8
CVE-2024-57227 -
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.
0.0
CVE-2024-13324 -
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: 2024-13362. Reason: This candidate is a reservation duplicate of 2024-13362. Notes: All CVE users should reference 2024-13362 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidentβ¦
8.8
CVE-2025-21380 - Azure Marketplace SaaS Resources Information Disclosure Vulnerability
Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network.
8.8
CVE-2025-21385 - Microsoft Purview Information Disclosure Vulnerability
A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network.
5.3
CVE-2024-13312 - Open Social - Moderately critical - Access bypass - SA-CONTRIB-2024-076
Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 11.8.0 before 12.3.10, from 12.4.0 before 12.4.9.
7.3
CVE-2024-13311 - Allow All File Extensions for file fields - Critical - Unsupported - SA-CONTRIB-2024-075
Vulnerability in Drupal Allow All File Extensions for file fields.This issue affects Allow All File Extensions for file fields: *.*.
6.5
CVE-2024-13310 - Git Utilities for Drupal - Critical - Unsupported - SA-CONTRIB-2024-074
Vulnerability in Drupal Git Utilities for Drupal.This issue affects Git Utilities for Drupal: *.*.
5.4
CVE-2024-13309 - Login Disable - Critical - Access bypass - SA-CONTRIB-2024-073
Improper Authentication vulnerability in Drupal Login Disable allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login Disable: from 2.0.0 before 2.1.1.
3.8
CVE-2024-13308 - Browser Back Button - Moderately critical - Cross site scripting - SA-CONTRIB-2024-072
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Browser Back Button allows Cross-Site Scripting (XSS).This issue affects Browser Back Button: from 1.0.0 before 2.0.2.
4.8
CVE-2024-13305 - Entity Form Steps - Moderately critical - Cross site scripting - SA-CONTRIB-2024-071
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Entity Form Steps allows Cross-Site Scripting (XSS).This issue affects Entity Form Steps: from 0.0.0 before 1.1.4.