NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-16638 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders allows Stored XSS. This iss... 2026-08-25 6.1 NETWORK MEDIUM NVD
CVE-2026-15917 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (... 2026-08-25 4.7 NETWORK MEDIUM NVD
CVE-2026-15916 Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, fr... 2026-08-25 4.2 NETWORK MEDIUM NVD
CVE-2026-15088 Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*. 2026-08-25 5.7 NETWORK MEDIUM NVD
CVE-2026-80186 A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a... 2026-08-25 7.6 ADJACENT_NETWORK HIGH NVD
CVE-2026-80185 BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP... 2026-08-25 5.7 ADJACENT_NETWORK MEDIUM NVD
CVE-2026-80184 In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts) c... 2026-08-25 7.6 NETWORK HIGH NVD
CVE-2026-80182 In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new ... 2026-08-25 7.6 NETWORK HIGH NVD
CVE-2026-73180 Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebS... 2026-08-25 6.8 NETWORK MEDIUM NVD
CVE-2026-68763 Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This ... 2026-08-25 7.5 NETWORK HIGH NVD
CVE-2026-68569 Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated ... 2026-08-25 8.1 NETWORK HIGH NVD
CVE-2026-68525 Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user ha... 2026-08-25 9.1 NETWORK CRITICAL NVD
CVE-2026-66422 Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm i... 2026-08-25 8.1 NETWORK HIGH NVD
CVE-2026-65927 Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule r... 2026-08-25 7.5 NETWORK HIGH NVD
CVE-2026-65905 Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client... 2026-08-25 9.8 NETWORK CRITICAL NVD