Vulnerabilities
Summary — last 7 days
New vulnerabilities2,544▼ 345 vs. last week
Critical / high1,339▲ 68 vs. last week
New active exploitation (KEV)5▼ 7 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (5.8) | 1.3% | — | Node Access User Reference Project Nodeaccess Userreference Module | 8/28/2013 | 6/16/2026 | The Node access user reference module 6.x-3.x before 6.x-3.5 and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to content containing a user reference field when the author update/delete grants are enabled and the author's user account is deleted, which allows remote attackers to modify the… | |
| Modified | High (7.5) | 1.4% | — | Drupal Nodeaccess Userreference | 5/1/2009 | 6/16/2026 | The Node Access User Reference module 5.x before 5.x-2.0-beta4 and 6.x before 6.x-2.0-beta6, a module for Drupal, interprets an empty CCK user reference as a reference to the anonymous user, which might allow remote attackers to bypass intended access restrictions to read or modify a node. |