2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13282 | HIGH | 8.8 | 0.3% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal Block permissions allows Forceful Browsing.This issue affects Block perm... |
| CVE-2024-13281 | CRITICAL | 9.1 | 0.3% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue affects Monster Menus:... |
| CVE-2024-13280 | CRITICAL | 9.8 | 0.4% | Jan 9, 2025 | Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Per... |
| CVE-2024-13279 | CRITICAL | 9.8 | 0.4% | Jan 9, 2025 | Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-... |
| CVE-2024-13278 | CRITICAL | 9.1 | 0.3% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 bef... |
| CVE-2024-13277 | CRITICAL | 9.1 | 0.3% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Browsing.This issue affects Smart IP Ban: f... |
| CVE-2024-13276 | HIGH | 7.5 | 0.4% | Jan 9, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Drupal File Entity (fieldable files) allows Forceful ... |
| CVE-2024-13275 | MEDIUM | 5.3 | 0.3% | Jan 9, 2025 | Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Drupal Security Kit allows HTTP DoS.This ... |
| CVE-2024-13274 | MEDIUM | 5.3 | 0.3% | Jan 9, 2025 | Improper Control of Interaction Frequency vulnerability in Drupal Open Social allows Functionality Misuse.This issue aff... |
| CVE-2024-13273 | MEDIUM | 5.4 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Open Social... |
| CVE-2024-13272 | MEDIUM | 6.3 | 0.2% | Jan 9, 2025 | Insufficient Granularity of Access Control vulnerability in Drupal Paragraphs table allows Content Spoofing.This issue a... |
| CVE-2024-13271 | MEDIUM | 4.3 | 0.3% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal Content Entity Clone allows Forceful Browsing.This issue affects Content... |
| CVE-2024-13270 | MEDIUM | 4.3 | 0.3% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal Freelinking allows Forceful Browsing.This issue affects Freelinking: fro... |
| CVE-2024-13269 | MEDIUM | 5.3 | 0.4% | Jan 9, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Advanced Varnish allows Forceful Browsing.This... |
| CVE-2024-13268 | MEDIUM | 6.8 | 0.5% | Jan 9, 2025 | Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno ... |
| CVE-2024-13267 | HIGH | 7.5 | 0.5% | Jan 9, 2025 | Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno ... |
| CVE-2024-13266 | MEDIUM | 5.3 | 0.3% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal Responsive and off-canvas menu allows Forceful Browsing.This issue affec... |
| CVE-2024-13265 | HIGH | 7.5 | 0.5% | Jan 9, 2025 | Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno ... |
| CVE-2024-13264 | CRITICAL | 9.8 | 0.4% | Jan 9, 2025 | Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno ... |
| CVE-2024-13263 | MEDIUM | 5.5 | 0.3% | Jan 9, 2025 | Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno ... |
| CVE-2024-13262 | MEDIUM | 4.8 | 0.3% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal View Passwo... |
| CVE-2024-13261 | LOW | 3.5 | 0.1% | Jan 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia DAM allows Cross Site Request Forgery.This issue affect... |
| CVE-2024-13260 | HIGH | 8.8 | 0.2% | Jan 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate queue importer allows Cross Site Request Forgery.This ... |
| CVE-2024-10215 | CRITICAL | 9.8 | 0.6% | Jan 9, 2025 | The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.... |
| CVE-2024-13259 | HIGH | 7.5 | 0.5% | Jan 9, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Image Sizes allows Forceful Browsing.This issu... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now