Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2020-13664
Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an administrator into visiting a malic…
Drupal
8.8.8 / 8.9.1+
MEDIUM 6.1
CVE-2020-13662
Open Redirect vulnerability in Drupal Core allows a user to be tricked into visiting a specially crafted link which would redirect them to an arbitra…
Drupal
after 7.70
MEDIUM 6.1
CVE-2020-13666
Cross-site scripting vulnerability in Drupal Core. Drupal AJAX API does not disable JSONP by default, allowing for an XSS attack. This issue affects:…
Drupal
7.73 / 8.8.10+
CRITICAL 9.8
CVE-2020-35191
The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker…
Drupal Docker Images
after 8.5.10-fpm-alpine
HIGH 8.8
CVE-2020-13671 KEV
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and …
Drupal
7.74 / 8.8.11+
CRITICAL 9.8
CVE-2019-6342
An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Wor…
Drupal
Mitigation only
MEDIUM 6.5
CVE-2013-4226
The Authenticated User Page Caching (Authcache) module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to cached pages, which all…
Authenticated User Page Caching
Mitigation only
CRITICAL 9.8
CVE-2011-2715
An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.
Data
Patch available
MEDIUM 6.1
CVE-2011-2714
A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field na…
Data
Mitigation only
CRITICAL 9.8
CVE-2019-19826
The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.in…
Views Dynamic Field
after 6.x-1.4
MEDIUM 6.1
CVE-2011-3373
Drupal Views Builk Operations (VBO) module 6.x-1.0 through 6.x-1.10 does not properly escape the vocabulary help when the vocabulary has had user tag…
Views Builk Operations
after 6.x1.10
HIGH 8.8
CVE-2012-2079
A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal.
Activity
Mitigation only
HIGH 7.5
CVE-2011-2726
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type i…
Drupal
7.5+
HIGH 7.5
CVE-2019-18856
A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to external resources with an S…
Svg Sanitizer
after 7.x-1.5
MEDIUM 6.5
CVE-2010-2473
Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was bl…
Drupal
5.22 / 6.16+
MEDIUM 6.1
CVE-2010-2250
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform…
Drupal
5.22 / 6.16+
MEDIUM 6.1
CVE-2010-2471
Drupal versions 5.x and 6.x has open redirection
Drupal
5.22 / 6.16+
MEDIUM 5.4
CVE-2019-6341EPSS 12%
In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File mod…
Drupal
7.65 / 8.5.14+
HIGH 8.1
CVE-2019-6340 KEVEPSS 92%
Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to a…
Drupal
8.5.11 / 8.6.10+
CRITICAL 9.8
CVE-2019-6339EPSS 33%
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built…
Drupal
7.62 / 8.5.9+
MEDIUM 6.5
CVE-2017-6922
In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently a…
Drupal
7.56 / 8.3.4+
MEDIUM 6.5
CVE-2017-6923
In Drupal 8.x prior to 8.3.7 When creating a view, you can optionally use Ajax to update the displayed data via filter parameters. The views subsyste…
Drupal
after 8.3.7
HIGH 8.0
CVE-2019-6338
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-party PEAR Archive_Tar library. …
Drupal
7.62 / 8.5.9+
MEDIUM 5.9
CVE-2017-6921
In Drupal 8 prior to 8.3.4; The file REST resource does not properly validate some fields when manipulating files. A site is only affected by this if…
Drupal
8.3.4+
HIGH 7.4
CVE-2017-6924
In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST that are approved even if the us…
Drupal
8.3.7+
CRITICAL 9.8
CVE-2017-6925
In versions of Drupal 8 core prior to 8.3.7; There is a vulnerability in the entity access system that could allow unwanted access to view, create, u…
Drupal
8.3.7+
CRITICAL 9.8
CVE-2017-6920EPSS 20%
Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely dur…
Drupal
8.3.4+
CRITICAL 9.8
CVE-2018-7602 KEVEPSS 99%
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple …
Drupal
7.59 / 8.4.8+
MEDIUM 6.1
CVE-2018-9861
Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), a…
Drupal
4.9.2 / 8.4.7+
HIGH 7.5
CVE-2018-9205EPSS 56%
Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.
Avatar Uploader
No fix yet