2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13280 | CRITICAL | 9.8 | 0.4% | Jan 9, 2025 | Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Per... |
| CVE-2024-13279 | CRITICAL | 9.8 | 0.4% | Jan 9, 2025 | Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-... |
| CVE-2024-13278 | CRITICAL | 9.1 | 0.3% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 bef... |
| CVE-2024-13277 | CRITICAL | 9.1 | 0.3% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Browsing.This issue affects Smart IP Ban: f... |
| CVE-2024-13264 | CRITICAL | 9.8 | 0.4% | Jan 9, 2025 | Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno ... |
| CVE-2024-10215 | CRITICAL | 9.8 | 0.6% | Jan 9, 2025 | The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.... |
| CVE-2024-13258 | CRITICAL | 9.8 | 0.6% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issu... |
| CVE-2024-13253 | CRITICAL | 9.1 | 0.4% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal Advanced PWA inc Push Notifications allows Forceful Browsing.This issue ... |
| CVE-2024-13242 | CRITICAL | 9.1 | 0.4% | Jan 9, 2025 | Exposed Dangerous Method or Function vulnerability in Drupal Swift Mailer allows Resource Location Spoofing.This issue a... |
| CVE-2024-13241 | CRITICAL | 9.1 | 0.3% | Jan 9, 2025 | Improper Authorization vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue... |
| CVE-2024-13239 | CRITICAL | 9.8 | 0.5% | Jan 9, 2025 | Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication Abuse.This issue affec... |
| CVE-2024-11642 | CRITICAL | 9.8 | 1.0% | Jan 9, 2025 | The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Paginatio... |
| CVE-2024-12802 | CRITICAL | 9.1 | 0.5% | Jan 9, 2025 | SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal ... |
| CVE-2024-43663 | CRITICAL | 9.8 | 1.0% | Jan 9, 2025 | There are many buffer overflow vulnerabilities present in several CGI binaries of the charging station.This issue affect... |
| CVE-2024-43661 | CRITICAL | 9.8 | 0.5% | Jan 9, 2025 | The <redacted>.so library, which is used by <redacted>, is vulnerable to a buffer overflow in the code that handles the ... |
| CVE-2024-43657 | CRITICAL | 9.3 | 1.4% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje... |
| CVE-2024-43656 | CRITICAL | 9.3 | 1.5% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje... |
| CVE-2024-43655 | CRITICAL | 9.3 | 1.2% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje... |
| CVE-2024-43654 | CRITICAL | 9.3 | 2.1% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware... |
| CVE-2024-43653 | CRITICAL | 9.3 | 2.1% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inj... |
| CVE-2024-43652 | CRITICAL | 9.3 | 1.9% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje... |
| CVE-2024-43651 | CRITICAL | 9.3 | 1.7% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje... |
| CVE-2024-43650 | CRITICAL | 9.3 | 1.6% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware ... |
| CVE-2024-43649 | CRITICAL | 9.3 | 1.8% | Jan 9, 2025 | Authenticated command injection in the filename of a <redacted>.exe request leads to remote code execution as the root u... |
| CVE-2024-43648 | CRITICAL | 9.3 | 1.8% | Jan 9, 2025 | Command injection in the <redacted> parameter of a <redacted>.exe request leads to remote code execution as the root use... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now