Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42028
Total
3422
Critical
12413
High
12340
Medium
CVE ID Severity Score Description Published
CVE-2026-81162 MEDIUM 5.3 Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects … Sep 02, 2026
CVE-2026-81161 LOW 3.3 Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0. Sep 02, 2026
CVE-2026-81160 MEDIUM 6.1 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Slick Carousel allows Stored XSS. This issue affects Slick Carousel versions: from … Sep 02, 2026
CVE-2026-81159 LOW 3.7 Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0. Sep 02, 2026
CVE-2026-81158 MEDIUM 5.3 Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0. Sep 02, 2026
CVE-2026-76782 HIGH 7.3 Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*. Sep 02, 2026
CVE-2026-76759 HIGH 7.3 Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*. Sep 02, 2026
CVE-2026-76758 MEDIUM 5.9 Vulnerability in Drupal Link content parser. This issue affects Link content parser versions: *.*. Sep 02, 2026
CVE-2026-76757 MEDIUM 5.9 Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*. Sep 02, 2026
CVE-2026-76756 MEDIUM 5.9 Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*. Sep 02, 2026
CVE-2026-76755 MEDIUM 5.9 Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*. Sep 02, 2026
CVE-2026-73478 MEDIUM 5.3 Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1. Sep 02, 2026
CVE-2026-73477 MEDIUM 5.3 Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versions: from 0.0.0 to 4.3.1. Sep 02, 2026
CVE-2026-73476 MEDIUM 5.4 Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13. Sep 02, 2026
CVE-2026-73475 CRITICAL 9.1 Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3. Sep 02, 2026
CVE-2026-73474 MEDIUM 5.3 Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery. This issue affects Entity Share Websub versions: from 0.0.0 to … Sep 02, 2026
CVE-2026-18986 MEDIUM 4.8 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Browser allows Stored XSS. This issue affects Entity Browser versions: from … Sep 02, 2026
CVE-2026-16647 UNKNOWN Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from … Sep 02, 2026
CVE-2026-84835 MEDIUM 5.3 Missing Authorization vulnerability in DimaFreund Rentsyst allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Rentsyst: from n/a through 2.1.2. Sep 02, 2026
CVE-2026-84808 MEDIUM 4.3 Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collection endpoint that fails to enforce activity-team access controls. Users with … Sep 02, 2026
CVE-2026-84807 MEDIUM 5.4 Kimai (kimai/kimai) through 2.65.0 contains a business logic / improper authorization vulnerability in the default team creation endpoints. An authenticated user with project permission-management privileges … Sep 02, 2026
CVE-2026-84806 MEDIUM 5.4 Kimai before 2.63.0 contains an improper authorization vulnerability in team access endpoints that allows authenticated users with team edit permissions and read-only access to grant … Sep 02, 2026
CVE-2026-84805 MEDIUM 4.3 Kimai versions from 2.61.0 before 2.63.0 fail to disable admin-only work-contract preferences for low-privilege users in the PATCH /api/users/{id}/preferences endpoint. Although the web interface gates … Sep 02, 2026
CVE-2026-84804 MEDIUM 5.4 Kimai before 2.65.0 fails to properly validate permissions when removing team access to activities, projects, and customers via API endpoints. Authenticated users with edit_team permission … Sep 02, 2026
CVE-2026-84803 CRITICAL 9.0 SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. Attackers can … Sep 02, 2026