Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42028
Total
3422
Critical
12413
High
12340
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-81162 | MEDIUM | 5.3 | Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects … | Sep 02, 2026 |
| CVE-2026-81161 | LOW | 3.3 | Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0. | Sep 02, 2026 |
| CVE-2026-81160 | MEDIUM | 6.1 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Slick Carousel allows Stored XSS. This issue affects Slick Carousel versions: from … | Sep 02, 2026 |
| CVE-2026-81159 | LOW | 3.7 | Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0. | Sep 02, 2026 |
| CVE-2026-81158 | MEDIUM | 5.3 | Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0. | Sep 02, 2026 |
| CVE-2026-76782 | HIGH | 7.3 | Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*. | Sep 02, 2026 |
| CVE-2026-76759 | HIGH | 7.3 | Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*. | Sep 02, 2026 |
| CVE-2026-76758 | MEDIUM | 5.9 | Vulnerability in Drupal Link content parser. This issue affects Link content parser versions: *.*. | Sep 02, 2026 |
| CVE-2026-76757 | MEDIUM | 5.9 | Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*. | Sep 02, 2026 |
| CVE-2026-76756 | MEDIUM | 5.9 | Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*. | Sep 02, 2026 |
| CVE-2026-76755 | MEDIUM | 5.9 | Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*. | Sep 02, 2026 |
| CVE-2026-73478 | MEDIUM | 5.3 | Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1. | Sep 02, 2026 |
| CVE-2026-73477 | MEDIUM | 5.3 | Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versions: from 0.0.0 to 4.3.1. | Sep 02, 2026 |
| CVE-2026-73476 | MEDIUM | 5.4 | Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13. | Sep 02, 2026 |
| CVE-2026-73475 | CRITICAL | 9.1 | Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3. | Sep 02, 2026 |
| CVE-2026-73474 | MEDIUM | 5.3 | Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery. This issue affects Entity Share Websub versions: from 0.0.0 to … | Sep 02, 2026 |
| CVE-2026-18986 | MEDIUM | 4.8 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Browser allows Stored XSS. This issue affects Entity Browser versions: from … | Sep 02, 2026 |
| CVE-2026-16647 | UNKNOWN | — | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from … | Sep 02, 2026 |
| CVE-2026-84835 | MEDIUM | 5.3 | Missing Authorization vulnerability in DimaFreund Rentsyst allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Rentsyst: from n/a through 2.1.2. | Sep 02, 2026 |
| CVE-2026-84808 | MEDIUM | 4.3 | Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collection endpoint that fails to enforce activity-team access controls. Users with … | Sep 02, 2026 |
| CVE-2026-84807 | MEDIUM | 5.4 | Kimai (kimai/kimai) through 2.65.0 contains a business logic / improper authorization vulnerability in the default team creation endpoints. An authenticated user with project permission-management privileges … | Sep 02, 2026 |
| CVE-2026-84806 | MEDIUM | 5.4 | Kimai before 2.63.0 contains an improper authorization vulnerability in team access endpoints that allows authenticated users with team edit permissions and read-only access to grant … | Sep 02, 2026 |
| CVE-2026-84805 | MEDIUM | 4.3 | Kimai versions from 2.61.0 before 2.63.0 fail to disable admin-only work-contract preferences for low-privilege users in the PATCH /api/users/{id}/preferences endpoint. Although the web interface gates … | Sep 02, 2026 |
| CVE-2026-84804 | MEDIUM | 5.4 | Kimai before 2.65.0 fails to properly validate permissions when removing team access to activities, projects, and customers via API endpoints. Authenticated users with edit_team permission … | Sep 02, 2026 |
| CVE-2026-84803 | CRITICAL | 9.0 | SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. Attackers can … | Sep 02, 2026 |