Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

core — Vulnerabilities & Security Advisories 93

All 93 CVE vulnerabilities found in core, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations affecting the core product line maintained by the vendor. It aggregates vulnerability data spanning from the initial release of the software through the most recent security advisories published in the current year. The content is organized to help security professionals and developers understand the historical context of software defects within this specific product ecosystem. Users can track the vendor's patching cadence and response times for critical issues. The page also provides insights into prevalent weakness classes, allowing analysts to identify recurring patterns in code quality or architectural flaws. Developers can look up the complete vulnerability history of the core product to assess long-term stability and risk. This resource serves as a centralized reference for auditing past incidents and evaluating the effectiveness of security measures implemented by the vendor over time. By reviewing these aggregated records, teams can better anticipate potential future threats and prioritize remediation efforts based on historical trends. The information is presented in a structured format to facilitate quick searching and comprehensive analysis without overwhelming the reader with unnecessary details.

Vendor: Drupal

CVE ID Title CVSS Severity Published
CVE-2026-66061 Home Assistant: iOS Companion app forwards NFC/QR tag scans without confirmation, enabling silent automation execution CWE-862 7.1 High 2026-08-07
CVE-2026-66060 Home Assistant: Unconfirmed NFC/QR tag scans allow silent automation execution by untrusted callers CWE-862 7.1 High 2026-08-07
CVE-2026-59717 Home Assistant Companion: `homeassistant://invite` Deep Link Credential Phishing CWE-601 4.3 Medium 2026-08-07
CVE-2026-71291 Bolt CMS Server-Side Template Injection via Unsandboxed allow_twig Field Rendering CWE-1336 8.8 High 2026-08-05
CVE-2026-53599 Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers CWE-434 7.5 High 2026-07-31
CVE-2026-48795 Incomplete fix for CVE-2026-25754 in @adonisjs/bodyparser CWE-1321 8.6 High 2026-07-15
CVE-2026-49858 API Platform Core: Cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate CWE-524 5.9 Medium 2026-07-01
CVE-2026-54164 API Platform Core: Missing IRI type check enables resource type confusion CWE-843 6.5 Medium 2026-07-01
CVE-2026-55844 Home Assistant: iOS Companion App ignores internal SSID allowlist for connections – possible leak of access token and sensor data CWE-319 7.5 High 2026-06-29
CVE-2026-54318 Home Assistant: Exported BroadcastReceiver allows local apps to spoof device location CWE-926 7.1 High 2026-06-23
CVE-2026-54317 Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN CWE-200 7.6 High 2026-06-23
CVE-2024-14036 Dräger Core 1.0.5 Denial of Service via Malformed SDC Message CWE-400 7.5 High 2026-06-02
CVE-2026-44698 Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injection CWE-94 8.3 High 2026-05-29
CVE-2026-44473 Ella Core: UE Downlink Redirection via Forged PDUSessionResourceSetupResponse CWE-358 7.1 High 2026-05-27
CVE-2026-44475 Ella Core: UE Security Capability bypass on NGAP PathSwitchRequest CWE-358 6.1 Medium 2026-05-27
CVE-2026-44474 Ella Core: Handover failures during concurrent Security Mode Command CWE-358 3.7 Low 2026-05-27
CVE-2026-45158 OPNsense: Command Injection via Attacker-Controlled DHCP Config CWE-88 9.1 Critical 2026-05-13
CVE-2026-44194 OPNsense: RCE on user managment CWE-78 9.1 Critical 2026-05-13
CVE-2026-44195 OPNsense: Authentication lockout bypass CWE-307 5.3 Medium 2026-05-13
CVE-2026-44193 OPNsense: RCE via XMLRPC endpoint using `opnsense.restore_config_section` method CWE-88 9.1 Critical 2026-05-13
CVE-2026-42552 Flight: Sensitive information disclosure via default error handler in flightphp/core CWE-209 7.5 High 2026-05-13
CVE-2026-42551 Flight: HTTP method override enabled by default enables CSRF escalation and middleware bypass in flightphp/core CWE-436 7.5 High 2026-05-13
CVE-2026-42550 Flight: SQL Injection via unvalidated identifiers in SimplePdo::insert / update / delete CWE-89 8.8 High 2026-05-13
CVE-2026-42549 Flight: Path traversal in `make:controller` CLI creates arbitrary directories outside project root CWE-22 4.4 Medium 2026-05-13
CVE-2026-42548 Flight: Reflected XSS via unvalidated JSONP callback in Flight::jsonp() CWE-79 - - 2026-05-13
CVE-2026-42278 UltraDAG: Smart Account Spending Policy Bypass via Pockets CWE-284 7.5AI High AI 2026-05-08
CVE-2026-40583 UltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant Halt CWE-460 9.1AI Critical AI 2026-04-21
CVE-2026-34578 OPNsense has an LDAP Injection via Unsanitized Username in Authentication CWE-90 8.2 High 2026-04-09
CVE-2026-34762 Ella Core Has Audit Log Falsification via Path/Body IMSI Mismatch in UpdateSubscriber CWE-20 2.7 Low 2026-04-02
CVE-2026-34761 Ella Core Panics Upon NGAP handover failure CWE-476 5.8 Medium 2026-04-02

All 93 known CVE vulnerabilities affecting core with full Chinese analysis, references, and POCs where available.