5.4
CVE-2024-13245 - CKEditor 4 LTS - WYSIWYG HTML editor - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024β¦
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor 4 LTS - WYSIWYG HTML editor allows Cross-Site Scripting (XSS).This issue affects CKEditor 4 LTS - WYSIWYG HTML editor: from 1.0.0 before 1.0.1.
8.8
CVE-2024-13244 - Migrate Tools - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2024-008
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate Tools allows Cross Site Request Forgery.This issue affects Migrate Tools: from 0.0.0 before 6.0.3.
6.5
CVE-2024-13243 - Entity Delete Log - Moderately critical - Access bypass - SA-CONTRIB-2024-007
Missing Authorization vulnerability in Drupal Entity Delete Log allows Forceful Browsing.This issue affects Entity Delete Log: from 0.0.0 before 1.1.1.
9.1
CVE-2024-13242 - Swift Mailer - Moderately critical - Access bypass - SA-CONTRIB-2024-006
Exposed Dangerous Method or Function vulnerability in Drupal Swift Mailer allows Resource Location Spoofing.This issue affects Swift Mailer: *.*.
9.1
CVE-2024-13241 - Open Social - Moderately critical - Information Disclosure - SA-CONTRIB-2024-005
Improper Authorization vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue affects Open Social: from 0.0.0 before 12.0.5.
7.5
CVE-2024-13240 - Open Social - Moderately critical - Access bypass - SA-CONTRIB-2024-004
Improper Access Control vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue affects Open Social: from 0.0.0 before 12.05.
9.8
CVE-2024-13239 - Two-factor Authentication (TFA) - Moderately critical - Access bypass - SA-CONTRIB-2024-003
Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication Abuse.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.5.0.
5.4
CVE-2024-13238 - Typogrify - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-002
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Typogrify allows Cross-Site Scripting (XSS).This issue affects Typogrify: from 0.0.0 before 1.3.0.
8.2
CVE-2025-21598 - Junos OS and Junos OS Evolved: When BGP traceoptions are configured, receipt of malformed BGP packeβ¦
AnΒ Out-of-bounds Read vulnerability in Juniper Networks Junos OS and Junos OS Evolved's routing protocol daemon (rpd) allows an unauthenticated, network-based attacker to sendΒ malformed BGP packets to a device configured with packet receive trace options enabled to crash rpd. This issue affects: Jβ¦
5.4
CVE-2024-13237 - File Entity (fieldable files) - Moderately critical - Cross Site Scripting, Access bypass - SA-CONTβ¦
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal File Entity (fieldable files) allows Cross-Site Scripting (XSS).This issue affects File Entity (fieldable files): from 7.X-* before 7.X-2.38.