Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

core — Vulnerabilities & Security Advisories 93

All 93 CVE vulnerabilities found in core, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations affecting the core product line maintained by the vendor. It aggregates vulnerability data spanning from the initial release of the software through the most recent security advisories published in the current year. The content is organized to help security professionals and developers understand the historical context of software defects within this specific product ecosystem. Users can track the vendor's patching cadence and response times for critical issues. The page also provides insights into prevalent weakness classes, allowing analysts to identify recurring patterns in code quality or architectural flaws. Developers can look up the complete vulnerability history of the core product to assess long-term stability and risk. This resource serves as a centralized reference for auditing past incidents and evaluating the effectiveness of security measures implemented by the vendor over time. By reviewing these aggregated records, teams can better anticipate potential future threats and prioritize remediation efforts based on historical trends. The information is presented in a structured format to facilitate quick searching and comprehensive analysis without overwhelming the reader with unnecessary details.

Vendor: Drupal

CVE ID Title CVSS Severity Published
CVE-2026-33907 Ella Core Panics during NAS Authentication Response/Failure with missing IEs CWE-476 6.5 Medium 2026-03-27
CVE-2026-33906 Ella Core has Privilege Escalation via Database Restore by NetworkManager role CWE-269 7.2 High 2026-03-27
CVE-2026-33904 Ella Core has a Denial of Service via SCTP connection cleanup deadlock CWE-833 6.5 Medium 2026-03-27
CVE-2026-33903 Ella Core panics when processing a crafted NGAP LocationReport message CWE-476 6.5 Medium 2026-03-27
CVE-2026-33045 Home Assistant has stored XSS in history-graphs CWE-79 6.1 - 2026-03-27
CVE-2026-33044 Home Assistant has stored XSS in Map-card through malicious device name CWE-79 5.4 - 2026-03-27
CVE-2026-23514 Kiteworks Core before 9.2.2 is vulnerable to Improper Ownership Management CWE-282 8.8 High 2026-03-25
CVE-2026-33283 Ella Core panics on malformed ULNASTransport Message without a Request Type CWE-476 6.5 Medium 2026-03-23
CVE-2026-33282 Ella Core panics on malformed NGAP Location Report CWE-476 7.5 High 2026-03-23
CVE-2026-33281 Ella Core panics on invalid PDU Session IDs in NGAP messages CWE-129 6.5 Medium 2026-03-23
CVE-2026-32320 Ella Core: AMF DoS via malformed PathSwitchRequest with empty NR security capability bitstrings CWE-125 6.5 Medium 2026-03-12
CVE-2026-32319 Ella Core: Unauthenticated AMF DoS via malformed InitialUEMessage with undersized integrity-protected NAS payload CWE-125 7.5 High 2026-03-12
CVE-2026-31889 Shopware has a potential take over of app credentials CWE-290 8.9 High 2026-03-11
CVE-2026-31888 Shopware has user enumeration via distinct error codes on Store API login endpoint CWE-204 5.3 Medium 2026-03-11
CVE-2026-31887 Shopware unauthenticated data extraction possible through store-api.order endpoint CWE-863 9.1AI Critical AI 2026-03-11
CVE-2026-30868 Cross-Site Request Forgery (CSRF) in opnsense/core CWE-352 6.3 Medium 2026-03-11
CVE-2026-27621 TypiCMS Core has Stored Cross-Site Scripting (XSS) via SVG File Upload CWE-79 5.4AI Medium AI 2026-02-25
CVE-2026-25577 Emmett has an Unhandled CookieError Exception Causing Denial of Service CWE-248 7.5 High 2026-02-10
CVE-2026-25762 AdonisJS vulnerable to Denial of Service (DoS) via Unrestricted Memory Buffering in PartHandler during File Type Detection CWE-400 7.5 High 2026-02-06
CVE-2026-25754 AdonisJS multipart body parsing has Prototype Pollution issue CWE-1321 7.2 High 2026-02-06
CVE-2026-21440 AdonisJS Path Traversal in Multipart File Handling CWE-22 7.5 - 2026-01-02
CVE-2025-62370 Alloy Core has a DoS vulnerability on `alloy_dyn_abi::TypedData` hashing CWE-248 7.5 High 2025-10-15
CVE-2025-59429 FreePBX core module vulnerable to reflected cross-site scripting via Asterisk HTTP Status page CWE-79 6.1AI Medium AI 2025-10-14
CVE-2025-62172 Home Assistant vulnerable to Stored XSS in Energy dashboard from Energy Entity Name CWE-80 5.4AI Medium AI 2025-10-14
CVE-2014-125127 Denial of Service (DoS) vulnerability in mikecao/flight CWE-770 7.5 High 2025-09-03
CVE-2025-31485 GraphQL grant on a property might be cached with different objects CWE-696 7.5 High 2025-04-03
CVE-2025-31481 GraphQL query operations security can be bypassed CWE-863 7.5 High 2025-04-03
CVE-2023-47639 API Platform Core can leak exceptions message that may contain sensitive information CWE-209 5.3 Medium 2025-04-03
CVE-2025-23204 GraphQl securityAfterResolver not called CWE-20 4.4 Medium 2025-03-24
CVE-2025-25305 SSL validation for outgoing requests in Home Assistant Core and used libs not correct CWE-940 7.0 High 2025-02-18

All 93 known CVE vulnerabilities affecting core with full Chinese analysis, references, and POCs where available.