Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · drupal

drupal

· 15 Critical

Total CVEs

861

Critical

15

Products

143

Search All CVEs →

861

Products (143)

drupal729 CVEsproject issue tracking module6 CVEsprint5 CVEseveryblog4 CVEsproject4 CVEsubercart module4 CVEsaggregation module4 CVEscontent construction kit3 CVEsdrupal project issue tracking3 CVEsshindig-integrator3 CVEsbibliography module2 CVEsdata2 CVEsdatabase administration module2 CVEstrailscout module2 CVEsartificial intelligence2 CVEsuser karma module2 CVEslocalization client2 CVEsviews2 CVEschatroom module2 CVEslogintoboggan module2 CVEssecure site module2 CVEsactivity2 CVEsdrupal easylinks module2 CVEsajax checklist2 CVEsbrilliant gallery2 CVEscookies consent management2 CVEshelp tip module2 CVEstalk2 CVEstaxonomy autotagger module2 CVEsimce module2 CVEscustom search module2 CVEsfeedapi mapper1 CVEsfileshare module1 CVEsform mail module1 CVEsforward module1 CVEsfullname field for cck1 CVEsgetid31 CVEsheader image1 CVEsinternationalization1 CVEsinvite module1 CVEsjob search1 CVEsjquery ui checkboxradio1 CVEslink module1 CVEslink to us1 CVEslocalization server1 CVEsmaestro1 CVEsmagic tabs module1 CVEsmailhandler1 CVEsmailsave1 CVEsmayo1 CVEsmediafield module1 CVEsmeta tags module1 CVEsmodal frame1 CVEsmrbs module1 CVEsnews page1 CVEsnewsflash1 CVEsnivo slider1 CVEsnode clone1 CVEsnode hierarchy module1 CVEsnode relativity module1 CVEsnodeaccess userreference1 CVEsnodefamily1 CVEsnodequeue1 CVEsobfuscate1 CVEsopenid1 CVEsorganic groups menu1 CVEsorganic groups module1 CVEsoutline designer module1 CVEspanels1 CVEspathauto module1 CVEspaypal node module1 CVEspetition node module1 CVEsplus11 CVEsprint module1 CVEsprofessional theme1 CVEsproject issue file review1 CVEsprotected node module1 CVEsquick tabs1 CVEsquiz1 CVEsrandomizer1 CVEsrealname1 CVEsrecipe module1 CVEsresponsive menus1 CVEssaml sp 2.0 single sign on1 CVEssearch keyword module1 CVEssemantically interconnected online communities1 CVEsservices module for drupal1 CVEsshoutbox1 CVEssimplecorp1 CVEssite profile directory module1 CVEsskeleton theme1 CVEsstock module1 CVEsstorage api1 CVEsstorm1 CVEssuggested terms module1 CVEssvg sanitizer1 CVEstasklist1 CVEstaxonomy image module1 CVEstaxonomy manager1 CVEstaxonomy theme module1 CVEstextimage1 CVEstinytax taxonomy block module1 CVEstoken module1 CVEstribune1 CVEsupload module1 CVEsuserpoints module1 CVEsviews builk operations1 CVEsviews bulk operations1 CVEsviews dynamic field1 CVEswebform module1 CVEsworkflow1 CVEsacidfree1 CVEszen1 CVEsarchive module1 CVEsasin field module1 CVEsatom module1 CVEsaudio module1 CVEsauthenticated user page caching1 CVEsavatar uploader1 CVEsbluemasters1 CVEsbueditor1 CVEscck comment reference1 CVEscomment mail1 CVEscomment upload module1 CVEscommons1 CVEscontext form alteration module1 CVEscvs management and tracker1 CVEsdevel module1 CVEsdoubleclick for publishers1 CVEsdrupal docker images1 CVEsdrupal e-commerce module1 CVEsdrupal mysite1 CVEsdrupal pathauto module1 CVEsdrupal project1 CVEsdrupal pubcookie module1 CVEsdrupal userreview module1 CVEse-commerce module1 CVEse-publish1 CVEseca\1 CVEsentity embed1 CVEsextended tracker1 CVEsfaq1 CVEsfeature module1 CVEs

Recent Vulnerabilities

View all 861
CVE-2026-9082CRITICAL 9.8KEV

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.

CVE-2026-6367MEDIUM 6.1

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core: from 11.3.0 before 11.3.7.

CVE-2026-6366MEDIUM 6.6

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.

CVE-2026-6365MEDIUM 6.1

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.

CVE-2025-13083LOW 3.7

Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8, from 7.0 before 7.103.

CVE-2025-13082MEDIUM 4.3

User Interface (UI) Misrepresentation of Critical Information vulnerability in Drupal Drupal core allows Content Spoofing.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

CVE-2025-13081MEDIUM 5.9

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

CVE-2025-13080MEDIUM 5.3

Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

CVE-2025-48915HIGH 8.6

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.15.

CVE-2025-48914HIGH 8.6

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.15.

CVE-2025-3474MEDIUM 6.5

Missing Authentication for Critical Function vulnerability in Drupal Panels allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Panels: from 0.0.0 before 4.9.0.

CVE-2025-3131MEDIUM 5.4

Cross-Site Request Forgery (CSRF) vulnerability in Drupal ECA: Event - Condition - Action allows Cross Site Request Forgery.This issue affects ECA: Event - Condition - Action: from 0.0.0 before 1.1.12, from 2.0.0 before 2.0.16, from 2.1.0 before 2.1.7, from 0.0.0 before 1.2.*.

CVE-2025-3130MEDIUM 5.4

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Obfuscate allows Stored XSS.This issue affects Obfuscate: from 0.0.0 before 2.0.1.

CVE-2025-3057MEDIUM 6.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

CVE-2025-31693MEDIUM 6.6

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.

CVE-2025-31692HIGH 7.5

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.

CVE-2025-31675MEDIUM 5.4

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.14, from 10.4.0 before 10.4.5, from 11.0.0 before 11.0.13, from 11.1.0 before 11.1.5. It also affects the Drupal 7 module from versions 7.x-1.0 through 7.x-1.12.

CVE-2025-31674HIGH 7.5

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

CVE-2025-31673MEDIUM 4.6

Incorrect Authorization vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

CVE-2024-55638CRITICAL 9.8

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called gadget chain presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.

CVE-2024-55637CRITICAL 9.8

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called gadget chain presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.

CVE-2024-55636CRITICAL 9.8

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so called gadget chain presents no direct threat, but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.

CVE-2024-55635MEDIUM 6.1

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 7.0 before 7.102.

CVE-2024-55634HIGH 8.1

A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.

CVE-2024-12393MEDIUM 5.4

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 8.8.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.