Latest CVE Feed
-
4.3
MEDIUMCVE-2024-13270
Incorrect Authorization vulnerability in Drupal Freelinking allows Forceful Browsing.This issue affects Freelinking: from 0.0.0 before 4.0.1.... Read more
Affected Products : freelinking- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2024-13269
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Advanced Varnish allows Forceful Browsing.This issue affects Advanced Varnish: from 0.0.0 before 4.0.11.... Read more
Affected Products : advanced_varnish- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Authorization
-
6.8
MEDIUMCVE-2024-13268
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno allows PHP Local File Inclusion.This issue affects Opigno: from 7.X-1.0 before 7.X-1.23.... Read more
Affected Products : opigno- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2024-13267
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno TinCan Question Type allows PHP Local File Inclusion.This issue affects Opigno TinCan Question Type: from 7.X-1.0 before 7.X-1.3.... Read more
Affected Products : tincan_question_type- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2024-13266
Incorrect Authorization vulnerability in Drupal Responsive and off-canvas menu allows Forceful Browsing.This issue affects Responsive and off-canvas menu: from 0.0.0 before 4.4.4.... Read more
Affected Products : responsive_and_off-canvas_menu- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-13265
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno Learning path allows PHP Local File Inclusion.This issue affects Opigno Learning path: from 0.0.0 before 3.1.2.... Read more
Affected Products : learning_path- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-13264
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno module allows PHP Local File Inclusion.This issue affects Opigno module: from 0.0.0 before 3.1.2.... Read more
Affected Products : opigno_module- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2024-13263
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno group manager allows PHP Local File Inclusion.This issue affects Opigno group manager: from 0.0.0 before 3.1.1.... Read more
Affected Products : group_manager- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2024-13262
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal View Password allows Cross-Site Scripting (XSS).This issue affects View Password: from 0.0.0 before 6.0.4.... Read more
Affected Products : view_password- Published: Jan. 09, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2024-13261
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia DAM allows Cross Site Request Forgery.This issue affects Acquia DAM: from 0.0.0 before 1.0.13, from 1.1.0 before 1.1.0-beta3.... Read more
Affected Products : dam- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2024-13260
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate queue importer allows Cross Site Request Forgery.This issue affects Migrate queue importer: from 0.0.0 before 2.1.1.... Read more
Affected Products : migrate_queue_importer- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.8
CRITICALCVE-2024-10215
The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resourc... Read more
- Published: Jan. 09, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Authentication
-
3.7
LOWCVE-2025-22151
Strawberry GraphQL is a library for creating GraphQL APIs. Starting in 0.182.0 and prior to version 0.257.0, a type confusion vulnerability exists in Strawberry GraphQL's relay integration that affects multiple ORM integrations (Django, SQLAlchemy, Pydant... Read more
Affected Products : strawberry- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Information Disclosure
-
8.2
HIGHCVE-2025-21598
An Out-of-bounds Read vulnerability in Juniper Networks Junos OS and Junos OS Evolved's routing protocol daemon (rpd) allows an unauthenticated, network-based attacker to send malformed BGP packets to a device configured with packet receive trace options ... Read more
- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-13259
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Image Sizes allows Forceful Browsing.This issue affects Image Sizes: from 0.0.0 before 3.0.2.... Read more
Affected Products : image_sizes- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2024-13258
Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issue affects Drupal REST & JSON API Authentication: from 0.0.0 before 2.0.13.... Read more
Affected Products : rest_\&_json_api_authentication- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2024-13257
Incorrect Authorization vulnerability in Drupal Commerce View Receipt allows Forceful Browsing.This issue affects Commerce View Receipt: from 0.0.0 before 1.0.3.... Read more
Affected Products : commerce_view_receipt- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-13256
Insufficient Granularity of Access Control vulnerability in Drupal Email Contact allows Forceful Browsing.This issue affects Email Contact: from 0.0.0 before 2.0.4.... Read more
Affected Products : email_contact- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-13255
Exposure of Sensitive Information Through Data Queries vulnerability in Drupal RESTful Web Services allows Forceful Browsing.This issue affects RESTful Web Services: from 7.X-2.0 before 7.X-2.10.... Read more
Affected Products : restful_web_services- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-13254
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal REST Views allows Forceful Browsing.This issue affects REST Views: from 0.0.0 before 3.0.1.... Read more
Affected Products : rest_views- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Information Disclosure