| CVE-2024-42898 | MEDIUM | 5.4 | 0.6% | Jan 9, 2025 | A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or ... |
| CVE-2024-13287 | MEDIUM | 5.4 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Views SVG A... |
| CVE-2024-13286 | MEDIUM | 5.4 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal SVG Embed a... |
| CVE-2024-13283 | MEDIUM | 6.1 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Facets allo... |
| CVE-2024-13275 | MEDIUM | 5.3 | 0.3% | Jan 9, 2025 | Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Drupal Security Kit allows HTTP DoS.This ... |
| CVE-2024-13274 | MEDIUM | 5.3 | 0.3% | Jan 9, 2025 | Improper Control of Interaction Frequency vulnerability in Drupal Open Social allows Functionality Misuse.This issue aff... |
| CVE-2024-13273 | MEDIUM | 5.4 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Open Social... |
| CVE-2024-13272 | MEDIUM | 6.3 | 0.2% | Jan 9, 2025 | Insufficient Granularity of Access Control vulnerability in Drupal Paragraphs table allows Content Spoofing.This issue a... |
| CVE-2024-13271 | MEDIUM | 4.3 | 0.3% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal Content Entity Clone allows Forceful Browsing.This issue affects Content... |
| CVE-2024-13270 | MEDIUM | 4.3 | 0.3% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal Freelinking allows Forceful Browsing.This issue affects Freelinking: fro... |
| CVE-2024-13269 | MEDIUM | 5.3 | 0.4% | Jan 9, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Advanced Varnish allows Forceful Browsing.This... |
| CVE-2024-13268 | MEDIUM | 6.8 | 0.5% | Jan 9, 2025 | Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno ... |
| CVE-2024-13266 | MEDIUM | 5.3 | 0.3% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal Responsive and off-canvas menu allows Forceful Browsing.This issue affec... |
| CVE-2024-13263 | MEDIUM | 5.5 | 0.3% | Jan 9, 2025 | Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno ... |
| CVE-2024-13262 | MEDIUM | 4.8 | 0.3% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal View Passwo... |
| CVE-2024-13257 | MEDIUM | 5.3 | 0.3% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal Commerce View Receipt allows Forceful Browsing.This issue affects Commer... |
| CVE-2024-13252 | MEDIUM | 5.4 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal TacJS allow... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now