CVE-2023-51767high · CVSS 7.0 — OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer val
CVE-2026-35385high · CVSS 7.5 — In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the
CVE-2026-35386low · CVSS 3.6 — In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario w
CVE-2026-35387low · CVSS 3.1 — OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgo
CVE-2026-35388low · CVSS 2.5 — OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
CVE-2026-35414medium · CVSS 4.2 — OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a
CVE-2026-59995medium · CVSS 4.2 — sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker
CVE-2026-59996medium · CVSS 4.2 — scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destina
CVE-2026-59997medium · CVSS 4.2 — internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-l
CVE-2026-59998medium · CVSS 4.8 — sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windo
CVE-2026-59999medium · CVSS 5.9 — In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
CVE-2026-60000low · CVSS 3.7 — sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempt
CVE-2026-60001medium · CVSS 6.5 — sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
CVE-2026-60002high · CVSS 7.7 — ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only
CVE-2024-11941high · CVSS 7.5 — A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, from 10.1.0 before 10.
CVE-2024-12393medium · CVSS 5.4 — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site S
CVE-2024-55634high · CVSS 8.1 — A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.
CVE-2024-55636critical · CVSS 9.8 — Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.
CVE-2024-55637critical · CVSS 9.8 — Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.
CVE-2024-55638critical · CVSS 9.8 — Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102
CVE-2025-31673medium · CVSS 4.6 — Incorrect Authorization vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: from 8.0.0 before 10.3.
CVE-2025-31674high · CVSS 7.5 — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.T
CVE-2025-31675medium · CVSS 5.4 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site S
CVE-2025-3057medium · CVSS 6.1 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site S
CVE-2025-13080medium · CVSS 5.3 — Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal
CVE-2025-13081medium · CVSS 5.9 — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.T
CVE-2025-13082medium · CVSS 4.3 — User Interface (UI) Misrepresentation of Critical Information vulnerability in Drupal Drupal core allows Content Spoofing.This issue affects
CVE-2025-13083low · CVSS 3.7 — Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrectly Configured Acces