Search

Search Results (307780 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-3735 1 Panelizer \(obsolete\) Project 1 Panelizer \(obsolete\) 2025-09-02 5.9 Medium
Vulnerability in Drupal Panelizer (obsolete).This issue affects Panelizer (obsolete): *.*.
CVE-2025-3736 1 Simple Gtm Project 1 Simple Gtm 2025-09-02 5.9 Medium
Vulnerability in Drupal Simple GTM.This issue affects Simple GTM: *.*.
CVE-2025-3737 1 Google Maps\ 1 Store Locator Project 2025-09-02 5.9 Medium
Vulnerability in Drupal Google Maps: Store Locator.This issue affects Google Maps: Store Locator: *.*.
CVE-2024-33663 2 Python-jose Project, Redhat 2 Python-jose, Ansible Automation Platform 2025-09-02 6.5 Medium
python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.
CVE-2025-3738 1 Google Optimize Project 1 Google Optimize 2025-09-02 5.9 Medium
Vulnerability in Drupal Google Optimize.This issue affects Google Optimize: *.*.
CVE-2025-3903 1 Ueditor Project 1 Ueditor 2025-09-02 7.3 High
Vulnerability in Drupal UEditor - 百度编辑器.This issue affects UEditor - 百度编辑器: *.*.
CVE-2025-3904 1 Sportsleague Project 1 Sportsleague 2025-09-02 7.3 High
Vulnerability in Drupal Sportsleague.This issue affects Sportsleague: *.*.
CVE-2025-3907 1 Drunkenmonkey 1 Search Api Solr 2025-09-02 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Search API Solr allows Cross Site Request Forgery.This issue affects Search API Solr: from 0.0.0 before 4.3.9.
CVE-2024-52888 1 Checkpoint 3 Gaia Os, Mobile Access, Remote Access Vpn 2025-09-02 5.4 Medium
For an authenticated end-user the portal may run a script while attempting to display a directory or some file's properties.
CVE-2024-52887 1 Checkpoint 3 Gaia Os, Mobile Access, Remote Access Vpn 2025-09-02 3.5 Low
Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing their own bookmark list.
CVE-2024-33664 1 Python-jose Project 1 Python-jose 2025-09-02 5.3 Medium
python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.
CVE-2025-31689 1 General Data Protection Regulation Project 1 General Data Protection Regulation 2025-09-02 8.1 High
Cross-Site Request Forgery (CSRF) vulnerability in Drupal General Data Protection Regulation allows Cross Site Request Forgery.This issue affects General Data Protection Regulation: from 0.0.0 before 3.0.1, from 3.1.0 before 3.1.2.
CVE-2025-31690 1 Cache Utility Project 1 Cache Utility 2025-09-02 8.8 High
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Cache Utility allows Cross Site Request Forgery.This issue affects Cache Utility: from 0.0.0 before 1.2.1.
CVE-2025-31691 1 Oauth2 Server Project 1 Oauth2 Server 2025-09-02 9.8 Critical
Missing Authorization vulnerability in Drupal OAuth2 Server allows Forceful Browsing.This issue affects OAuth2 Server: from 0.0.0 before 2.1.0.
CVE-2025-31694 1 Two-factor Authentication Project 1 Two-factor Authentication 2025-09-02 8.1 High
Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) allows Forceful Browsing.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.10.0.
CVE-2025-31695 1 Upstreamable 1 Link Field Display Mode Formatter 2025-09-02 6.1 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Link field display mode formatter allows Cross-Site Scripting (XSS).This issue affects Link field display mode formatter: from 0.0.0 before 1.6.0.
CVE-2025-31696 1 Chapterthree 1 Rapidoc Oas Field Formatter 2025-09-02 6.1 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal RapiDoc OAS Field Formatter allows Cross-Site Scripting (XSS).This issue affects RapiDoc OAS Field Formatter: from 0.0.0 before 1.0.1.
CVE-2025-31697 1 Formatter Suite Project 1 Formatter Suite 2025-09-02 6.1 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Formatter Suite allows Cross-Site Scripting (XSS).This issue affects Formatter Suite: from 0.0.0 before 2.1.0.
CVE-2025-3059 1 Profile Private Project 1 Profile Private 2025-09-02 5.3 Medium
Vulnerability in Drupal Profile Private.This issue affects Profile Private: *.*.
CVE-2025-3060 1 Flattern Project 1 Flattern 2025-09-02 6.6 Medium
Vulnerability in Drupal Flattern – Multipurpose Bootstrap Business Profile.This issue affects Flattern – Multipurpose Bootstrap Business Profile: *.*.