2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13298MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Tarte au Ci...
CVE-2024-13297MEDIUM6.6Deserialization of Untrusted Data vulnerability in Drupal Eloqua allows Object Injection.This issue affects Eloqua: from...
CVE-2024-13296MEDIUM6.6Deserialization of Untrusted Data vulnerability in Drupal Mailjet allows Object Injection.This issue affects Mailjet: fr...
CVE-2024-13295MEDIUM6.6Deserialization of Untrusted Data vulnerability in Drupal Node export allows Object Injection.This issue affects Node ex...
CVE-2024-13294MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal POST File a...
CVE-2024-13293LOW3.1Cross-Site Request Forgery (CSRF) vulnerability in Drupal POST File allows Cross Site Request Forgery.This issue affects...
CVE-2024-13292MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Tooltip all...
CVE-2024-13291HIGH7.3Incorrect Authorization vulnerability in Drupal Basic HTTP Authentication allows Forceful Browsing.This issue affects Ba...
CVE-2024-13290MEDIUM5.3Incorrect Authorization vulnerability in Drupal OhDear Integration allows Forceful Browsing.This issue affects OhDear In...
CVE-2024-13289MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Cookiebot +...
CVE-2024-13288MEDIUM4.3Deserialization of Untrusted Data vulnerability in Drupal Monster Menus allows Object Injection.This issue affects Monst...
CVE-2024-56114MEDIUM6.5Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit t...
CVE-2024-56113HIGH7.5Smart Toilet Lab - Motius 1.3.11 is running with debug mode turned on (DEBUG = True) and exposing sensitive information ...
CVE-2024-55494MEDIUM6.1A PHP Code Injection vulnerability that can lead to Remote Code Execution (RCE) and XSS in Opencode Mobile Collect Call ...
CVE-2024-54887HIGH8TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2...
CVE-2024-54762MEDIUM6.3Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method...
CVE-2024-54761MEDIUM6.3BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.
CVE-2024-54724CRITICAL9.8PHPYun before 7.0.2 is vulnerable to code execution through backdoor-restricted arbitrary file writing and file inclusio...
CVE-2024-46505CRITICAL9.1Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.
CVE-2024-42898MEDIUM5.4A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or ...
CVE-2024-13287MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Views SVG A...
CVE-2024-13286MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal SVG Embed a...
CVE-2024-13285CRITICAL9.8Vulnerability in Drupal wkhtmltopdf.This issue affects wkhtmltopdf: *.*.
CVE-2024-13284HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Gutenberg allows Cross Site Request Forgery.This issue affects...
CVE-2024-13283MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Facets allo...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now