Vulnerability index

Browse CVEs

38 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2024-45440EPSS 9% core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of… Drupal No fix yet Fix from $1,6002024-08-29 HIGH 7.5 CVE-2024-22362 Drupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an attacker may be able to cause a… Drupal Mitigation only Fix from $1,9502024-01-16 CRITICAL 9.8 CVE-2019-6342 An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Wor… Drupal Mitigation only Fix from $2,3002020-05-28 MEDIUM 6.5 CVE-2013-4226 The Authenticated User Page Caching (Authcache) module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to cached pages, which all… Authenticated User Page Caching Mitigation only Fix from $1,6002020-02-18 MEDIUM 6.1 CVE-2011-2714 A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field na… Data Mitigation only Fix from $1,6002020-01-14 HIGH 8.8 CVE-2012-2079 A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal. Activity Mitigation only Fix from $1,9502019-11-22 HIGH 7.5 CVE-2018-9205EPSS 56% Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path. Avatar Uploader No fix yet Fix from $1,9502018-04-04 CRITICAL 9.8 CVE-2014-5170 The Storage API module 7.x before 7.x-1.6 for Drupal might allow remote attackers to execute arbitrary code by leveraging failure to update .htaccess… Storage Api Mitigation only Fix from $2,3002018-03-29 MEDIUM 6.1 CVE-2015-7943 Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the LABj… Drupal Mitigation only Fix from $1,6002017-10-18 HIGH 8.1 CVE-2017-6381 A 3rd party development library including with Drupal 8 development dependencies is vulnerable to remote code execution. This is mitigated by the def… Drupal Mitigation only Fix from $1,9502017-03-16 HIGH 7.5 CVE-2017-6377 When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resul… Drupal Mitigation only Fix from $1,9502017-03-16 HIGH 7.5 CVE-2017-6379 Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a … Drupal Mitigation only Fix from $1,9502017-03-16 MEDIUM 6.1 CVE-2016-7571 Cross-site scripting (XSS) vulnerability in Drupal 8.x before 8.1.10 allows remote attackers to inject arbitrary web script or HTML via vectors invol… Drupal Mitigation only Fix from $1,6002016-10-03 MEDIUM 5.3 CVE-2016-6212 The Views module 7.x-3.x before 7.x-3.14 in Drupal 7.x and the Views module in Drupal 8.x before 8.1.3 might allow remote authenticated users to bypa… Drupal Mitigation only Fix from $1,6002016-09-09 HIGH 8.8 CVE-2016-6211 The User module in Drupal 7.x before 7.44 allows remote authenticated users to gain privileges via vectors involving contributed or custom code that … Drupal Mitigation only Fix from $1,9502016-09-09 MEDIUM 5.8 CVE-2015-3232 Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and con… Drupal Mitigation only Fix from $1,6002015-06-22 MEDIUM 6.8 CVE-2013-7407 Cross-site request forgery (CSRF) vulnerability in the MRBS module for Drupal allows remote attackers to hijack the authentication of unspecified vic… Mrbs Module Mitigation only Fix from $1,6002014-10-22 HIGH 7.5 CVE-2014-1475 The OpenID module in Drupal 6.x before 6.30 and 7.x before 7.26 allows remote OpenID users to authenticate as other users via unspecified vectors. Drupal Mitigation only Fix from $1,9502014-01-24 MEDIUM 6.8 CVE-2012-0825 Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modif… Drupal Mitigation only Fix from $1,6002013-10-28 MEDIUM 6.8 CVE-2012-0826 Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hij… Drupal Mitigation only Fix from $1,6002013-10-28 HIGH 7.5 CVE-2012-2306 SQL injection vulnerability in the Addressbook module for Drupal 6.x-4.2 and earlier allows remote attackers to execute arbitrary SQL commands via un… Drupal Mitigation only Fix from $1,9502012-07-25 MEDIUM 5.8 CVE-2012-1589 Open redirect vulnerability in the Form API in Drupal 7.x before 7.13 allows remote attackers to redirect users to arbitrary web sites and conduct ph… Drupal Mitigation only Fix from $1,6002012-05-18 MEDIUM 5.0 CVE-2011-3730 Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an err… Drupal No fix yet Fix from $1,6002011-09-23 HIGH 7.5 CVE-2008-6134 SQL injection vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified … Everyblog Mitigation only Fix from $1,9502009-02-14 HIGH 7.5 CVE-2008-6136 Unspecified vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to gain privileges as another user or an administrat… Everyblog No fix yet Fix from $1,9502009-02-14 HIGH 7.5 CVE-2008-6137 EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to bypass access restrictions via unknown vectors. Everyblog No fix yet Fix from $1,9502009-02-14 MEDIUM 6.0 CVE-2008-4633 SQL injection vulnerability in Node Vote 5.x before 5.x-1.1 and 6.x before 6.x-1.0, a module for Drupal, when "Allow user to vote again" is enabled, … Node Clone Mitigation only Fix from $1,6002008-10-21 HIGH 7.5 CVE-2008-4597 Shindig-Integrator 5.x, a module for Drupal, does not properly restrict generated page access, which allows remote attackers to gain privileges via u… Shindig Integrator Mitigation only Fix from $1,9502008-10-17 HIGH 7.5 CVE-2008-4598 Unspecified vulnerability in Shindig-Integrator 5.x, a module for Drupal, has unspecified impact and remote attack vectors related to "numerous flaws… Shindig Integrator Mitigation only Fix from $1,9502008-10-17 MEDIUM 5.0 CVE-2008-3661 Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http… Drupal Mitigation only Fix from $1,6002008-09-23