2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-13280CRITICAL9.8Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Per...
CVE-2024-13279CRITICAL9.8Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-...
CVE-2024-13278CRITICAL9.1Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 bef...
CVE-2024-13277CRITICAL9.1Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Browsing.This issue affects Smart IP Ban: f...
CVE-2024-13264CRITICAL9.8Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno ...
CVE-2024-10215CRITICAL9.8The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6....
CVE-2024-13258CRITICAL9.8Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issu...
CVE-2024-13253CRITICAL9.1Incorrect Authorization vulnerability in Drupal Advanced PWA inc Push Notifications allows Forceful Browsing.This issue ...
CVE-2024-13242CRITICAL9.1Exposed Dangerous Method or Function vulnerability in Drupal Swift Mailer allows Resource Location Spoofing.This issue a...
CVE-2024-13241CRITICAL9.1Improper Authorization vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue...
CVE-2024-13239CRITICAL9.8Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication Abuse.This issue affec...
CVE-2024-11642CRITICAL9.8The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Paginatio...
CVE-2024-12802CRITICAL9.1SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal ...
CVE-2024-43663CRITICAL9.8There are many buffer overflow vulnerabilities present in several CGI binaries of the charging station.This issue affect...
CVE-2024-43661CRITICAL9.8The <redacted>.so library, which is used by <redacted>, is vulnerable to a buffer overflow in the code that handles the ...
CVE-2024-43657CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje...
CVE-2024-43656CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje...
CVE-2024-43655CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje...
CVE-2024-43654CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware...
CVE-2024-43653CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability  allows OS Command Inj...
CVE-2024-43652CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje...
CVE-2024-43651CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje...
CVE-2024-43650CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware ...
CVE-2024-43649CRITICAL9.3Authenticated command injection in the filename of a <redacted>.exe request leads to remote code execution as the root u...
CVE-2024-43648CRITICAL9.3Command injection in the <redacted> parameter of a <redacted>.exe request leads to remote code execution as the root use...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now