8.8

CVSS3.1

CVE-2025-21385 - Microsoft Purview Information Disclosure Vulnerability

A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network.

๐Ÿ“… Published: Jan. 9, 2025, 10:07 p.m. ๐Ÿ”„ Last Modified: Feb. 13, 2026, 7:56 p.m.

5.3

CVSS3.1

CVE-2024-13312 - Open Social - Moderately critical - Access bypass - SA-CONTRIB-2024-076

Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 11.8.0 before 12.3.10, from 12.4.0 before 12.4.9.

๐Ÿ“… Published: Jan. 9, 2025, 8:28 p.m. ๐Ÿ”„ Last Modified: Jan. 31, 2025, 4:15 p.m.

7.3

CVSS3.1

CVE-2024-13311 - Allow All File Extensions for file fields - Critical - Unsupported - SA-CONTRIB-2024-075

Vulnerability in Drupal Allow All File Extensions for file fields.This issue affects Allow All File Extensions for file fields: *.*.

๐Ÿ“… Published: Jan. 9, 2025, 8:28 p.m. ๐Ÿ”„ Last Modified: Sept. 2, 2025, 6:29 p.m.

6.5

CVSS3.1

CVE-2024-13310 - Git Utilities for Drupal - Critical - Unsupported - SA-CONTRIB-2024-074

Vulnerability in Drupal Git Utilities for Drupal.This issue affects Git Utilities for Drupal: *.*.

๐Ÿ“… Published: Jan. 9, 2025, 8:27 p.m. ๐Ÿ”„ Last Modified: Sept. 2, 2025, 6:29 p.m.

5.4

CVSS3.1

CVE-2024-13309 - Login Disable - Critical - Access bypass - SA-CONTRIB-2024-073

Improper Authentication vulnerability in Drupal Login Disable allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login Disable: from 2.0.0 before 2.1.1.

๐Ÿ“… Published: Jan. 9, 2025, 8:27 p.m. ๐Ÿ”„ Last Modified: Aug. 28, 2025, 11:26 a.m.

3.8

CVSS3.1

CVE-2024-13308 - Browser Back Button - Moderately critical - Cross site scripting - SA-CONTRIB-2024-072

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Browser Back Button allows Cross-Site Scripting (XSS).This issue affects Browser Back Button: from 1.0.0 before 2.0.2.

๐Ÿ“… Published: Jan. 9, 2025, 8:27 p.m. ๐Ÿ”„ Last Modified: Sept. 5, 2025, 4:51 p.m.

4.8

CVSS3.1

CVE-2024-13305 - Entity Form Steps - Moderately critical - Cross site scripting - SA-CONTRIB-2024-071

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Entity Form Steps allows Cross-Site Scripting (XSS).This issue affects Entity Form Steps: from 0.0.0 before 1.1.4.

๐Ÿ“… Published: Jan. 9, 2025, 8:25 p.m. ๐Ÿ”„ Last Modified: Aug. 28, 2025, 11:32 a.m.

4.5

CVSS3.1

CVE-2024-13304 - Minify JS - Moderately critical - Cross site request forgery - SA-CONTRIB-2024-070

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Minify JS allows Cross Site Request Forgery.This issue affects Minify JS: from 0.0.0 before 3.0.3.

๐Ÿ“… Published: Jan. 9, 2025, 8:25 p.m. ๐Ÿ”„ Last Modified: Aug. 28, 2025, 11:34 a.m.

5.3

CVSS3.1

CVE-2024-13303 - Download All Files - Critical - Access bypass - SA-CONTRIB-2024-069

Missing Authorization vulnerability in Drupal Download All Files allows Forceful Browsing.This issue affects Download All Files: from 0.0.0 before 2.0.2.

๐Ÿ“… Published: Jan. 9, 2025, 8:24 p.m. ๐Ÿ”„ Last Modified: Sept. 2, 2025, 6:29 p.m.

5.3

CVSS3.1

CVE-2024-13302 - Pages Restriction Access - Critical - Access bypass - SA-CONTRIB-2024-068

Incorrect Authorization vulnerability in Drupal Pages Restriction Access allows Forceful Browsing.This issue affects Pages Restriction Access: from 2.0.0 before 2.0.3.

๐Ÿ“… Published: Jan. 9, 2025, 8:24 p.m. ๐Ÿ”„ Last Modified: Sept. 2, 2025, 6:29 p.m.
Total resulsts: 343919
Page 6669 of 34,392
ยซ previous page ยป next page
Filters