Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

core — Vulnerabilities & Security Advisories 137

All 137 CVE vulnerabilities found in core, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security advisories and vulnerability records for the product core. It collects entries spanning multiple years, covering various weakness classes including buffer overflows, memory corruption, and access control flaws. Readers can track the vendor's published advisories, understand the evolution of specific weakness categories, and review the product's complete vulnerability history to identify recurring patterns. The dataset includes both confirmed and unpatched issues, enabling users to assess the overall risk profile and remediation status over time. By correlating vulnerability reports with patch releases, the page helps teams prioritize updates and verify that known defects have been addressed in the latest build.

Vendor: Drupal

CVE ID Title CVSS Severity Published
CVE-2026-45158 OPNsense: Command Injection via Attacker-Controlled DHCP Config CWE-88 9.1 Critical 2026-05-13
CVE-2026-44194 OPNsense: RCE on user managment CWE-78 9.1 Critical 2026-05-13
CVE-2026-44195 OPNsense: Authentication lockout bypass CWE-307 5.3 Medium 2026-05-13
CVE-2026-44193 OPNsense: RCE via XMLRPC endpoint using `opnsense.restore_config_section` method CWE-88 9.1 Critical 2026-05-13
CVE-2026-42552 Flight: Sensitive information disclosure via default error handler in flightphp/core CWE-209 7.5 High 2026-05-13
CVE-2026-42551 Flight: HTTP method override enabled by default enables CSRF escalation and middleware bypass in flightphp/core CWE-436 7.5 High 2026-05-13
CVE-2026-42550 Flight: SQL Injection via unvalidated identifiers in SimplePdo::insert / update / delete CWE-89 8.8 High 2026-05-13
CVE-2026-42549 Flight: Path traversal in `make:controller` CLI creates arbitrary directories outside project root CWE-22 4.4 Medium 2026-05-13
CVE-2026-42548 Flight: Reflected XSS via unvalidated JSONP callback in Flight::jsonp() CWE-79 - - 2026-05-13
CVE-2026-42278 UltraDAG: Smart Account Spending Policy Bypass via Pockets CWE-284 7.5AI High AI 2026-05-08
CVE-2026-40583 UltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant Halt CWE-460 9.1AI Critical AI 2026-04-21
CVE-2026-34578 OPNsense has an LDAP Injection via Unsanitized Username in Authentication CWE-90 8.2 High 2026-04-09
CVE-2026-34762 Ella Core Has Audit Log Falsification via Path/Body IMSI Mismatch in UpdateSubscriber CWE-20 2.7 Low 2026-04-02
CVE-2026-34761 Ella Core Panics Upon NGAP handover failure CWE-476 5.8 Medium 2026-04-02
CVE-2026-33907 Ella Core Panics during NAS Authentication Response/Failure with missing IEs CWE-476 6.5 Medium 2026-03-27
CVE-2026-33906 Ella Core has Privilege Escalation via Database Restore by NetworkManager role CWE-269 7.2 High 2026-03-27
CVE-2026-33904 Ella Core has a Denial of Service via SCTP connection cleanup deadlock CWE-833 6.5 Medium 2026-03-27
CVE-2026-33903 Ella Core panics when processing a crafted NGAP LocationReport message CWE-476 6.5 Medium 2026-03-27
CVE-2026-33045 Home Assistant has stored XSS in history-graphs CWE-79 6.1 - 2026-03-27
CVE-2026-33044 Home Assistant has stored XSS in Map-card through malicious device name CWE-79 5.4 - 2026-03-27
CVE-2026-23514 Kiteworks Core before 9.2.2 is vulnerable to Improper Ownership Management CWE-282 8.8 High 2026-03-25
CVE-2026-33283 Ella Core panics on malformed ULNASTransport Message without a Request Type CWE-476 6.5 Medium 2026-03-23
CVE-2026-33282 Ella Core panics on malformed NGAP Location Report CWE-476 7.5 High 2026-03-23
CVE-2026-33281 Ella Core panics on invalid PDU Session IDs in NGAP messages CWE-129 6.5 Medium 2026-03-23
CVE-2026-32320 Ella Core: AMF DoS via malformed PathSwitchRequest with empty NR security capability bitstrings CWE-125 6.5 Medium 2026-03-12
CVE-2026-32319 Ella Core: Unauthenticated AMF DoS via malformed InitialUEMessage with undersized integrity-protected NAS payload CWE-125 7.5 High 2026-03-12
CVE-2026-31889 Shopware has a potential take over of app credentials CWE-290 8.9 High 2026-03-11
CVE-2026-31888 Shopware has user enumeration via distinct error codes on Store API login endpoint CWE-204 5.3 Medium 2026-03-11
CVE-2026-31887 Shopware unauthenticated data extraction possible through store-api.order endpoint CWE-863 9.1AI Critical AI 2026-03-11
CVE-2026-30868 Cross-Site Request Forgery (CSRF) in opnsense/core CWE-352 6.3 Medium 2026-03-11

All 137 known CVE vulnerabilities affecting core with full Chinese analysis, references, and POCs where available.