Latest CVE Feed
-
3.5
LOWCVE-2024-13261
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia DAM allows Cross Site Request Forgery.This issue affects Acquia DAM: from 0.0.0 before 1.0.13, from 1.1.0 before 1.1.0-beta3.... Read more
Affected Products : dam- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2024-13260
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate queue importer allows Cross Site Request Forgery.This issue affects Migrate queue importer: from 0.0.0 before 2.1.1.... Read more
Affected Products : migrate_queue_importer- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.8
CRITICALCVE-2024-10215
The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resourc... Read more
- Published: Jan. 09, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Authentication
-
3.7
LOWCVE-2025-22151
Strawberry GraphQL is a library for creating GraphQL APIs. Starting in 0.182.0 and prior to version 0.257.0, a type confusion vulnerability exists in Strawberry GraphQL's relay integration that affects multiple ORM integrations (Django, SQLAlchemy, Pydant... Read more
Affected Products : strawberry- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Information Disclosure
-
8.2
HIGHCVE-2025-21598
An Out-of-bounds Read vulnerability in Juniper Networks Junos OS and Junos OS Evolved's routing protocol daemon (rpd) allows an unauthenticated, network-based attacker to send malformed BGP packets to a device configured with packet receive trace options ... Read more
- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-13259
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Image Sizes allows Forceful Browsing.This issue affects Image Sizes: from 0.0.0 before 3.0.2.... Read more
Affected Products : image_sizes- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2024-13258
Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issue affects Drupal REST & JSON API Authentication: from 0.0.0 before 2.0.13.... Read more
Affected Products : rest_\&_json_api_authentication- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2024-13257
Incorrect Authorization vulnerability in Drupal Commerce View Receipt allows Forceful Browsing.This issue affects Commerce View Receipt: from 0.0.0 before 1.0.3.... Read more
Affected Products : commerce_view_receipt- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-13256
Insufficient Granularity of Access Control vulnerability in Drupal Email Contact allows Forceful Browsing.This issue affects Email Contact: from 0.0.0 before 2.0.4.... Read more
Affected Products : email_contact- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-13255
Exposure of Sensitive Information Through Data Queries vulnerability in Drupal RESTful Web Services allows Forceful Browsing.This issue affects RESTful Web Services: from 7.X-2.0 before 7.X-2.10.... Read more
Affected Products : restful_web_services- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-13254
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal REST Views allows Forceful Browsing.This issue affects REST Views: from 0.0.0 before 3.0.1.... Read more
Affected Products : rest_views- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Information Disclosure
-
9.1
CRITICALCVE-2024-13253
Incorrect Authorization vulnerability in Drupal Advanced PWA inc Push Notifications allows Forceful Browsing.This issue affects Advanced PWA inc Push Notifications: from 0.0.0 before 1.5.0.... Read more
Affected Products : advanced_pwa_inc_push_notifications- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2024-13252
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal TacJS allows Cross-Site Scripting (XSS).This issue affects TacJS: from 0.0.0 before 6.5.0.... Read more
Affected Products : tacjs- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2024-13251
Incorrect Privilege Assignment vulnerability in Drupal Registration role allows Privilege Escalation.This issue affects Registration role: from 0.0.0 before 2.0.1.... Read more
Affected Products : registration_role- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2024-13250
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Drupal Symfony Mailer Lite allows Cross Site Request Forgery.This issue affects Drupal Symfony Mailer Lite: from 0.0.0 before 1.0.6.... Read more
Affected Products : drupal_symfony_mailer_lite- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2024-13249
Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 7.X-1.0 before 7.X-1.2.... Read more
Affected Products : node_access_rebuild_progressive- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2024-13248
Incorrect Privilege Assignment vulnerability in Drupal Private content allows Target Influence via Framing.This issue affects Private content: from 0.0.0 before 2.1.0.... Read more
Affected Products : private_content- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
4.8
MEDIUMCVE-2024-13247
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Coffee allows Cross-Site Scripting (XSS).This issue affects Coffee: from 0.0.0 before 1.4.0.... Read more
Affected Products : coffee- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2024-13246
Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 0.0.0 before 2.0.2.... Read more
Affected Products : node_access_rebuild_progressive- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Misconfiguration
-
5.4
MEDIUMCVE-2024-13245
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor 4 LTS - WYSIWYG HTML editor allows Cross-Site Scripting (XSS).This issue affects CKEditor 4 LTS - WYSIWYG HTML editor: from 1.0.0 before ... Read more
Affected Products : ckeditor_4- Published: Jan. 09, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cross-Site Scripting