Export limit exceeded: 360000 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (360000 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-3736 | 1 Simple Gtm Project | 1 Simple Gtm | 2025-09-02 | 5.9 Medium |
| Vulnerability in Drupal Simple GTM.This issue affects Simple GTM: *.*. | ||||
| CVE-2025-3737 | 1 Google Maps\ | 1 Store Locator Project | 2025-09-02 | 5.9 Medium |
| Vulnerability in Drupal Google Maps: Store Locator.This issue affects Google Maps: Store Locator: *.*. | ||||
| CVE-2024-33663 | 2 Python-jose Project, Redhat | 2 Python-jose, Ansible Automation Platform | 2025-09-02 | 6.5 Medium |
| python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217. | ||||
| CVE-2025-3738 | 1 Google Optimize Project | 1 Google Optimize | 2025-09-02 | 5.9 Medium |
| Vulnerability in Drupal Google Optimize.This issue affects Google Optimize: *.*. | ||||
| CVE-2025-3903 | 1 Ueditor Project | 1 Ueditor | 2025-09-02 | 7.3 High |
| Vulnerability in Drupal UEditor - 百度编辑器.This issue affects UEditor - 百度编辑器: *.*. | ||||
| CVE-2025-3904 | 1 Sportsleague Project | 1 Sportsleague | 2025-09-02 | 7.3 High |
| Vulnerability in Drupal Sportsleague.This issue affects Sportsleague: *.*. | ||||
| CVE-2025-3907 | 1 Drunkenmonkey | 1 Search Api Solr | 2025-09-02 | 4.3 Medium |
| Cross-Site Request Forgery (CSRF) vulnerability in Drupal Search API Solr allows Cross Site Request Forgery.This issue affects Search API Solr: from 0.0.0 before 4.3.9. | ||||
| CVE-2024-52888 | 1 Checkpoint | 3 Gaia Os, Mobile Access, Remote Access Vpn | 2025-09-02 | 5.4 Medium |
| For an authenticated end-user the portal may run a script while attempting to display a directory or some file's properties. | ||||
| CVE-2024-52887 | 1 Checkpoint | 3 Gaia Os, Mobile Access, Remote Access Vpn | 2025-09-02 | 3.5 Low |
| Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing their own bookmark list. | ||||
| CVE-2024-33664 | 1 Python-jose Project | 1 Python-jose | 2025-09-02 | 5.3 Medium |
| python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319. | ||||
| CVE-2025-31689 | 1 General Data Protection Regulation Project | 1 General Data Protection Regulation | 2025-09-02 | 8.1 High |
| Cross-Site Request Forgery (CSRF) vulnerability in Drupal General Data Protection Regulation allows Cross Site Request Forgery.This issue affects General Data Protection Regulation: from 0.0.0 before 3.0.1, from 3.1.0 before 3.1.2. | ||||
| CVE-2025-31690 | 1 Cache Utility Project | 1 Cache Utility | 2025-09-02 | 8.8 High |
| Cross-Site Request Forgery (CSRF) vulnerability in Drupal Cache Utility allows Cross Site Request Forgery.This issue affects Cache Utility: from 0.0.0 before 1.2.1. | ||||
| CVE-2025-31691 | 1 Oauth2 Server Project | 1 Oauth2 Server | 2025-09-02 | 9.8 Critical |
| Missing Authorization vulnerability in Drupal OAuth2 Server allows Forceful Browsing.This issue affects OAuth2 Server: from 0.0.0 before 2.1.0. | ||||
| CVE-2025-31694 | 1 Two-factor Authentication Project | 1 Two-factor Authentication | 2025-09-02 | 8.1 High |
| Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) allows Forceful Browsing.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.10.0. | ||||
| CVE-2025-31695 | 1 Upstreamable | 1 Link Field Display Mode Formatter | 2025-09-02 | 6.1 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Link field display mode formatter allows Cross-Site Scripting (XSS).This issue affects Link field display mode formatter: from 0.0.0 before 1.6.0. | ||||
| CVE-2025-31696 | 1 Chapterthree | 1 Rapidoc Oas Field Formatter | 2025-09-02 | 6.1 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal RapiDoc OAS Field Formatter allows Cross-Site Scripting (XSS).This issue affects RapiDoc OAS Field Formatter: from 0.0.0 before 1.0.1. | ||||
| CVE-2025-31697 | 1 Formatter Suite Project | 1 Formatter Suite | 2025-09-02 | 6.1 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Formatter Suite allows Cross-Site Scripting (XSS).This issue affects Formatter Suite: from 0.0.0 before 2.1.0. | ||||
| CVE-2025-3059 | 1 Profile Private Project | 1 Profile Private | 2025-09-02 | 5.3 Medium |
| Vulnerability in Drupal Profile Private.This issue affects Profile Private: *.*. | ||||
| CVE-2025-3060 | 1 Flattern Project | 1 Flattern | 2025-09-02 | 6.6 Medium |
| Vulnerability in Drupal Flattern – Multipurpose Bootstrap Business Profile.This issue affects Flattern – Multipurpose Bootstrap Business Profile: *.*. | ||||
| CVE-2025-3061 | 1 Material Admin Project | 1 Material Admin | 2025-09-02 | 6.6 Medium |
| Vulnerability in Drupal Material Admin.This issue affects Material Admin: *.*. | ||||