Export limit exceeded: 383071 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 383071 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 383071 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (383071 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-15916 | 2026-08-25 | N/A | ||
| Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*. | ||||
| CVE-2026-15917 | 2026-08-25 | N/A | ||
| Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.2.*. | ||||
| CVE-2026-55805 | 2026-08-25 | N/A | ||
| Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*. | ||||
| CVE-2026-16638 | 2026-08-25 | N/A | ||
| Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders allows Stored XSS. This issue affects Media Folders versions: from 0.0.0 to 1.0.8. | ||||
| CVE-2026-16639 | 2026-08-25 | N/A | ||
| Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0. | ||||
| CVE-2026-16640 | 2026-08-25 | N/A | ||
| Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API Autocomplete allows Reflected XSS. This issue affects Search API Autocomplete versions: from 0.0.0 to 1.12.0. | ||||
| CVE-2026-16646 | 2026-08-25 | N/A | ||
| Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*. | ||||
| CVE-2026-16641 | 2026-08-25 | N/A | ||
| Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*. | ||||
| CVE-2026-16642 | 2026-08-25 | N/A | ||
| Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*. | ||||
| CVE-2026-16643 | 2026-08-25 | N/A | ||
| Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*. | ||||
| CVE-2026-16644 | 2026-08-25 | N/A | ||
| Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0. | ||||
| CVE-2026-16645 | 2026-08-25 | N/A | ||
| Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0. | ||||
| CVE-2026-15088 | 2026-08-25 | N/A | ||
| Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*. | ||||
| CVE-2026-18259 | 2026-08-25 | N/A | ||
| Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2. | ||||
| CVE-2026-18260 | 2026-08-25 | N/A | ||
| Vulnerability in Drupal Disable Login Page. This issue affects Disable Login Page versions: *.*. | ||||
| CVE-2026-18261 | 2026-08-25 | N/A | ||
| Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*. | ||||
| CVE-2026-18985 | 2026-08-25 | N/A | ||
| Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1. | ||||
| CVE-2026-80186 | 1 Redhat | 1 Enterprise Linux | 2026-08-25 | 7.6 High |
| A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution. | ||||
| CVE-2026-80185 | 1 Redhat | 1 Enterprise Linux | 2026-08-25 | 5.7 Medium |
| BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd. | ||||
| CVE-2026-79911 | 1 Totolink | 1 N600r Firmware | 2026-08-25 | 10 Critical |
| A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. | ||||