8.8

CVSS3.1

CVE-2024-13250 - Drupal Symfony Mailer Lite - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2024-014

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Drupal Symfony Mailer Lite allows Cross Site Request Forgery.This issue affects Drupal Symfony Mailer Lite: from 0.0.0 before 1.0.6.

๐Ÿ“… Published: Jan. 9, 2025, 6:57 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 4:28 p.m.

5.4

CVSS3.1

CVE-2024-13249 - Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-013

Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 7.X-1.0 before 7.X-1.2.

๐Ÿ“… Published: Jan. 9, 2025, 6:55 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 3:59 p.m.

5.5

CVSS3.1

CVE-2024-13248 - Private content - Moderately critical - Access bypass - SA-CONTRIB-2024-012

Incorrect Privilege Assignment vulnerability in Drupal Private content allows Target Influence via Framing.This issue affects Private content: from 0.0.0 before 2.1.0.

๐Ÿ“… Published: Jan. 9, 2025, 6:53 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 3:58 p.m.

4.8

CVSS3.1

CVE-2024-13247 - Coffee - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-011

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Coffee allows Cross-Site Scripting (XSS).This issue affects Coffee: from 0.0.0 before 1.4.0.

๐Ÿ“… Published: Jan. 9, 2025, 6:53 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 3:23 p.m.

5.3

CVSS3.1

CVE-2024-13246 - Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-010

Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 0.0.0 before 2.0.2.

๐Ÿ“… Published: Jan. 9, 2025, 6:52 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 3:18 p.m.

3.7

CVSS3.1

CVE-2025-22151 - Strawberry GraphQL has a type resolution vulnerability

Strawberry GraphQL is a library for creating GraphQL APIs. Starting in 0.182.0 and prior to version 0.257.0, a type confusion vulnerability exists in Strawberry GraphQL's relay integration that affects multiple ORM integrations (Django, SQLAlchemy, Pydantic). The vulnerability occurs when multiple โ€ฆ

๐Ÿ“… Published: Jan. 9, 2025, 6:51 p.m. ๐Ÿ”„ Last Modified: Jan. 9, 2025, 8:09 p.m.

5.4

CVSS3.1

CVE-2024-13245 - CKEditor 4 LTS - WYSIWYG HTML editor - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024โ€ฆ

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor 4 LTS - WYSIWYG HTML editor allows Cross-Site Scripting (XSS).This issue affects CKEditor 4 LTS - WYSIWYG HTML editor: from 1.0.0 before 1.0.1.

๐Ÿ“… Published: Jan. 9, 2025, 6:51 p.m. ๐Ÿ”„ Last Modified: July 7, 2025, 3:03 p.m.

8.8

CVSS3.1

CVE-2024-13244 - Migrate Tools - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2024-008

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate Tools allows Cross Site Request Forgery.This issue affects Migrate Tools: from 0.0.0 before 6.0.3.

๐Ÿ“… Published: Jan. 9, 2025, 6:50 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 4:55 p.m.

6.5

CVSS3.1

CVE-2024-13243 - Entity Delete Log - Moderately critical - Access bypass - SA-CONTRIB-2024-007

Missing Authorization vulnerability in Drupal Entity Delete Log allows Forceful Browsing.This issue affects Entity Delete Log: from 0.0.0 before 1.1.1.

๐Ÿ“… Published: Jan. 9, 2025, 6:49 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 4:50 p.m.

9.1

CVSS3.1

CVE-2024-13242 - Swift Mailer - Moderately critical - Access bypass - SA-CONTRIB-2024-006

Exposed Dangerous Method or Function vulnerability in Drupal Swift Mailer allows Resource Location Spoofing.This issue affects Swift Mailer: *.*.

๐Ÿ“… Published: Jan. 9, 2025, 6:49 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 4:49 p.m.
Total resulsts: 343887
Page 6672 of 34,389
ยซ previous page ยป next page
Filters