Latest CVE Feed
-
7.6
HIGHCVE-2024-5746
A Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with the Site Administrator role to gain arbitrary code execution capability on the GitHub Enterprise Server instance. Exploitation required au... Read more
Affected Products : enterprise_server- Published: Jun. 20, 2024
- Modified: Aug. 27, 2025
-
10.0
CRITICALCVE-2024-4985
An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication with the optional encrypted assertions feature. This vulnerability allowed an attacker to forge a SAML response to ... Read more
Affected Products : enterprise_server- Published: May. 20, 2024
- Modified: Aug. 27, 2025
-
9.8
CRITICALCVE-2024-11122
A vulnerability, which was classified as critical, has been found in 上海灵当信息科技有限公司 Lingdang CRM up to 8.6.4.3. Affected by this issue is some unknown functionality of the file /crm/wechatSession/index.php?msgid=1&operation=upload. The manipulation of the a... Read more
Affected Products : lingdang_crm- Published: Nov. 12, 2024
- Modified: Aug. 27, 2025
-
7.5
HIGHCVE-2024-11123
A vulnerability, which was classified as problematic, was found in 上海灵当信息科技有限公司 Lingdang CRM up to 8.6.4.3. This affects an unknown part of the file /crm/data/pdf.php. The manipulation of the argument url with the input ../config.inc.php leads to path tra... Read more
Affected Products : lingdang_crm- Published: Nov. 12, 2024
- Modified: Aug. 27, 2025
-
3.5
LOWCVE-2024-13261
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia DAM allows Cross Site Request Forgery.This issue affects Acquia DAM: from 0.0.0 before 1.0.13, from 1.1.0 before 1.1.0-beta3.... Read more
Affected Products : dam- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.5
MEDIUMCVE-2024-13263
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno group manager allows PHP Local File Inclusion.This issue affects Opigno group manager: from 0.0.0 before 3.1.1.... Read more
Affected Products : group_manager- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-13264
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno module allows PHP Local File Inclusion.This issue affects Opigno module: from 0.0.0 before 3.1.2.... Read more
Affected Products : opigno_module- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2024-13265
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno Learning path allows PHP Local File Inclusion.This issue affects Opigno Learning path: from 0.0.0 before 3.1.2.... Read more
Affected Products : learning_path- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2024-13266
Incorrect Authorization vulnerability in Drupal Responsive and off-canvas menu allows Forceful Browsing.This issue affects Responsive and off-canvas menu: from 0.0.0 before 4.4.4.... Read more
Affected Products : responsive_and_off-canvas_menu- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-13267
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno TinCan Question Type allows PHP Local File Inclusion.This issue affects Opigno TinCan Question Type: from 7.X-1.0 before 7.X-1.3.... Read more
Affected Products : tincan_question_type- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Injection
-
6.8
MEDIUMCVE-2024-13268
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno allows PHP Local File Inclusion.This issue affects Opigno: from 7.X-1.0 before 7.X-1.23.... Read more
Affected Products : opigno- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2024-13269
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Advanced Varnish allows Forceful Browsing.This issue affects Advanced Varnish: from 0.0.0 before 4.0.11.... Read more
Affected Products : advanced_varnish- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-13270
Incorrect Authorization vulnerability in Drupal Freelinking allows Forceful Browsing.This issue affects Freelinking: from 0.0.0 before 4.0.1.... Read more
Affected Products : freelinking- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-13271
Incorrect Authorization vulnerability in Drupal Content Entity Clone allows Forceful Browsing.This issue affects Content Entity Clone: from 0.0.0 before 1.0.4.... Read more
Affected Products : content_entity_clone- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Authorization
-
6.3
MEDIUMCVE-2024-13272
Insufficient Granularity of Access Control vulnerability in Drupal Paragraphs table allows Content Spoofing.This issue affects Paragraphs table: from 0.0.0 before 1.23.0, from 2.0.0 before 2.0.2.... Read more
Affected Products : paragraphs_table- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Authorization
-
6.3
MEDIUMCVE-2025-9005
A vulnerability was determined in mtons mblog up to 3.5.0. Affected is an unknown function of the file /register. The manipulation leads to information exposure through error message. It is possible to launch the attack remotely. The complexity of an atta... Read more
Affected Products : mblog- Published: Aug. 15, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2022-38129
A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Management Server (SMS). This allows an unauthenticated remote attacker to upload arbitrary files to the SMS host.... Read more
Affected Products : sensor_management_server- EPSS Score: %3.73
- Published: Aug. 10, 2022
- Modified: Aug. 27, 2025
-
7.5
HIGHCVE-2022-36923
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain... Read more
- EPSS Score: %0.27
- Published: Aug. 10, 2022
- Modified: Aug. 27, 2025
-
4.7
MEDIUMCVE-2022-34704
Windows Defender Credential Guard Information Disclosure Vulnerability... Read more
Affected Products : windows_10 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_20h2 windows_10_21h2 windows_server_2022 windows_11_21h2 windows_11 +4 more products- EPSS Score: %1.73
- Published: Aug. 09, 2022
- Modified: Aug. 27, 2025
-
4.3
MEDIUMCVE-2022-31674
VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can access log files that lead to information disclosure.... Read more
Affected Products : vrealize_operations- EPSS Score: %0.36
- Published: Aug. 10, 2022
- Modified: Aug. 27, 2025