General-Purpose System Vulnerabilities
Vulnerabilities related to traditional IT systems, servers, and desktop applications.
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2025-6675 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows… | Medium (4.8) | 2025-06-26 | General-Purpose |
| CVE-2025-6674 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor5 … | Medium (6.1) | 2025-06-26 | General-Purpose |
| CVE-2025-5682 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cook… | Medium (4.3) | 2025-06-26 | General-Purpose |
| CVE-2025-49003 | DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, a threat actor … | Critical (9.8) | 2025-06-26 | General-Purpose |
| CVE-2025-48923 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Toc.Js all… | Medium (6.1) | 2025-06-26 | General-Purpose |