2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13282HIGH8.8Incorrect Authorization vulnerability in Drupal Block permissions allows Forceful Browsing.This issue affects Block perm...
CVE-2024-13281CRITICAL9.1Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue affects Monster Menus:...
CVE-2024-13280CRITICAL9.8Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Per...
CVE-2024-13279CRITICAL9.8Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-...
CVE-2024-13278CRITICAL9.1Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 bef...
CVE-2024-13277CRITICAL9.1Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Browsing.This issue affects Smart IP Ban: f...
CVE-2024-13276HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in Drupal File Entity (fieldable files) allows Forceful ...
CVE-2024-13275MEDIUM5.3Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Drupal Security Kit allows HTTP DoS.This ...
CVE-2024-13274MEDIUM5.3Improper Control of Interaction Frequency vulnerability in Drupal Open Social allows Functionality Misuse.This issue aff...
CVE-2024-13273MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Open Social...
CVE-2024-13272MEDIUM6.3Insufficient Granularity of Access Control vulnerability in Drupal Paragraphs table allows Content Spoofing.This issue a...
CVE-2024-13271MEDIUM4.3Incorrect Authorization vulnerability in Drupal Content Entity Clone allows Forceful Browsing.This issue affects Content...
CVE-2024-13270MEDIUM4.3Incorrect Authorization vulnerability in Drupal Freelinking allows Forceful Browsing.This issue affects Freelinking: fro...
CVE-2024-13269MEDIUM5.3Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Advanced Varnish allows Forceful Browsing.This...
CVE-2024-13268MEDIUM6.8Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno ...
CVE-2024-13267HIGH7.5Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno ...
CVE-2024-13266MEDIUM5.3Incorrect Authorization vulnerability in Drupal Responsive and off-canvas menu allows Forceful Browsing.This issue affec...
CVE-2024-13265HIGH7.5Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno ...
CVE-2024-13264CRITICAL9.8Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno ...
CVE-2024-13263MEDIUM5.5Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno ...
CVE-2024-13262MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal View Passwo...
CVE-2024-13261LOW3.5Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia DAM allows Cross Site Request Forgery.This issue affect...
CVE-2024-13260HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate queue importer allows Cross Site Request Forgery.This ...
CVE-2024-10215CRITICAL9.8The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6....
CVE-2024-13259HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Image Sizes allows Forceful Browsing.This issu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now