5.4

CVSS3.1

CVE-2025-13983 - Tagify - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-121

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allows Cross-Site Scripting (XSS).This issue affects Tagify: from 0.0.0 before 1.2.44.

πŸ“… Published: Jan. 28, 2026, 8:02 p.m. πŸ”„ Last Modified: Feb. 3, 2026, 4:36 p.m.

8.1

CVSS3.1

CVE-2025-13982 - Login Time Restriction - Moderately critical - Cross-Site Request Forgery - SA-CONTRIB-2025-120

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Login Time Restriction allows Cross Site Request Forgery.This issue affects Login Time Restriction: from 0.0.0 before 1.0.3.

πŸ“… Published: Jan. 28, 2026, 8:01 p.m. πŸ”„ Last Modified: Feb. 19, 2026, 9:18 p.m.

4.4

CVSS3.1

CVE-2025-13981 - AI (Artificial Intelligence) - Moderately critical - Cross-Site Scripting - SA-CONTRIB-2025-119

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI (Artificial Intelligence) allows Cross-Site Scripting (XSS).This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.7, from 1.1.0 before 1.1.7, from 1.2.0 before 1.2.4.

πŸ“… Published: Jan. 28, 2026, 8:01 p.m. πŸ”„ Last Modified: Feb. 19, 2026, 9:19 p.m.

5.3

CVSS3.1

CVE-2025-13980 - CKEditor 5 Premium Features - Moderately critical - Access bypass - SA-CONTRIB-2025-118

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CKEditor 5 Premium Features allows Functionality Bypass.This issue affects CKEditor 5 Premium Features: from 0.0.0 before 1.2.10, from 1.3.0 before 1.3.6, from 1.4.0 before 1.4.3, from 1.5.0 before 1.5.1, from 1.6.0 be…

πŸ“… Published: Jan. 28, 2026, 8:01 p.m. πŸ”„ Last Modified: Feb. 12, 2026, 7:43 p.m.

5.4

CVSS3.1

CVE-2025-13979 - Mini site - Moderately critical - Cross-Site Scripting - SA-CONTRIB-2025-117

Privilege Defined With Unsafe Actions vulnerability in Drupal Mini site allows Stored XSS.This issue affects Mini site: from 0.0.0 before 3.0.2.

πŸ“… Published: Jan. 28, 2026, 8 p.m. πŸ”„ Last Modified: Feb. 12, 2026, 7:50 p.m.

5.3

CVSS3.1

CVE-2023-37525 - HCL BigFix Compliance is vulnerable to a sensitive information disclosure

A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF directory, which may contain Java class files and configuration information, leading to unauthorized access to application internals.

πŸ“… Published: Jan. 28, 2026, 7:58 p.m. πŸ”„ Last Modified: Feb. 12, 2026, 7:51 p.m.

6.5

CVSS3.1

CVE-2026-21865 - Discourse topic conversion permission vulnerability for moderators

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can convert some personal messages to public topics when they shouldn't have access. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. As a workarou…

πŸ“… Published: Jan. 28, 2026, 7:51 p.m. πŸ”„ Last Modified: April 18, 2026, 1:45 a.m.

5.1

CVSS4.0

CVE-2025-69289 - Discourse has insecure default configuration that allows non-admin moderators to takeover any non-s…

Discourse is an open source discussion platform. A privilege escalation vulnerability in versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 allows a non-admin moderator to bypass email-change restrictions, allowing a takeover of non-staff accounts. This issue is patched in versions 3.5.4, …

πŸ“… Published: Jan. 28, 2026, 7:33 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 8:47 p.m.

7.8

CVSS3.1

CVE-2025-46691 -

Dell PremierColor Panel Driver, versions prior to 1.0.0.1 A01, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

πŸ“… Published: Jan. 28, 2026, 7:31 p.m. πŸ”„ Last Modified: March 9, 2026, 2:30 p.m.

6.5

CVSS3.1

CVE-2025-61728 - Excessive CPU consumption when building archive index in archive/zip

archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.

πŸ“… Published: Jan. 28, 2026, 7:30 p.m. πŸ”„ Last Modified: Feb. 6, 2026, 6:45 p.m.
Total resulsts: 349182
Page 1904 of 34,919
Β« previous page Β» next page
Filters