Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2026-9082 KEVEPSS 88%
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection.
This …
Drupal
10.4.10 / 10.5.10+
HIGH 8.8
CVE-2020-13671 KEV
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and …
Drupal
7.74 / 8.8.11+
HIGH 8.1
CVE-2019-6340 KEVEPSS 92%
Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to a…
Drupal
8.5.11 / 8.6.10+
CRITICAL 9.8
CVE-2018-7602 KEVEPSS 99%
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple …
Drupal
7.59 / 8.4.8+
CRITICAL 9.8
CVE-2018-7600 KEVEPSS 100%
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issu…
Drupal
8.3.9 / 8.4.6+