Export limit exceeded: 15784 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 386040 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (386040 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-81269 | 1 Drupal | 1 Data Field | 2026-09-02 | 5.3 Medium |
| Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13. | ||||
| CVE-2026-81168 | 1 Drupal | 1 Captcha Protected Page | 2026-09-02 | 3.7 Low |
| Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2. | ||||
| CVE-2026-81166 | 1 Drupal | 1 Digital Signage Framework | 2026-09-02 | 5.3 Medium |
| Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1. | ||||
| CVE-2026-81165 | 1 Drupal | 1 Blazy | 2026-09-02 | 5.3 Medium |
| Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18. | ||||
| CVE-2026-81162 | 1 Drupal | 1 Dxpr Builder: The Best Editing (ai) Experience For Drupal | 2026-09-02 | 5.3 Medium |
| Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1. | ||||
| CVE-2026-81161 | 1 Drupal | 1 Content Moderation Notifications | 2026-09-02 | 3.3 Low |
| Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0. | ||||
| CVE-2026-77125 | 1 Sonatype | 1 Nexus Repository Manager | 2026-09-02 | N/A |
| A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobstore group management REST API endpoints did not correctly enforce the intended authorization check. A user granted only the nexus:blobstores:create permission could invoke these endpoints to convert an existing blobstore into a group blobstore, an action that should require the nexus:blobstores:update permission instead. This could result in unauthorized modification of blobstore configuration without administrator approval. The nexus:blobstores:create permission is a named permission that must be explicitly granted by an administrator; it is not held by default. | ||||
| CVE-2026-76759 | 1 Drupal | 1 Screenshot | 2026-09-02 | 7.3 High |
| Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*. | ||||
| CVE-2026-76758 | 1 Drupal | 1 Link Content Parser | 2026-09-02 | 5.9 Medium |
| Vulnerability in Drupal Link content parser. This issue affects Link content parser versions: *.*. | ||||
| CVE-2026-76757 | 1 Drupal | 1 Gammu Sms Daemon | 2026-09-02 | 5.9 Medium |
| Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*. | ||||
| CVE-2026-76756 | 1 Drupal | 1 Gammu Sms Daemon | 2026-09-02 | 5.9 Medium |
| Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*. | ||||
| CVE-2026-73731 | 1 Hewlett Packard Enterprise (hpe) | 1 Fabric Composer | 2026-09-02 | 6.1 Medium |
| A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. | ||||
| CVE-2026-73729 | 1 Hewlett Packard Enterprise (hpe) | 1 Fabric Composer | 2026-09-02 | 6.5 Medium |
| A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to upstream AFC dependencies to view sensitive information. Successful exploitation could allow an attacker to access data beyond what is authorized by the user's existing privilege level, potentially leading to further unauthorized access. | ||||
| CVE-2026-73477 | 1 Drupal | 1 Quick Tabs | 2026-09-02 | 5.3 Medium |
| Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versions: from 0.0.0 to 4.3.1. | ||||
| CVE-2026-73476 | 1 Drupal | 1 External Authentication | 2026-09-02 | 5.4 Medium |
| Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13. | ||||
| CVE-2026-73475 | 1 Drupal | 1 Commerce Paypal | 2026-09-02 | 9.1 Critical |
| Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3. | ||||
| CVE-2026-75134 | 2026-09-02 | 6.4 Medium | ||
| SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permissive KSES allowlist that explicitly permits the onload event handler on iframe elements. Attackers can store crafted JavaScript payloads in post content that execute when the affected post is viewed or previewed by higher-privileged users, potentially leading to privilege escalation or account compromise. | ||||
| CVE-2026-54789 | 1 Openidc | 1 Mod Auth Openidc | 2026-09-02 | 7.5 High |
| mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`. The issue is fixed in version 2.4.19.4 by stopping the scan at the string terminator so a value-less token is rejected. No in-product workarounds are available. As a stop-gap, an upstream reverse proxy or WAF that rejects or normalizes malformed `Cookie` headers (tokens lacking `=`) can reduce exposure, but upgrading is the recommended remediation. | ||||
| CVE-2026-53670 | 2026-09-02 | N/A | ||
| PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, in the Prevail eBPF verifier, EbpfTransformer::add() silently skips offset-variable updates when the destination register carries a non-singleton typeset (two or more simultaneously possible pointer types). Subsequent bounds checks use the stale offset and accept out-of-bounds memory accesses, so a crafted BPF program passes verification even though it would corrupt memory at runtime. This issue has been patched in version 0.2.4. | ||||
| CVE-2026-52131 | 1 Ggml-org | 1 Llama.cpp | 2026-09-02 | 7.5 High |
| llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::read function. | ||||
