Vulnerability index

Browse CVEs

252 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2022-25277 Drupal core sanitizes filenames with dangerous extensions upon upload (reference: SA-CORE-2020-012) and strips leading and trailing dots from filenam… Drupal 9.3.19 / 9.4.3+ Fix from $1,9502023-04-26 MEDIUM 6.5 CVE-2022-25278 Under certain circumstances, the Drupal core form API evaluates form element access incorrectly. This may lead to a user being able to alter data the… Drupal 9.3.19 / 9.4.3+ Fix from $1,6002023-04-26 MEDIUM 6.1 CVE-2022-25276 The Media oEmbed iframe route does not properly validate the iframe domain setting, which allows embeds to be displayed in the context of the primary… Drupal 9.3.19 / 9.4.3+ Fix from $1,6002023-04-26 HIGH 7.5 CVE-2022-25273 Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This co… Drupal 9.2.18 / 9.3.12+ Fix from $1,9502023-04-26 HIGH 7.5 CVE-2022-25275 In some situations, the Image module does not correctly check access to image files not stored in the standard public files directory when generating… Drupal 7.91 / 9.3.19+ Fix from $1,9502023-04-26 MEDIUM 5.4 CVE-2022-25274 Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, r… Drupal 9.3.12+ Fix from $1,6002023-04-26 HIGH 7.5 CVE-2022-31042 Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive information. On making a request using … Drupal 6.5.7 / 7.4.4+ Fix from $1,9502022-06-10 HIGH 7.5 CVE-2022-31043 Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive information. On making a request usi… Drupal 6.5.7 / 7.4.4+ Fix from $1,9502022-06-10 HIGH 8.8 CVE-2022-26493 Xecurify's miniOrange Premium, Standard, and Enterprise Drupal SAML SP modules possess an authentication and authorization bypass vulnerability. An a… Saml Sp 2.0 Single Sign On after 8.x-2.24 Fix from $1,9502022-06-03 HIGH 8.1 CVE-2022-29248 Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that … Drupal 6.5.6 / 7.4.3+ Fix from $1,9502022-05-25 HIGH 7.5 CVE-2022-24775 guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak… Drupal 1.8.4 / 2.1.1+ Fix from $1,9502022-03-21 HIGH 7.5 CVE-2022-24729 CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plug… Drupal 4.18.0 / 9.2.15+ Fix from $1,9502022-03-16 MEDIUM 5.4 CVE-2022-24728 CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may … Drupal 4.18.0 / 9.2.15+ Fix from $1,6002022-03-16 MEDIUM 6.5 CVE-2022-25270 The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" perm… Drupal 9.2.13 / 9.3.6+ Fix from $1,6002022-02-17 HIGH 7.5 CVE-2022-25271 Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This co… Drupal 7.88 / 9.2.13+ Fix from $1,9502022-02-16 CRITICAL 9.8 CVE-2020-13675 Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which cause… Drupal 8.9.19 / 9.1.13+ Fix from $2,3002022-02-11 HIGH 7.5 CVE-2020-13670 Information Disclosure vulnerability in file module of Drupal Core allows an attacker to gain access to the file metadata of a permanent private file… Drupal 8.8.10 / 8.9.6+ Fix from $1,9502022-02-11 HIGH 7.5 CVE-2020-13677 Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which may result in unintended access… Drupal 8.9.19 / 9.1.13+ Fix from $1,9502022-02-11 MEDIUM 6.5 CVE-2020-13674 The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to p… Drupal 8.9.19 / 9.1.13+ Fix from $1,6002022-02-11 MEDIUM 6.5 CVE-2020-13676 The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data. Sites are… Drupal 8.9.19 / 9.1.13+ Fix from $1,6002022-02-11 MEDIUM 6.1 CVE-2020-13668 Access Bypass vulnerability in Drupal Core allows for an attacker to leverage the way that HTML is rendered for affected forms in order to exploit th… Drupal 8.8.10 / 8.9.6+ Fix from $1,6002022-02-11 MEDIUM 6.1 CVE-2020-13669 Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows attacker to inject XSS. This issue affects: Drupal Core 8.8.x versions pri… Drupal 8.8.10 / 8.9.6+ Fix from $1,6002022-02-11 MEDIUM 6.1 CVE-2020-13672 Cross-site Scripting (XSS) vulnerability in Drupal core's sanitization API fails to properly filter cross-site scripting under certain circumstances.… Drupal 7.80 / 8.9.14+ Fix from $1,6002022-02-11 MEDIUM 6.1 CVE-2020-13673 The Entity Embed module provides a filter to allow embedding entities in content fields. In certain circumstances, the filter could allow an unprivil… Entity Embed Patch available Fix from $1,6002022-02-11 MEDIUM 5.4 CVE-2021-41165 CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may a… Drupal 4.17.0 / 8.9.20+ Fix from $1,6002021-11-17 MEDIUM 5.4 CVE-2021-41164 CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module… Drupal 4.17.0 / 8.9.20+ Fix from $1,6002021-11-17 HIGH 8.8 CVE-2020-13663 Cross Site Request Forgery vulnerability in Drupal Core Form API does not properly handle certain form input from cross-site requests, which can lead… Drupal 7.72 / 8.8.8+ Fix from $1,9502021-06-11 MEDIUM 6.1 CVE-2020-13688 Cross-site scripting vulnerability in l Drupal Core allows an attacker could leverage the way that HTML is rendered for affected forms in order to ex… Drupal 8.8.10 / 8.9.6+ Fix from $1,6002021-06-11 MEDIUM 5.3 CVE-2020-13667 Access bypass vulnerability in of Drupal Core Workspaces allows an attacker to access data without correct permissions. The Workspaces module doesn't… Drupal 8.8.10 / 8.9.6+ Fix from $1,6002021-05-17 CRITICAL 9.8 CVE-2020-13665 Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in read/write mode. Only sites that have the read_only set to FALSE under… Drupal 8.8.8 / 8.9.1+ Fix from $2,3002021-05-05