Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

43798
Total
3549
Critical
13122
High
12955
Medium
CVE ID Severity Score Description Published
CVE-2026-44476 UNKNOWN Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is … Aug 25, 2026
CVE-2026-41707 HIGH 7.4 Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID … Aug 25, 2026
CVE-2026-18985 HIGH 8.1 Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1. Aug 25, 2026
CVE-2026-18261 MEDIUM 5.7 Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*. Aug 25, 2026
CVE-2026-18260 MEDIUM 5.7 Vulnerability in Drupal Disable Login Page. This issue affects Disable Login Page versions: *.*. Aug 25, 2026
CVE-2026-18259 HIGH 7.5 Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2. Aug 25, 2026
CVE-2026-16646 MEDIUM 5.7 Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*. Aug 25, 2026
CVE-2026-16645 CRITICAL 9.1 Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery … Aug 25, 2026
CVE-2026-16644 CRITICAL 9.1 Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0. Aug 25, 2026
CVE-2026-16643 MEDIUM 5.7 Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*. Aug 25, 2026
CVE-2026-16642 MEDIUM 5.7 Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*. Aug 25, 2026
CVE-2026-16641 CRITICAL 9.8 Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*. Aug 25, 2026
CVE-2026-16640 MEDIUM 6.1 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API Autocomplete allows Reflected XSS. This issue affects Search API Autocomplete … Aug 25, 2026
CVE-2026-16639 CRITICAL 9.8 Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from … Aug 25, 2026
CVE-2026-16638 MEDIUM 6.1 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders allows Stored XSS. This issue affects Media Folders versions: from … Aug 25, 2026
CVE-2026-15917 MEDIUM 4.7 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: … Aug 25, 2026
CVE-2026-15916 MEDIUM 4.2 Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from … Aug 25, 2026
CVE-2026-15088 MEDIUM 5.7 Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*. Aug 25, 2026
CVE-2026-79804 HIGH 7.3 A vulnerability was found in SililaWijesinghe Food Ordering System up to ba314e897e3365600461e5ea59432e39ceaa0fa5. Affected by this issue is some unknown functionality of the file /search.php. Performing … Aug 25, 2026
CVE-2026-78655 UNKNOWN Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts … Aug 25, 2026
CVE-2026-78619 UNKNOWN Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically. The helper searches the … Aug 25, 2026
CVE-2026-73180 UNKNOWN Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had … Aug 25, 2026
CVE-2026-68763 UNKNOWN Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache … Aug 25, 2026
CVE-2026-68569 UNKNOWN Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did … Aug 25, 2026
CVE-2026-68525 UNKNOWN Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST … Aug 25, 2026