2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13258CRITICAL9.8Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issu...
CVE-2024-13257MEDIUM5.3Incorrect Authorization vulnerability in Drupal Commerce View Receipt allows Forceful Browsing.This issue affects Commer...
CVE-2024-13256HIGH7.5Insufficient Granularity of Access Control vulnerability in Drupal Email Contact allows Forceful Browsing.This issue aff...
CVE-2024-13255HIGH7.5Exposure of Sensitive Information Through Data Queries vulnerability in Drupal RESTful Web Services allows Forceful Brow...
CVE-2024-13254HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in Drupal REST Views allows Forceful Browsing.This issue...
CVE-2024-13253CRITICAL9.1Incorrect Authorization vulnerability in Drupal Advanced PWA inc Push Notifications allows Forceful Browsing.This issue ...
CVE-2024-13252MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal TacJS allow...
CVE-2024-13251HIGH8.8Incorrect Privilege Assignment vulnerability in Drupal Registration role allows Privilege Escalation.This issue affects ...
CVE-2024-13250HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Drupal Symfony Mailer Lite allows Cross Site Request Forgery.T...
CVE-2024-13249MEDIUM5.4Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framin...
CVE-2024-13248MEDIUM5.5Incorrect Privilege Assignment vulnerability in Drupal Private content allows Target Influence via Framing.This issue af...
CVE-2024-13247MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Coffee allo...
CVE-2024-13246MEDIUM5.3Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framin...
CVE-2024-13245MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor 4 ...
CVE-2024-13244HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate Tools allows Cross Site Request Forgery.This issue aff...
CVE-2024-13243MEDIUM6.5Missing Authorization vulnerability in Drupal Entity Delete Log allows Forceful Browsing.This issue affects Entity Delet...
CVE-2024-13242CRITICAL9.1Exposed Dangerous Method or Function vulnerability in Drupal Swift Mailer allows Resource Location Spoofing.This issue a...
CVE-2024-13241CRITICAL9.1Improper Authorization vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue...
CVE-2024-13240HIGH7.5Improper Access Control vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issu...
CVE-2024-13239CRITICAL9.8Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication Abuse.This issue affec...
CVE-2024-13238MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Typogrify a...
CVE-2024-13237MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal File Entity...
CVE-2024-10106LOW3.7A buffer overflow vulnerability in the packet handoff plugin allows an attacker to overwrite memory outside the plugin's...
CVE-2024-43176MEDIUM5.4IBM OpenPages 9.0 could allow an authenticated user to obtain sensitive information such as configurations that should o...
CVE-2024-6155MEDIUM5.4The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Authenticated (Subscriber+) Ser...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now