Latest CVE Feed
-
5.4
MEDIUMCVE-2025-31675
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.14, from 10.4.0 before 10.4.5, from 11.0.0 be... Read more
Affected Products : drupal- Published: Mar. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cross-Site Scripting
-
4.6
MEDIUMCVE-2025-31673
Incorrect Authorization vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.... Read more
Affected Products : drupal- Published: Mar. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-55638
Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9. Drupal core contains a chain of methods that is exploitabl... Read more
Affected Products : drupal- Published: Dec. 10, 2024
- Modified: Jun. 02, 2025
-
9.8
CRITICALCVE-2024-55637
Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploi... Read more
Affected Products : drupal- Published: Dec. 10, 2024
- Modified: Jun. 02, 2025
-
9.8
CRITICALCVE-2024-55636
Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploi... Read more
Affected Products : drupal- Published: Dec. 10, 2024
- Modified: Jun. 02, 2025
-
6.1
MEDIUMCVE-2024-55635
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 7.0 before 7.102.... Read more
Affected Products : drupal- Published: Dec. 10, 2024
- Modified: Jun. 02, 2025
-
8.1
HIGHCVE-2024-55634
A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.... Read more
Affected Products : drupal- Published: Dec. 10, 2024
- Modified: Jun. 02, 2025
-
5.4
MEDIUMCVE-2024-12393
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 8.8.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 be... Read more
Affected Products : drupal- Published: Dec. 10, 2024
- Modified: Jun. 02, 2025
-
5.9
MEDIUMCVE-2024-11942
A vulnerability in Drupal Core allows File Manipulation.This issue affects Drupal Core: from 10.0.0 before 10.2.10.... Read more
Affected Products : drupal- Published: Dec. 05, 2024
- Modified: Jun. 02, 2025
-
7.5
HIGHCVE-2024-11941
A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, from 10.1.0 before 10.1.8.... Read more
Affected Products : drupal- Published: Dec. 05, 2024
- Modified: Jun. 02, 2025
-
7.2
HIGHCVE-2024-22628
Budget and Expense Tracker System v1.0 is vulnerable to SQL Injection via /expense_budget/admin/?page=reports/budget&date_start=2023-12-28&date_end=... Read more
Affected Products : budget_and_expense_tracker_system- EPSS Score: %0.14
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
8.8
HIGHCVE-2024-21672
This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.3 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C... Read more
- EPSS Score: %4.27
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
7.5
HIGHCVE-2023-52116
Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.... Read more
- EPSS Score: %0.07
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
7.5
HIGHCVE-2023-52109
Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.... Read more
- EPSS Score: %0.07
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
7.5
HIGHCVE-2023-52108
Vulnerability of process priorities being raised in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.... Read more
- EPSS Score: %0.06
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
7.5
HIGHCVE-2023-52104
Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.... Read more
- EPSS Score: %0.18
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
7.5
HIGHCVE-2023-52100
The Celia Keyboard module has a vulnerability in access control. Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- EPSS Score: %0.14
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
9.8
CRITICALCVE-2023-49351
A stack-based buffer overflow vulnerability in /bin/webs binary in Edimax BR6478AC V2 firmware veraion v1.23 allows attackers to overwrite other values located on the stack due to an incorrect use of the strcpy() function.... Read more
- EPSS Score: %0.28
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
5.3
MEDIUMCVE-2023-48926
An issue in 202 ecommerce Advanced Loyalty Program: Loyalty Points before v2.3.4 for PrestaShop allows unauthenticated attackers to arbitrarily change an order status.... Read more
Affected Products : advanced_loyalty_program- EPSS Score: %0.20
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
4.3
MEDIUMCVE-2023-3178
The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow attackers to make logged in users with the manage_postman_smtp capability delete arbitrary logs via a CSRF attack.... Read more
- EPSS Score: %0.16
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025