7.5

CVSS3.1

CVE-2024-13254 - REST Views - Moderately critical - Information Disclosure - SA-CONTRIB-2024-018

Insertion of Sensitive Information Into Sent Data vulnerability in Drupal REST Views allows Forceful Browsing.This issue affects REST Views: from 0.0.0 before 3.0.1.

๐Ÿ“… Published: Jan. 9, 2025, 6:59 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 4:12 p.m.

9.1

CVSS3.1

CVE-2024-13253 - Advanced PWA - Critical - Access bypass - SA-CONTRIB-2024-017

Incorrect Authorization vulnerability in Drupal Advanced PWA inc Push Notifications allows Forceful Browsing.This issue affects Advanced PWA inc Push Notifications: from 0.0.0 before 1.5.0.

๐Ÿ“… Published: Jan. 9, 2025, 6:59 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 4:08 p.m.

5.4

CVSS3.1

CVE-2024-13252 - TacJS - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-016

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal TacJS allows Cross-Site Scripting (XSS).This issue affects TacJS: from 0.0.0 before 6.5.0.

๐Ÿ“… Published: Jan. 9, 2025, 6:58 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 4:11 p.m.

8.8

CVSS3.1

CVE-2024-13251 - Registration role - Critical - Access bypass - SA-CONTRIB-2024-015

Incorrect Privilege Assignment vulnerability in Drupal Registration role allows Privilege Escalation.This issue affects Registration role: from 0.0.0 before 2.0.1.

๐Ÿ“… Published: Jan. 9, 2025, 6:58 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 4:06 p.m.

8.8

CVSS3.1

CVE-2024-13250 - Drupal Symfony Mailer Lite - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2024-014

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Drupal Symfony Mailer Lite allows Cross Site Request Forgery.This issue affects Drupal Symfony Mailer Lite: from 0.0.0 before 1.0.6.

๐Ÿ“… Published: Jan. 9, 2025, 6:57 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 4:28 p.m.

5.4

CVSS3.1

CVE-2024-13249 - Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-013

Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 7.X-1.0 before 7.X-1.2.

๐Ÿ“… Published: Jan. 9, 2025, 6:55 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 3:59 p.m.

5.5

CVSS3.1

CVE-2024-13248 - Private content - Moderately critical - Access bypass - SA-CONTRIB-2024-012

Incorrect Privilege Assignment vulnerability in Drupal Private content allows Target Influence via Framing.This issue affects Private content: from 0.0.0 before 2.1.0.

๐Ÿ“… Published: Jan. 9, 2025, 6:53 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 3:58 p.m.

4.8

CVSS3.1

CVE-2024-13247 - Coffee - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-011

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Coffee allows Cross-Site Scripting (XSS).This issue affects Coffee: from 0.0.0 before 1.4.0.

๐Ÿ“… Published: Jan. 9, 2025, 6:53 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 3:23 p.m.

5.3

CVSS3.1

CVE-2024-13246 - Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-010

Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 0.0.0 before 2.0.2.

๐Ÿ“… Published: Jan. 9, 2025, 6:52 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 3:18 p.m.

3.7

CVSS3.1

CVE-2025-22151 - Strawberry GraphQL has a type resolution vulnerability

Strawberry GraphQL is a library for creating GraphQL APIs. Starting in 0.182.0 and prior to version 0.257.0, a type confusion vulnerability exists in Strawberry GraphQL's relay integration that affects multiple ORM integrations (Django, SQLAlchemy, Pydantic). The vulnerability occurs when multiple โ€ฆ

๐Ÿ“… Published: Jan. 9, 2025, 6:51 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 7201 of 34,919
ยซ previous page ยป next page
Filters