8.6

CVSS3.1

CVE-2026-20084 - Bootp VLAN Leakage in Cisco IOS XE DHCP Snooping Leading to Denial of Service

A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packets to be forwarded between VLANs, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of BOOTP packets on Cisco …

πŸ“… Published: March 25, 2026, 4:02 p.m. πŸ”„ Last Modified: March 26, 2026, 5:35 p.m.

4.8

CVSS3.1

CVE-2026-3218 - Responsive Favicons - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-019

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Responsive Favicons allows Cross-Site Scripting (XSS).This issue affects Responsive Favicons: from 0.0.0 before 2.0.2.

πŸ“… Published: March 25, 2026, 3:24 p.m. πŸ”„ Last Modified: April 2, 2026, 7:59 a.m.

6.1

CVSS3.1

CVE-2026-3217 - SAML SSO - Service Provider - Critical - Cross-site scripting - SA-CONTRIB-2026-018

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal SAML SSO - Service Provider allows Cross-Site Scripting (XSS).This issue affects SAML SSO - Service Provider: from 0.0.0 before 3.1.3.

πŸ“… Published: March 25, 2026, 3:24 p.m. πŸ”„ Last Modified: April 2, 2026, 7:59 a.m.

5

CVSS3.1

CVE-2026-3216 - Drupal Canvas - Moderately critical - Server-side request forgery, Information disclosure - SA-CONT…

Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal Canvas allows Server Side Request Forgery.This issue affects Drupal Canvas: from 0.0.0 before 1.1.1.

πŸ“… Published: March 25, 2026, 3:24 p.m. πŸ”„ Last Modified: April 2, 2026, 7:59 a.m.

5.4

CVSS3.1

CVE-2026-3215 - Islandora - Moderately critical - Arbitrary file upload, Cross-site scripting - SA-CONTRIB-2026-016

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Islandora allows Cross-Site Scripting (XSS).This issue affects Islandora: from 0.0.0 before 2.17.5.

πŸ“… Published: March 25, 2026, 3:24 p.m. πŸ”„ Last Modified: April 2, 2026, 7:59 a.m.

6.5

CVSS3.1

CVE-2026-3214 - CAPTCHA - Moderately critical - Access bypass - SA-CONTRIB-2026-015

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA allows Functionality Bypass.This issue affects CAPTCHA: from 0.0.0 before 1.17.0, from 2.0.0 before 2.0.10.

πŸ“… Published: March 25, 2026, 3:23 p.m. πŸ”„ Last Modified: April 3, 2026, 9:39 a.m.

4.7

CVSS3.1

CVE-2026-3213 - Anti-Spam by CleanTalk - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-014

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam by CleanTalk allows Cross-Site Scripting (XSS).This issue affects Anti-Spam by CleanTalk: from 0.0.0 before 9.7.0.

πŸ“… Published: March 25, 2026, 3:22 p.m. πŸ”„ Last Modified: April 2, 2026, 7:59 a.m.

7.6

CVSS3.1

CVE-2026-24750 - Kiteworks Secure Data Forms vulnerable to Cross-site Scripting

Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, an authenticated attacker could exploit an Improper Neutralization of Input During Web Page Generation as Stored XSS when modifying forms. Upgrade Kiteworks to version 9.2.1 or later to receive a patch.

πŸ“… Published: March 25, 2026, 3:22 p.m. πŸ”„ Last Modified: March 29, 2026, 8:28 p.m.

5.4

CVSS3.1

CVE-2026-3212 - Tagify - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-013

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allows Cross-Site Scripting (XSS).This issue affects Tagify: from 0.0.0 before 1.2.49.

πŸ“… Published: March 25, 2026, 3:22 p.m. πŸ”„ Last Modified: March 29, 2026, 8:28 p.m.

4.3

CVSS3.1

CVE-2026-3211 - Theme Negotiation by Rules - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-012

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Theme Negotiation by Rules allows Cross Site Request Forgery.This issue affects Theme Negotiation by Rules: from 0.0.0 before 1.2.1.

πŸ“… Published: March 25, 2026, 3:21 p.m. πŸ”„ Last Modified: April 2, 2026, 7:59 a.m.
Total resulsts: 349182
Page 907 of 34,919
Β« previous page Β» next page
Filters