2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-46505CRITICAL9.1Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.
CVE-2024-42898MEDIUM5.4A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or ...
CVE-2024-13287MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Views SVG A...
CVE-2024-13286MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal SVG Embed a...
CVE-2024-13285CRITICAL9.8Vulnerability in Drupal wkhtmltopdf.This issue affects wkhtmltopdf: *.*.
CVE-2024-13284HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Gutenberg allows Cross Site Request Forgery.This issue affects...
CVE-2024-13283MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Facets allo...
CVE-2024-13282HIGH8.8Incorrect Authorization vulnerability in Drupal Block permissions allows Forceful Browsing.This issue affects Block perm...
CVE-2024-13281CRITICAL9.1Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue affects Monster Menus:...
CVE-2024-13280CRITICAL9.8Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Per...
CVE-2024-13279CRITICAL9.8Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-...
CVE-2024-13278CRITICAL9.1Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 bef...
CVE-2024-13277CRITICAL9.1Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Browsing.This issue affects Smart IP Ban: f...
CVE-2024-13276HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in Drupal File Entity (fieldable files) allows Forceful ...
CVE-2024-13275MEDIUM5.3Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Drupal Security Kit allows HTTP DoS.This ...
CVE-2024-13274MEDIUM5.3Improper Control of Interaction Frequency vulnerability in Drupal Open Social allows Functionality Misuse.This issue aff...
CVE-2024-13273MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Open Social...
CVE-2024-13272MEDIUM6.3Insufficient Granularity of Access Control vulnerability in Drupal Paragraphs table allows Content Spoofing.This issue a...
CVE-2024-13271MEDIUM4.3Incorrect Authorization vulnerability in Drupal Content Entity Clone allows Forceful Browsing.This issue affects Content...
CVE-2024-13270MEDIUM4.3Incorrect Authorization vulnerability in Drupal Freelinking allows Forceful Browsing.This issue affects Freelinking: fro...
CVE-2024-13269MEDIUM5.3Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Advanced Varnish allows Forceful Browsing.This...
CVE-2024-13268MEDIUM6.8Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno ...
CVE-2024-13267HIGH7.5Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno ...
CVE-2024-13266MEDIUM5.3Incorrect Authorization vulnerability in Drupal Responsive and off-canvas menu allows Forceful Browsing.This issue affec...
CVE-2024-13265HIGH7.5Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now