Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

core — Vulnerabilities & Security Advisories 93

All 93 CVE vulnerabilities found in core, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations affecting the core product line maintained by the vendor. It aggregates vulnerability data spanning from the initial release of the software through the most recent security advisories published in the current year. The content is organized to help security professionals and developers understand the historical context of software defects within this specific product ecosystem. Users can track the vendor's patching cadence and response times for critical issues. The page also provides insights into prevalent weakness classes, allowing analysts to identify recurring patterns in code quality or architectural flaws. Developers can look up the complete vulnerability history of the core product to assess long-term stability and risk. This resource serves as a centralized reference for auditing past incidents and evaluating the effectiveness of security measures implemented by the vendor over time. By reviewing these aggregated records, teams can better anticipate potential future threats and prioritize remediation efforts based on historical trends. The information is presented in a structured format to facilitate quick searching and comprehensive analysis without overwhelming the reader with unnecessary details.

Vendor: Drupal

CVE ID Title CVSS Severity Published
CVE-2023-50715 User accounts disclosed to unauthenticated actors on the LAN CWE-200 4.3 Medium 2023-12-15
CVE-2023-41893 Account takeover via auth_callback login in Home Assistant Core CWE-200 4.3 Medium 2023-10-19
CVE-2023-41894 Local-only webhooks externally accessible via SniTun in Home Assistant Core CWE-669 5.3 Medium 2023-10-19
CVE-2023-41895 Cross-site Scripting via auth_callback login in Home Assistant Core CWE-79 8.8 High 2023-10-19
CVE-2023-41896 Fake websocket server installation permits full takeover in Home Assistant Core CWE-345 7.1 High 2023-10-19
CVE-2023-41897 Lack of XFO header allows clickjacking in Home Assistant Core CWE-1021 8.8 High 2023-10-19
CVE-2023-41899 Partial Server-Side Request Forgery in Home Assistant Core CWE-918 6.6 Medium 2023-10-19
CVE-2023-41898 Arbitrary URL load in Android WebView in `MyActivity.kt` in Home Assistant Companion for Android CWE-345 8.6 High 2023-10-19
CVE-2023-44385 Client-Side Request Forgery in Home Assistant iOS/macOS native Apps CWE-352 8.6 High 2023-10-19
CVE-2023-5256 Drupal core - Critical - Cache poisoning - SA-CORE-2023-006 CWE-200 9.1 - 2023-09-28
CVE-2022-25273 Drupal core 输入验证错误漏洞 7.5 - 2023-04-26
CVE-2022-25274 Drupal 安全漏洞 8.1 - 2023-04-26
CVE-2022-25275 Drupal 安全漏洞 8.8 - 2023-04-26
CVE-2022-25276 Drupal 跨站脚本漏洞 6.1 - 2023-04-26
CVE-2022-25277 Drupal 代码问题漏洞 8.2 - 2023-04-26
CVE-2022-25278 Drupal 访问控制错误漏洞 6.5 - 2023-04-26
CVE-2023-31250 Drupal core - Moderately critical - Access bypass - SA-CORE-2023-005 6.5 - 2023-04-26
CVE-2023-27482 Home Assistant 授权问题漏洞 CWE-287 10.0 Critical 2023-03-08
CVE-2023-25575 Secured properties in API Platform Core may be accessible within collections CWE-842 7.7 High 2023-02-28
CVE-2022-25270 Drupal 访问控制错误漏洞 6.5 - 2022-02-16
CVE-2022-25271 Drupal 输入验证错误漏洞 CWE-20 7.5 - 2022-02-16
CVE-2020-13677 Drupal 安全漏洞 CWE-284 5.9 - 2022-02-11
CVE-2020-13676 Drupal 访问控制错误漏洞 CWE-284 6.5 - 2022-02-11
CVE-2020-13670 Drupal core 信息泄露漏洞 7.5 - 2022-02-11
CVE-2020-13674 Drupal QuickEdit module 跨站请求伪造漏洞 CWE-352 6.5 - 2022-02-11
CVE-2020-13675 Drupal 代码问题漏洞 CWE-284 9.1 - 2022-02-11
CVE-2020-13672 Drupal跨站脚本漏洞 CWE-79 6.1 - 2022-02-11
CVE-2020-13669 Drupal core 跨站脚本漏洞 CWE-79 6.1 - 2022-02-11
CVE-2020-13668 Access bypass in Drupal Core 8/9 7.2 - 2022-02-11
CVE-2021-32671 XSS vulnerability with translator CWE-79 10.0 Critical 2021-06-07

All 93 known CVE vulnerabilities affecting core with full Chinese analysis, references, and POCs where available.