Vulnerability index

Browse CVEs

252 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2010-3091 The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not verifying t… Drupal Patch available Fix from $1,6002010-09-29 MEDIUM 5.5 CVE-2010-3092 The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configurat… Drupal Patch available Fix from $1,6002010-09-21 MEDIUM 6.8 CVE-2009-4066 Multiple cross-site request forgery (CSRF) vulnerabilities in the "My Account" feature in PHPList Integration module 5 before 5.x-1.2 and 6 before 6.… Drupal Patch available Fix from $1,6002009-11-24 HIGH 10.0 CVE-2009-3352 Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors. Drupal 7.0+ Fix from $1,9502009-09-24 MEDIUM 6.5 CVE-2009-2372 Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator… Drupal 6.13+ Fix from $1,6002009-07-08 MEDIUM 6.4 CVE-2009-2035 Unspecified vulnerability in Services 6.x before 6.x-0.14, a module for Drupal, when key-based access is enabled, allows remote attackers to read or … Services Module For Drupal after 6.x-0.13 Fix from $1,6002009-06-12 HIGH 7.5 CVE-2009-1507 The Node Access User Reference module 5.x before 5.x-2.0-beta4 and 6.x before 6.x-2.0-beta6, a module for Drupal, interprets an empty CCK user refere… Nodeaccess Userreference Patch available Fix from $1,9502009-05-01 MEDIUM 6.5 CVE-2009-1505 SQL injection vulnerability in the News Page module 5.x before 5.x-1.2 for Drupal allows remote authenticated users, with News Page nodes create and … News Page Patch available Fix from $1,6002009-05-01 MEDIUM 6.8 CVE-2008-6532 Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers … Drupal Patch available Fix from $1,6002009-03-26 HIGH 10.0 CVE-2009-1034 SQL injection vulnerability in the Tasklist module 5.x-1.x before 5.x-1.3 and 5.x-2.x before 5.x-2.0-alpha1, a module for Drupal, allows remote attac… Tasklist after 5.x-2.x Fix from $1,9502009-03-20 MEDIUM 6.8 CVE-2009-1036 Cross-site request forgery (CSRF) vulnerability in the Plus 1 module before 6.x-2.6, a module for Drupal, allows remote attackers to cast votes for c… Plus1 after 6.x-2.5 Fix from $1,6002009-03-20 MEDIUM 5.0 CVE-2009-1037 Unspecified vulnerability in the Send by e-mail module in the "Printer, e-mail and PDF versions" module 5.x before 5.x-4.4 and 6.x before 6.x-1.4, a … Print Patch available Fix from $1,6002009-03-20 MEDIUM 6.8 CVE-2008-6384 Multiple cross-site request forgery (CSRF) vulnerabilities in Comment Mail 5.x before 5.x-1.1, a module for Drupal, allow remote attackers to hijack … Comment Mail Patch available Fix from $1,6002009-03-02 MEDIUM 6.0 CVE-2008-6383 SQL injection vulnerability in SpeedTech Organization and Resource Manager (Storm) 5.x before 5.x-1.14 and 6.x before 6.x-1.18, a module for Drupal, … Storm Patch available Fix from $1,6002009-03-02 MEDIUM 6.5 CVE-2008-6276 Multiple SQL injection vulnerabilities in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allow remote a… User Karma Module Patch available Fix from $1,6002009-02-25 HIGH 9.3 CVE-2008-6171 includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attack… Drupal Patch available Fix from $1,9502009-02-19 MEDIUM 6.8 CVE-2008-6169 Cross-site request forgery (CSRF) vulnerability in the Localization client 5.x before 5.x-1.1 and 6.x before 6.x-1.6 and the Localization server 5.x … Localization Client after 6.x-1.5 Fix from $1,6002009-02-19 MEDIUM 5.0 CVE-2008-6160 Semantically-Interconnected Online Communities (SIOC) 5.x before 5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, does not properly implement men… Semantically Interconnected Online Communities after 6.x_1.0 Fix from $1,6002009-02-18 HIGH 7.5 CVE-2008-6134 SQL injection vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified … Everyblog Mitigation only Fix from $1,9502009-02-14 HIGH 7.5 CVE-2008-6136 Unspecified vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to gain privileges as another user or an administrat… Everyblog No fix yet Fix from $1,9502009-02-14 HIGH 7.5 CVE-2008-6137 EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to bypass access restrictions via unknown vectors. Everyblog No fix yet Fix from $1,9502009-02-14 HIGH 7.5 CVE-2008-6020 SQL injection vulnerability in the Views module 6.x before 6.x-2.2 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecifi… Views after 6.x-2.1 Fix from $1,9502009-02-02 MEDIUM 6.0 CVE-2008-5998 Multiple SQL injection vulnerabilities in the ajax_checklist_save function in the Ajax Checklist module 5.x before 5.x-1.1 for Drupal allow remote au… Ajax Checklist Patch available Fix from $1,6002009-01-28 HIGH 7.5 CVE-2008-4793 The node module API in Drupal 5.x before 5.11 allows remote attackers to bypass node validation and have unspecified other impact via unknown vectors… Drupal after 5.10 Fix from $1,9502008-10-29 MEDIUM 6.0 CVE-2008-4789 The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restricti… Drupal after 6.4 Fix from $1,6002008-10-29 MEDIUM 6.0 CVE-2008-4790 The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restrictions and read "files attached to… Drupal after 5.10 Fix from $1,6002008-10-29 MEDIUM 6.0 CVE-2008-4791 The user module in Drupal 5.x before 5.11 and 6.x before 6.5 might allow remote authenticated users to bypass intended login access rules and success… Drupal 5.11 / 6.5+ Fix from $1,6002008-10-29 MEDIUM 6.0 CVE-2008-4792 The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form… Drupal 5.11 / 6.5+ Fix from $1,6002008-10-29 MEDIUM 6.0 CVE-2008-4633 SQL injection vulnerability in Node Vote 5.x before 5.x-1.1 and 6.x before 6.x-1.0, a module for Drupal, when "Allow user to vote again" is enabled, … Node Clone Mitigation only Fix from $1,6002008-10-21 HIGH 7.5 CVE-2008-4597 Shindig-Integrator 5.x, a module for Drupal, does not properly restrict generated page access, which allows remote attackers to gain privileges via u… Shindig Integrator Mitigation only Fix from $1,9502008-10-17