2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-13267HIGH7.5Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno ...
CVE-2024-13265HIGH7.5Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno ...
CVE-2024-13260HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate queue importer allows Cross Site Request Forgery.This ...
CVE-2024-13259HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Image Sizes allows Forceful Browsing.This issu...
CVE-2024-13256HIGH7.5Insufficient Granularity of Access Control vulnerability in Drupal Email Contact allows Forceful Browsing.This issue aff...
CVE-2024-13255HIGH7.5Exposure of Sensitive Information Through Data Queries vulnerability in Drupal RESTful Web Services allows Forceful Brow...
CVE-2024-13254HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in Drupal REST Views allows Forceful Browsing.This issue...
CVE-2024-13251HIGH8.8Incorrect Privilege Assignment vulnerability in Drupal Registration role allows Privilege Escalation.This issue affects ...
CVE-2024-13250HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Drupal Symfony Mailer Lite allows Cross Site Request Forgery.T...
CVE-2024-13244HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate Tools allows Cross Site Request Forgery.This issue aff...
CVE-2024-13240HIGH7.5Improper Access Control vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issu...
CVE-2024-12848HIGH8.8The SKT Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on t...
CVE-2024-12542HIGH8.6The linkID plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when incl...
CVE-2024-12330HIGH7.5The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to Sensit...
CVE-2024-43660HIGH7.5The CGI script <redacted>.sh can be used to download any file on the filesystem. This issue affects Iocharger firmware ...
CVE-2024-43659HIGH8.3After gaining access to the firmware of a charging station, a file at <redacted> can be accessed to obtain default crede...
CVE-2024-43658HIGH7.2Patch traversal, External Control of File Name or Path vulnerability in Iocharger Home allows deletion of arbitrary fil...
CVE-2024-12805HIGH7.2A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and...
CVE-2024-12803HIGH7.2A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash ...
CVE-2024-53706HIGH7.8A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to e...
CVE-2024-53705HIGH7.5A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establis...
CVE-2024-13212HIGH8.8A vulnerability classified as critical has been found in SingMR HouseRent 1.0. This affects the function singleUpload/up...
CVE-2024-13211HIGH8.8A vulnerability was found in SingMR HouseRent 1.0. It has been rated as critical. Affected by this issue is some unknown...
CVE-2024-13210HIGH7.2A vulnerability was found in donglight bookstore电商书城系统说明 1.0. It has been declared as critical. Affected by this vulnera...
CVE-2024-13206HIGH8.5A vulnerability classified as critical has been found in REVE Antivirus 1.0.0.0 on Linux. This affects an unknown part o...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now