Vulnerability index

Browse CVEs

252 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Drupal MEDIUM 5.8
CVE-2015-3233

Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and cond…

Patch available
Fix from $1,600 2015-06-22
Drupal MEDIUM 5.8
CVE-2015-3232

Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and con…

Mitigation only
Fix from $1,600 2015-06-22
Drupal MEDIUM 5.0
CVE-2014-9016EPSS 82%

The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote…

Fix: 6.x-2.1 / 7.34+
Fix from $1,600 2014-11-24
Drupal MEDIUM 6.8
CVE-2014-9015

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to …

Fix: 6.34 / 7.34+
Fix from $1,600 2014-11-24
Mrbs Module MEDIUM 6.8
CVE-2013-7407

Cross-site request forgery (CSRF) vulnerability in the MRBS module for Drupal allows remote attackers to hijack the authentication of unspecified vic…

Mitigation only
Fix from $1,600 2014-10-22
Drupal HIGH 7.5
CVE-2014-3704EPSS 100%

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which al…

Fix: 7.32+
Fix from $1,950 2014-10-16
Drupal MEDIUM 6.8
CVE-2014-5267

modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declar…

Patch available
Fix from $1,600 2014-09-30
Drupal MEDIUM 5.0
CVE-2014-5019

The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host head…

Patch available
Fix from $1,600 2014-07-22
Drupal MEDIUM 5.0
CVE-2014-2983

Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different anonymous users, which allows remote anonymous user…

Fix: 6.31 / 7.27+
Fix from $1,600 2014-04-23
Drupal HIGH 7.5
CVE-2014-1475

The OpenID module in Drupal 6.x before 6.30 and 7.x before 7.26 allows remote OpenID users to authenticate as other users via unspecified vectors.

Mitigation only
Fix from $1,950 2014-01-24
Drupal MEDIUM 6.8
CVE-2013-6386

Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote a…

Patch available
Fix from $1,600 2013-12-07
Drupal MEDIUM 5.8
CVE-2013-6389

Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.24 allows remote attackers to redirect users to arbitrary web sites and cond…

Patch available
Fix from $1,600 2013-12-07
Drupal MEDIUM 5.1
CVE-2013-6385

The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF v…

Patch available
Fix from $1,600 2013-12-07
Drupal MEDIUM 6.8
CVE-2012-0825

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modif…

Mitigation only
Fix from $1,600 2013-10-28
Drupal MEDIUM 6.8
CVE-2012-0826

Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hij…

Mitigation only
Fix from $1,600 2013-10-28
Drupal MEDIUM 5.0
CVE-2013-0316

The Image module in Drupal 7.x before 7.20 allows remote attackers to cause a denial of service (CPU and disk space consumption) via a large number o…

Patch available
Fix from $1,600 2013-03-27
Drupal MEDIUM 6.0
CVE-2012-5653

The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execut…

Patch available
Fix from $1,600 2013-01-03
Drupal MEDIUM 5.0
CVE-2012-5651

Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information…

Patch available
Fix from $1,600 2013-01-03
Drupal MEDIUM 5.0
CVE-2012-5652

Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result.

Patch available
Fix from $1,600 2013-01-03
Drupal MEDIUM 6.8
CVE-2012-4553

Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an e…

Patch available
Fix from $1,600 2012-11-11
Drupal MEDIUM 5.0
CVE-2012-4554EPSS 16%

The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an XRDS file.

Patch available
Fix from $1,600 2012-11-11
Drupal MEDIUM 5.0
CVE-2012-1591

The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of private images, which allows r…

Patch available
Fix from $1,600 2012-10-01
Drupal HIGH 7.5
CVE-2012-2306

SQL injection vulnerability in the Addressbook module for Drupal 6.x-4.2 and earlier allows remote attackers to execute arbitrary SQL commands via un…

Mitigation only
Fix from $1,950 2012-07-25
Drupal MEDIUM 5.0
CVE-2012-2922

The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] pa…

Fix: after 7.14
Fix from $1,600 2012-05-21
Drupal MEDIUM 5.8
CVE-2012-1589

Open redirect vulnerability in the Form API in Drupal 7.x before 7.13 allows remote attackers to redirect users to arbitrary web sites and conduct ph…

Mitigation only
Fix from $1,600 2012-05-18
Drupal MEDIUM 6.8
CVE-2007-6752

Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users fo…

Fix: after 7.12
Fix from $1,600 2012-03-28
Drupal MEDIUM 5.0
CVE-2011-3730

Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an err…

No fix yet
Fix from $1,600 2011-09-23
Drupal HIGH 7.5
CVE-2011-2687

Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks…

Patch available
Fix from $1,950 2011-07-27
Drupal MEDIUM 5.0
CVE-2010-3685

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking fo…

Patch available
Fix from $1,600 2010-09-29
Drupal MEDIUM 5.0
CVE-2010-3686

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring th…

Patch available
Fix from $1,600 2010-09-29