Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43798
Total
3549
Critical
13122
High
12955
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-44476 | UNKNOWN | — | Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is … | Aug 25, 2026 |
| CVE-2026-41707 | HIGH | 7.4 | Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID … | Aug 25, 2026 |
| CVE-2026-18985 | HIGH | 8.1 | Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1. | Aug 25, 2026 |
| CVE-2026-18261 | MEDIUM | 5.7 | Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*. | Aug 25, 2026 |
| CVE-2026-18260 | MEDIUM | 5.7 | Vulnerability in Drupal Disable Login Page. This issue affects Disable Login Page versions: *.*. | Aug 25, 2026 |
| CVE-2026-18259 | HIGH | 7.5 | Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2. | Aug 25, 2026 |
| CVE-2026-16646 | MEDIUM | 5.7 | Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*. | Aug 25, 2026 |
| CVE-2026-16645 | CRITICAL | 9.1 | Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery … | Aug 25, 2026 |
| CVE-2026-16644 | CRITICAL | 9.1 | Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0. | Aug 25, 2026 |
| CVE-2026-16643 | MEDIUM | 5.7 | Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*. | Aug 25, 2026 |
| CVE-2026-16642 | MEDIUM | 5.7 | Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*. | Aug 25, 2026 |
| CVE-2026-16641 | CRITICAL | 9.8 | Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*. | Aug 25, 2026 |
| CVE-2026-16640 | MEDIUM | 6.1 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API Autocomplete allows Reflected XSS. This issue affects Search API Autocomplete … | Aug 25, 2026 |
| CVE-2026-16639 | CRITICAL | 9.8 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from … | Aug 25, 2026 |
| CVE-2026-16638 | MEDIUM | 6.1 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders allows Stored XSS. This issue affects Media Folders versions: from … | Aug 25, 2026 |
| CVE-2026-15917 | MEDIUM | 4.7 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: … | Aug 25, 2026 |
| CVE-2026-15916 | MEDIUM | 4.2 | Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from … | Aug 25, 2026 |
| CVE-2026-15088 | MEDIUM | 5.7 | Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*. | Aug 25, 2026 |
| CVE-2026-79804 | HIGH | 7.3 | A vulnerability was found in SililaWijesinghe Food Ordering System up to ba314e897e3365600461e5ea59432e39ceaa0fa5. Affected by this issue is some unknown functionality of the file /search.php. Performing … | Aug 25, 2026 |
| CVE-2026-78655 | UNKNOWN | — | Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts … | Aug 25, 2026 |
| CVE-2026-78619 | UNKNOWN | — | Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically. The helper searches the … | Aug 25, 2026 |
| CVE-2026-73180 | UNKNOWN | — | Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had … | Aug 25, 2026 |
| CVE-2026-68763 | UNKNOWN | — | Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache … | Aug 25, 2026 |
| CVE-2026-68569 | UNKNOWN | — | Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did … | Aug 25, 2026 |
| CVE-2026-68525 | UNKNOWN | — | Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST … | Aug 25, 2026 |