Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.9
CVE-2026-55803
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issu…
Drupal
10.5.12 / 10.6.11+
MEDIUM 5.9
CVE-2026-55804
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issu…
Drupal
10.5.12 / 10.6.11+
MEDIUM 5.9
CVE-2026-55806
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versi…
Drupal
10.5.12 / 10.6.11+
MEDIUM 5.4
CVE-2026-55808
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting …
Drupal
10.5.12 / 10.6.11+
CRITICAL 9.8
CVE-2026-9082 KEVEPSS 88%
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection.
This …
Drupal
10.4.10 / 10.5.10+
MEDIUM 6.6
CVE-2026-6366
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.
This iss…
Drupal
10.5.9 / 10.6.7+
MEDIUM 6.1
CVE-2026-6365
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting …
Drupal
10.5.9 / 10.6.7+
MEDIUM 6.1
CVE-2026-6367
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting …
Drupal
11.3.7+
MEDIUM 5.9
CVE-2025-13081
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue…
Drupal
10.4.9 / 10.5.6+
MEDIUM 5.3
CVE-2025-13080
Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: fro…
Drupal
10.4.9 / 10.5.6+
HIGH 8.6
CVE-2025-48914
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-…
Cookies Consent Management
1.2.15+
HIGH 8.6
CVE-2025-48915
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-…
Cookies Consent Management
1.2.15+
MEDIUM 6.5
CVE-2025-3474
Missing Authentication for Critical Function vulnerability in Drupal Panels allows Exploiting Incorrectly Configured Access Control Security Levels.T…
Panels
4.9+
MEDIUM 5.4
CVE-2025-3131
Cross-Site Request Forgery (CSRF) vulnerability in Drupal ECA: Event - Condition - Action allows Cross Site Request Forgery.This issue affects ECA: E…
Eca\
1.1.12 / 2.0.16+
MEDIUM 5.4
CVE-2025-3130
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Obfuscate allows Stored XSS.This issue a…
Obfuscate
2.0.1+
MEDIUM 6.1
CVE-2025-3057
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting …
Drupal
10.3.13 / 10.4.3+
MEDIUM 5.4
CVE-2025-31675
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting …
Drupal
10.3.14 / 10.4.5+
HIGH 7.5
CVE-2025-31674
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue…
Drupal
10.3.13 / 10.4.3+
CRITICAL 9.8
CVE-2024-55636
Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, fro…
Drupal
10.2.11 / 10.3.9+
CRITICAL 9.8
CVE-2024-55637
Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, fro…
Drupal
10.2.11 / 10.3.9+
CRITICAL 9.8
CVE-2024-55638
Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.…
Drupal
7.102 / 10.2.11+
HIGH 8.1
CVE-2024-55634
A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from…
Drupal
10.2.11 / 10.3.9+
MEDIUM 6.1
CVE-2024-55635
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting …
Drupal
7.102+
MEDIUM 5.4
CVE-2024-12393
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting …
Drupal
10.2.11 / 10.3.9+
HIGH 7.5
CVE-2024-11941
A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, from 10.1.0 before 10.1.8.
Drupal
10.1.8 / 10.2.2+
MEDIUM 5.9
CVE-2024-11942
A vulnerability in Drupal Core allows File Manipulation.This issue affects Drupal Core: from 10.0.0 before 10.2.10.
Drupal
10.2.10+
MEDIUM 5.3
CVE-2024-45440EPSS 9%
core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of…
Drupal
No fix yet
HIGH 7.5
CVE-2024-22362
Drupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an attacker may be able to cause a…
Drupal
Mitigation only
HIGH 7.5
CVE-2023-5256
In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause sensitive information to be cac…
Drupal
9.5.11 / 10.0.11+
MEDIUM 6.5
CVE-2023-31250
The file download facility doesn't sufficiently sanitize file paths in certain situations. This may result in users gaining access to private files t…
Drupal
7.96 / 9.4.14+