2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13264 | CRITICAL | 9.8 | 0.4% | Jan 9, 2025 | Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno ... |
| CVE-2024-13263 | MEDIUM | 5.5 | 0.3% | Jan 9, 2025 | Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno ... |
| CVE-2024-13262 | MEDIUM | 4.8 | 0.3% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal View Passwo... |
| CVE-2024-13261 | LOW | 3.5 | 0.1% | Jan 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia DAM allows Cross Site Request Forgery.This issue affect... |
| CVE-2024-13260 | HIGH | 8.8 | 0.2% | Jan 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate queue importer allows Cross Site Request Forgery.This ... |
| CVE-2024-10215 | CRITICAL | 9.8 | 0.6% | Jan 9, 2025 | The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.... |
| CVE-2024-13259 | HIGH | 7.5 | 0.5% | Jan 9, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Image Sizes allows Forceful Browsing.This issu... |
| CVE-2024-13258 | CRITICAL | 9.8 | 0.6% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issu... |
| CVE-2024-13257 | MEDIUM | 5.3 | 0.3% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal Commerce View Receipt allows Forceful Browsing.This issue affects Commer... |
| CVE-2024-13256 | HIGH | 7.5 | 0.4% | Jan 9, 2025 | Insufficient Granularity of Access Control vulnerability in Drupal Email Contact allows Forceful Browsing.This issue aff... |
| CVE-2024-13255 | HIGH | 7.5 | 0.5% | Jan 9, 2025 | Exposure of Sensitive Information Through Data Queries vulnerability in Drupal RESTful Web Services allows Forceful Brow... |
| CVE-2024-13254 | HIGH | 7.5 | 0.5% | Jan 9, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Drupal REST Views allows Forceful Browsing.This issue... |
| CVE-2024-13253 | CRITICAL | 9.1 | 0.4% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal Advanced PWA inc Push Notifications allows Forceful Browsing.This issue ... |
| CVE-2024-13252 | MEDIUM | 5.4 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal TacJS allow... |
| CVE-2024-13251 | HIGH | 8.8 | 0.3% | Jan 9, 2025 | Incorrect Privilege Assignment vulnerability in Drupal Registration role allows Privilege Escalation.This issue affects ... |
| CVE-2024-13250 | HIGH | 8.8 | 0.2% | Jan 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Drupal Symfony Mailer Lite allows Cross Site Request Forgery.T... |
| CVE-2024-13249 | MEDIUM | 5.4 | 0.2% | Jan 9, 2025 | Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framin... |
| CVE-2024-13248 | MEDIUM | 5.5 | 0.2% | Jan 9, 2025 | Incorrect Privilege Assignment vulnerability in Drupal Private content allows Target Influence via Framing.This issue af... |
| CVE-2024-13247 | MEDIUM | 4.8 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Coffee allo... |
| CVE-2024-13246 | MEDIUM | 5.3 | 0.3% | Jan 9, 2025 | Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framin... |
| CVE-2024-13245 | MEDIUM | 5.4 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor 4 ... |
| CVE-2024-13244 | HIGH | 8.8 | 0.2% | Jan 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate Tools allows Cross Site Request Forgery.This issue aff... |
| CVE-2024-13243 | MEDIUM | 6.5 | 0.3% | Jan 9, 2025 | Missing Authorization vulnerability in Drupal Entity Delete Log allows Forceful Browsing.This issue affects Entity Delet... |
| CVE-2024-13242 | CRITICAL | 9.1 | 0.4% | Jan 9, 2025 | Exposed Dangerous Method or Function vulnerability in Drupal Swift Mailer allows Resource Location Spoofing.This issue a... |
| CVE-2024-13241 | CRITICAL | 9.1 | 0.3% | Jan 9, 2025 | Improper Authorization vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now