4.8

CVSS3.1

CVE-2024-13247 - Coffee - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-011

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Coffee allows Cross-Site Scripting (XSS).This issue affects Coffee: from 0.0.0 before 1.4.0.

๐Ÿ“… Published: Jan. 9, 2025, 6:53 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 3:23 p.m.

5.3

CVSS3.1

CVE-2024-13246 - Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-010

Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 0.0.0 before 2.0.2.

๐Ÿ“… Published: Jan. 9, 2025, 6:52 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 3:18 p.m.

3.7

CVSS3.1

CVE-2025-22151 - Strawberry GraphQL has a type resolution vulnerability

Strawberry GraphQL is a library for creating GraphQL APIs. Starting in 0.182.0 and prior to version 0.257.0, a type confusion vulnerability exists in Strawberry GraphQL's relay integration that affects multiple ORM integrations (Django, SQLAlchemy, Pydantic). The vulnerability occurs when multiple โ€ฆ

๐Ÿ“… Published: Jan. 9, 2025, 6:51 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-13245 - CKEditor 4 LTS - WYSIWYG HTML editor - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024โ€ฆ

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor 4 LTS - WYSIWYG HTML editor allows Cross-Site Scripting (XSS).This issue affects CKEditor 4 LTS - WYSIWYG HTML editor: from 1.0.0 before 1.0.1.

๐Ÿ“… Published: Jan. 9, 2025, 6:51 p.m. ๐Ÿ”„ Last Modified: July 7, 2025, 3:03 p.m.

8.8

CVSS3.1

CVE-2024-13244 - Migrate Tools - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2024-008

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate Tools allows Cross Site Request Forgery.This issue affects Migrate Tools: from 0.0.0 before 6.0.3.

๐Ÿ“… Published: Jan. 9, 2025, 6:50 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 4:55 p.m.

6.5

CVSS3.1

CVE-2024-13243 - Entity Delete Log - Moderately critical - Access bypass - SA-CONTRIB-2024-007

Missing Authorization vulnerability in Drupal Entity Delete Log allows Forceful Browsing.This issue affects Entity Delete Log: from 0.0.0 before 1.1.1.

๐Ÿ“… Published: Jan. 9, 2025, 6:49 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 4:50 p.m.

9.1

CVSS3.1

CVE-2024-13242 - Swift Mailer - Moderately critical - Access bypass - SA-CONTRIB-2024-006

Exposed Dangerous Method or Function vulnerability in Drupal Swift Mailer allows Resource Location Spoofing.This issue affects Swift Mailer: *.*.

๐Ÿ“… Published: Jan. 9, 2025, 6:49 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 4:49 p.m.

9.1

CVSS3.1

CVE-2024-13241 - Open Social - Moderately critical - Information Disclosure - SA-CONTRIB-2024-005

Improper Authorization vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue affects Open Social: from 0.0.0 before 12.0.5.

๐Ÿ“… Published: Jan. 9, 2025, 6:47 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 4:42 p.m.

7.5

CVSS3.1

CVE-2024-13240 - Open Social - Moderately critical - Access bypass - SA-CONTRIB-2024-004

Improper Access Control vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue affects Open Social: from 0.0.0 before 12.05.

๐Ÿ“… Published: Jan. 9, 2025, 6:46 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 4:41 p.m.

9.8

CVSS3.1

CVE-2024-13239 - Two-factor Authentication (TFA) - Moderately critical - Access bypass - SA-CONTRIB-2024-003

Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication Abuse.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.5.0.

๐Ÿ“… Published: Jan. 9, 2025, 6:35 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 4:38 p.m.
Total resulsts: 345145
Page 6798 of 34,515
ยซ previous page ยป next page
Filters