Latest CVE Feed
-
9.8
CRITICALCVE-2024-54724
PHPYun before 7.0.2 is vulnerable to code execution through backdoor-restricted arbitrary file writing and file inclusion.... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 21, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2024-46505
Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 23, 2025
-
5.4
MEDIUMCVE-2024-42898
A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Account Settings page.... Read more
Affected Products : nagios_xi- Published: Jan. 09, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-13287
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Views SVG Animation allows Cross-Site Scripting (XSS).This issue affects Views SVG Animation: from 0.0.0 before 1.0.1.... Read more
Affected Products : views_svg_animation- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-13286
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal SVG Embed allows Cross-Site Scripting (XSS).This issue affects SVG Embed: from 0.0.0 before 2.1.2.... Read more
Affected Products : svg_embed- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2024-13285
Vulnerability in Drupal wkhtmltopdf.This issue affects wkhtmltopdf: *.*.... Read more
Affected Products : wkhtmltopdf- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
-
8.8
HIGHCVE-2024-13284
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Gutenberg allows Cross Site Request Forgery.This issue affects Gutenberg: from 0.0.0 before 2.13.0, from 3.0.0 before 3.0.5.... Read more
Affected Products : gutenberg- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.1
MEDIUMCVE-2024-13283
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Facets allows Cross-Site Scripting (XSS).This issue affects Facets: from 0.0.0 before 2.0.9.... Read more
Affected Products : facets- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2024-13282
Incorrect Authorization vulnerability in Drupal Block permissions allows Forceful Browsing.This issue affects Block permissions: from 1.0.0 before 1.2.0.... Read more
Affected Products : block_permissions- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authorization
-
9.1
CRITICALCVE-2024-13281
Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue affects Monster Menus: from 0.0.0 before 9.3.2.... Read more
Affected Products : monster_menus- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-13280
Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Persistent Login: from 0.0.0 before 1.8.0, from 2.0.* before 2.2.2.... Read more
Affected Products : persistent_login- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-13279
Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.8.0.... Read more
Affected Products : two-factor_authentication- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2024-13278
Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 before 1.8.0.... Read more
Affected Products : diff- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authorization
-
9.1
CRITICALCVE-2024-13277
Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Browsing.This issue affects Smart IP Ban: from 7.X-1.0 before 7.X-1.1.... Read more
Affected Products : smart_ip_ban- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-13276
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal File Entity (fieldable files) allows Forceful Browsing.This issue affects File Entity (fieldable files): from 7.X-* before 7.X-2.39.... Read more
Affected Products : file_entity- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Information Disclosure
-
5.3
MEDIUMCVE-2024-13275
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Drupal Security Kit allows HTTP DoS.This issue affects Security Kit: from 0.0.0 before 2.0.3.... Read more
Affected Products : security_kit- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2024-13274
Improper Control of Interaction Frequency vulnerability in Drupal Open Social allows Functionality Misuse.This issue affects Open Social: from 0.0.0 before 12.3.8, from 12.4.0 before 12.4.5.... Read more
Affected Products : open_social- Published: Jan. 09, 2025
- Modified: Jan. 14, 2025
-
5.4
MEDIUMCVE-2024-13273
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Open Social allows Cross-Site Scripting (XSS).This issue affects Open Social: from 0.0.0 before 12.3.8, from 12.4.0 before 12.4.5, from 13.0.0 bef... Read more
Affected Products : open_social- Published: Jan. 09, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Cross-Site Scripting
-
6.3
MEDIUMCVE-2024-13272
Insufficient Granularity of Access Control vulnerability in Drupal Paragraphs table allows Content Spoofing.This issue affects Paragraphs table: from 0.0.0 before 1.23.0, from 2.0.0 before 2.0.2.... Read more
Affected Products : paragraphs_table- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-13271
Incorrect Authorization vulnerability in Drupal Content Entity Clone allows Forceful Browsing.This issue affects Content Entity Clone: from 0.0.0 before 1.0.4.... Read more
Affected Products : content_entity_clone- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Authorization