Filter
-Infinity
0

Oracle REST Data ServicesJQuery Cross-Site Scripting (XSS) Vulnerability

First published (updated )

DrupalDrupal core - Moderately critical - Gadget Chain - SA-CORE-2025-003

7.5
EPSS
0.06%
First published (updated )

DrupalWEB-T - Moderately critical - Access bypass, Denial of service - SA-CONTRIB-2025-030

EPSS
0.05%
First published (updated )

Drupal AIAI (Artificial Intelligence) - Critical - Remote Code Execution - SA-CONTRIB-2025-021

7.5
EPSS
0.19%
First published (updated )

composer/drupal/coreDrupal core - Moderately critical - Cross Site Scripting - SA-CORE-2025-004

EPSS
0.04%
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

composer/drupal/coreDrupal core - Moderately critical - Access bypass - SA-CORE-2025-002

EPSS
0.02%
First published (updated )

Oracle Financial Services Analytical Applications InfrastructureCross-site Scripting in CKEditor4

First published (updated )

Oracle Financial Services Analytical Applications InfrastructureRegular expression Denial of Service in dialog plugin

7.5
First published (updated )

composer/guzzlehttp/psr7Improper Input Validation in guzzlehttp/psr7

7.5
First published (updated )

composer/guzzlehttp/guzzleCross-domain cookie leakage in Guzzle

8.1
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

DrupalFailure to strip the Cookie header on change in host or HTTP downgrade in Guzzle

7.5
First published (updated )

DrupalFix failure to strip Authorization header on HTTP downgrade in Guzzle

7.5
First published (updated )

TwigTwig may load a template outside a configured directory when using the filesystem loader

7.5
First published (updated )

composer/drupal/corecore/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) …

First published (updated )

DrupalECA: Event - Condition - Action - Critical - Cross site request forgery - SA-CONTRIB-2025-031

EPSS
0.01%
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Drupal AIAI (Artificial Intelligence) - Moderately critical - Gadget Chain - SA-CONTRIB-2025-022

EPSS
0.15%
First published (updated )

DrupalDrupal core - Critical - Cross site scripting - SA-CORE-2025-001

EPSS
0.03%
First published (updated )

Debian LinuxXSS

First published (updated )

Red Hat FedoraPEAR Archive_Tar Deserialization of Untrusted Data Vulnerability

First published (updated )

Red Hat FedoraPEAR Archive_Tar Improper Link Resolution Vulnerability

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Restful Web ServicesInput Validation

First published (updated )

Ubercart Currency ConversionSession fixation vulnerability in the Ubercart module 6.x-2.x before 6.x-2.13 and 7.x-3.x before 7.x…

First published (updated )

Debian LinuxInfoleak

First published (updated )

Florian Weber SpacesThe Spaces OG submodule in the Spaces module 6.x-3.x before 6.x-3.7 for Drupal does not properly del…

2.1
First published (updated )

Drupallib/Auth/Source/External.php in the drupalauth module before 1.2.2 for simpleSAMLphp allows remote a…

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Drupal Monster MenusThe Monster Menus module 7.x-1.x before 7.x-1.15 allows remote attackers to read arbitrary node comm…

2.6
First published (updated )

Google AuthenticatorThe Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal a…

First published (updated )

Google AuthenticatorThe Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal d…

First published (updated )

FilefieldThe FileField Sources module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.9 for Drupal does not p…

First published (updated )

MediafrontXSS

2.1
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203