Vulnerability index

Browse CVEs

252 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.9 CVE-2026-55803 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issu… Drupal 10.5.12 / 10.6.11+ Fix from $1,6002026-07-10 MEDIUM 5.9 CVE-2026-55804 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issu… Drupal 10.5.12 / 10.6.11+ Fix from $1,6002026-07-10 MEDIUM 5.9 CVE-2026-55806 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versi… Drupal 10.5.12 / 10.6.11+ Fix from $1,6002026-07-10 MEDIUM 5.4 CVE-2026-55808 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting … Drupal 10.5.12 / 10.6.11+ Fix from $1,6002026-07-10 CRITICAL 9.8 CVE-2026-9082 KEVEPSS 88% Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This … Drupal 10.4.10 / 10.5.10+ Fix from $2,3002026-05-20 MEDIUM 6.6 CVE-2026-6366 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This iss… Drupal 10.5.9 / 10.6.7+ Fix from $1,6002026-05-19 MEDIUM 6.1 CVE-2026-6365 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting … Drupal 10.5.9 / 10.6.7+ Fix from $1,6002026-05-19 MEDIUM 6.1 CVE-2026-6367 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting … Drupal 11.3.7+ Fix from $1,6002026-05-19 MEDIUM 5.9 CVE-2025-13081 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue… Drupal 10.4.9 / 10.5.6+ Fix from $1,6002025-11-18 MEDIUM 5.3 CVE-2025-13080 Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: fro… Drupal 10.4.9 / 10.5.6+ Fix from $1,6002025-11-18 HIGH 8.6 CVE-2025-48914 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-… Cookies Consent Management 1.2.15+ Fix from $1,9502025-06-13 HIGH 8.6 CVE-2025-48915 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-… Cookies Consent Management 1.2.15+ Fix from $1,9502025-06-13 MEDIUM 6.5 CVE-2025-3474 Missing Authentication for Critical Function vulnerability in Drupal Panels allows Exploiting Incorrectly Configured Access Control Security Levels.T… Panels 4.9+ Fix from $1,6002025-04-09 MEDIUM 5.4 CVE-2025-3131 Cross-Site Request Forgery (CSRF) vulnerability in Drupal ECA: Event - Condition - Action allows Cross Site Request Forgery.This issue affects ECA: E… Eca\ 1.1.12 / 2.0.16+ Fix from $1,6002025-04-09 MEDIUM 5.4 CVE-2025-3130 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Obfuscate allows Stored XSS.This issue a… Obfuscate 2.0.1+ Fix from $1,6002025-04-02 MEDIUM 6.1 CVE-2025-3057 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting … Drupal 10.3.13 / 10.4.3+ Fix from $1,6002025-03-31 MEDIUM 5.4 CVE-2025-31675 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting … Drupal 10.3.14 / 10.4.5+ Fix from $1,6002025-03-31 HIGH 7.5 CVE-2025-31674 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue… Drupal 10.3.13 / 10.4.3+ Fix from $1,9502025-03-31 CRITICAL 9.8 CVE-2024-55636 Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, fro… Drupal 10.2.11 / 10.3.9+ Fix from $2,3002024-12-10 CRITICAL 9.8 CVE-2024-55637 Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, fro… Drupal 10.2.11 / 10.3.9+ Fix from $2,3002024-12-10 CRITICAL 9.8 CVE-2024-55638 Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.… Drupal 7.102 / 10.2.11+ Fix from $2,3002024-12-10 HIGH 8.1 CVE-2024-55634 A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from… Drupal 10.2.11 / 10.3.9+ Fix from $1,9502024-12-10 MEDIUM 6.1 CVE-2024-55635 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting … Drupal 7.102+ Fix from $1,6002024-12-10 MEDIUM 5.4 CVE-2024-12393 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting … Drupal 10.2.11 / 10.3.9+ Fix from $1,6002024-12-10 HIGH 7.5 CVE-2024-11941 A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, from 10.1.0 before 10.1.8. Drupal 10.1.8 / 10.2.2+ Fix from $1,9502024-12-05 MEDIUM 5.9 CVE-2024-11942 A vulnerability in Drupal Core allows File Manipulation.This issue affects Drupal Core: from 10.0.0 before 10.2.10. Drupal 10.2.10+ Fix from $1,6002024-12-05 MEDIUM 5.3 CVE-2024-45440EPSS 9% core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of… Drupal No fix yet Fix from $1,6002024-08-29 HIGH 7.5 CVE-2024-22362 Drupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an attacker may be able to cause a… Drupal Mitigation only Fix from $1,9502024-01-16 HIGH 7.5 CVE-2023-5256 In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause sensitive information to be cac… Drupal 9.5.11 / 10.0.11+ Fix from $1,9502023-09-28 MEDIUM 6.5 CVE-2023-31250 The file download facility doesn't sufficiently sanitize file paths in certain situations. This may result in users gaining access to private files t… Drupal 7.96 / 9.4.14+ Fix from $1,6002023-04-26