Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

core — Vulnerabilities & Security Advisories 137

All 137 CVE vulnerabilities found in core, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security advisories and vulnerability records for the product core. It collects entries spanning multiple years, covering various weakness classes including buffer overflows, memory corruption, and access control flaws. Readers can track the vendor's published advisories, understand the evolution of specific weakness categories, and review the product's complete vulnerability history to identify recurring patterns. The dataset includes both confirmed and unpatched issues, enabling users to assess the overall risk profile and remediation status over time. By correlating vulnerability reports with patch releases, the page helps teams prioritize updates and verify that known defects have been addressed in the latest build.

Vendor: Drupal

CVE ID Title CVSS Severity Published
CVE-2026-102099 Kiteworks Core arbitrary file write CWE-22 7.2 High 2026-09-30
CVE-2026-102093 Kiteworks Core improper privilege management CWE-269 7.2 High 2026-09-30
CVE-2026-102092 Kiteworks Core stored XSS CWE-79 8.7 High 2026-09-30
CVE-2026-102090 Kiteworks Core content injection CWE-601 4.3 Medium 2026-09-30
CVE-2026-102098 Kiteworks Core SQL Injection CWE-89 7.2 High 2026-09-30
CVE-2026-63000 REDAXO: Missing CSRF Protection on Package Update Action Allows Forced Addon Updates CWE-352 6.4 Medium 2026-09-23
CVE-2026-62998 REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration CWE-20 4.3 Medium 2026-09-23
CVE-2026-63002 REDAXO: Stored XSS in Mediapool Sync Page via Unescaped Filesystem Filenames CWE-79 4.8 Medium 2026-09-23
CVE-2026-63001 REDAXO: Stored XSS via Unescaped Media Manager Type Name in `mediaIsInUse()` CWE-79 4.8 Medium 2026-09-23
CVE-2026-91129 Home Assistant: mDNS Server-Side Request Forgery CWE-918 5.4 Medium 2026-09-22
CVE-2026-91130 Home Assistant: XSS in Statistics Graph Card CWE-80 9.3 Critical 2026-09-22
CVE-2026-53581 ntp: write path traversal CWE-22 9.0 Critical 2026-09-08
CVE-2026-85093 Cheshire Cat AI Memory Collection Endpoint Information Disclosure CWE-863 6.5 Medium 2026-09-03
CVE-2026-57499 Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE) CWE-20 9.1 Critical 2026-08-27
CVE-2026-66061 Home Assistant: iOS Companion app forwards NFC/QR tag scans without confirmation, enabling silent automation execution CWE-862 7.1 High 2026-08-07
CVE-2026-66060 Home Assistant: Unconfirmed NFC/QR tag scans allow silent automation execution by untrusted callers CWE-862 7.1 High 2026-08-07
CVE-2026-59717 Home Assistant Companion: `homeassistant://invite` Deep Link Credential Phishing CWE-601 4.3 Medium 2026-08-07
CVE-2026-71291 Bolt CMS Server-Side Template Injection via Unsandboxed allow_twig Field Rendering CWE-1336 8.8 High 2026-08-05
CVE-2026-53599 Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers CWE-434 7.5 High 2026-07-31
CVE-2026-48795 Incomplete fix for CVE-2026-25754 in @adonisjs/bodyparser CWE-1321 8.6 High 2026-07-15
CVE-2026-49858 API Platform Core: Cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate CWE-524 5.9 Medium 2026-07-01
CVE-2026-54164 API Platform Core: Missing IRI type check enables resource type confusion CWE-843 6.5 Medium 2026-07-01
CVE-2026-55844 Home Assistant: iOS Companion App ignores internal SSID allowlist for connections – possible leak of access token and sensor data CWE-319 7.5 High 2026-06-29
CVE-2026-54318 Home Assistant: Exported BroadcastReceiver allows local apps to spoof device location CWE-926 7.1 High 2026-06-23
CVE-2026-54317 Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN CWE-200 7.6 High 2026-06-23
CVE-2024-14036 Dräger Core 1.0.5 Denial of Service via Malformed SDC Message CWE-400 7.5 High 2026-06-02
CVE-2026-44698 Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injection CWE-94 8.3 High 2026-05-29
CVE-2026-44473 Ella Core: UE Downlink Redirection via Forged PDUSessionResourceSetupResponse CWE-358 7.1 High 2026-05-27
CVE-2026-44475 Ella Core: UE Security Capability bypass on NGAP PathSwitchRequest CWE-358 6.1 Medium 2026-05-27
CVE-2026-44474 Ella Core: Handover failures during concurrent Security Mode Command CWE-358 3.7 Low 2026-05-27

All 137 known CVE vulnerabilities affecting core with full Chinese analysis, references, and POCs where available.