2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13264CRITICAL9.8Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno ...
CVE-2024-13263MEDIUM5.5Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno ...
CVE-2024-13262MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal View Passwo...
CVE-2024-13261LOW3.5Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia DAM allows Cross Site Request Forgery.This issue affect...
CVE-2024-13260HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate queue importer allows Cross Site Request Forgery.This ...
CVE-2024-10215CRITICAL9.8The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6....
CVE-2024-13259HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Image Sizes allows Forceful Browsing.This issu...
CVE-2024-13258CRITICAL9.8Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issu...
CVE-2024-13257MEDIUM5.3Incorrect Authorization vulnerability in Drupal Commerce View Receipt allows Forceful Browsing.This issue affects Commer...
CVE-2024-13256HIGH7.5Insufficient Granularity of Access Control vulnerability in Drupal Email Contact allows Forceful Browsing.This issue aff...
CVE-2024-13255HIGH7.5Exposure of Sensitive Information Through Data Queries vulnerability in Drupal RESTful Web Services allows Forceful Brow...
CVE-2024-13254HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in Drupal REST Views allows Forceful Browsing.This issue...
CVE-2024-13253CRITICAL9.1Incorrect Authorization vulnerability in Drupal Advanced PWA inc Push Notifications allows Forceful Browsing.This issue ...
CVE-2024-13252MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal TacJS allow...
CVE-2024-13251HIGH8.8Incorrect Privilege Assignment vulnerability in Drupal Registration role allows Privilege Escalation.This issue affects ...
CVE-2024-13250HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Drupal Symfony Mailer Lite allows Cross Site Request Forgery.T...
CVE-2024-13249MEDIUM5.4Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framin...
CVE-2024-13248MEDIUM5.5Incorrect Privilege Assignment vulnerability in Drupal Private content allows Target Influence via Framing.This issue af...
CVE-2024-13247MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Coffee allo...
CVE-2024-13246MEDIUM5.3Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framin...
CVE-2024-13245MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor 4 ...
CVE-2024-13244HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate Tools allows Cross Site Request Forgery.This issue aff...
CVE-2024-13243MEDIUM6.5Missing Authorization vulnerability in Drupal Entity Delete Log allows Forceful Browsing.This issue affects Entity Delet...
CVE-2024-13242CRITICAL9.1Exposed Dangerous Method or Function vulnerability in Drupal Swift Mailer allows Resource Location Spoofing.This issue a...
CVE-2024-13241CRITICAL9.1Improper Authorization vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now