Записи Drupal
863 опубликованных записей вендора drupal.
Профиль для исследователя
- Попали в KEV
- 8 · 0,9 %
- С эксплойтом
- 13 · 1,5 %
- Pre-auth RCE
- 60
- С записью об исправлении
- 24,6 %
- Медиана: публикация → KEV
- 886 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')360
- CWE-264 Permissions, Privileges, and Access Controls130
- CWE-352 Cross-Site Request Forgery (CSRF)67
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')33
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor30
- CWE-20 Improper Input Validation29
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
863 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2018-7600Готовый эксплойт | Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because odrupal · drupal · CWE-20 | Критическая9,8 | KEV | 100,0 % | 29 мар. 2018 г. |
99Срочно | CVE-2018-7602Готовый эксплойт | Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004drupal · drupal · CWE-94 | Критическая9,8 | KEV | 99,2 % | 19 июл. 2018 г. |
90Срочно | CVE-2019-6340Готовый эксплойт | Drupal core - Highly critical - Remote Code Executiondrupal · drupal · CWE-502 | Высокая8,1 | KEV | 92,0 % | 21 февр. 2019 г. |
86Срочно | CVE-2020-28949Готовый эксплойт | Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as filphp · archive tar | Высокая7,8 | KEV | 84,6 % | 19 нояб. 2020 г. |
81Срочно | CVE-2020-36193Готовый эксплойт | Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a relatphp · archive tar · CWE-22 | Высокая7,5 | KEV | 70,6 % | 18 янв. 2021 г. |
79На этой неделе | CVE-2020-11023Готовый эксплойт | Potential XSS vulnerability in jQueryjquery · jquery · CWE-79 | Средняя6,1 | KEV | 84,9 % | 29 апр. 2020 г. |
76На этой неделе | CVE-2020-13671Готовый эксплойт | Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extendrupal · drupal · CWE-434 | Высокая8,8 | KEV | 35,4 % | 20 нояб. 2020 г. |
74На этой неделе | CVE-2026-9082Готовый эксплойт | Drupal core - Highly critical - SQL injection - SA-CORE-2026-004drupal · drupal · CWE-89 | Критическая9,8 | KEV | 15,7 % | 20 мая 2026 г. |
60На этой неделе | CVE-2014-3704Готовый эксплойт | The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements,drupal · drupal · CWE-89 | Высокая7,5 | — | 100,0 % | 15 окт. 2014 г. |
54В плане | CVE-2020-11022Proof of concept | jQuery has a potential XSS vulnerabilityjquery · jquery · CWE-79 | Средняя6,1 | — | 99,2 % | 29 апр. 2020 г. |
54В плане | CVE-2005-1921Готовый эксплойт | Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1php · xml rpc · CWE-94 | Высокая7,5 | — | 79,1 % | 5 июл. 2005 г. |
50В плане | CVE-2019-11358Proof of concept | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototypjquery · jquery · CWE-1321 | Средняя6,1 | — | 87,2 % | 19 апр. 2019 г. |
50В плане | CVE-2019-6339Proof of concept | PHAR stream wrapper Arbitrary PHP code executiondrupal · drupal · CWE-20 | Критическая9,8 | — | 35,6 % | 22 янв. 2019 г. |
47В плане | CVE-2018-9205Proof of concept | Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.drupal · avatar uploader · CWE-22 | Высокая7,5 | — | 55,1 % | 4 апр. 2018 г. |
47В плане | CVE-2016-5385Эксплойта нет | PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from thp · storeever msl6480 tape library firmware · CWE-601 | Высокая8,1 | — | 50,4 % | 18 июл. 2016 г. |
45В плане | CVE-2014-9016Готовый эксплойт | The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allodrupal · drupal | Средняя5,0 | — | 82,2 % | 24 нояб. 2014 г. |
45В плане | CVE-2020-28948Proof of concept | Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.php · archive tar · CWE-502 | Высокая7,8 | — | 47,5 % | 19 нояб. 2020 г. |
45В плане | CVE-2017-6920Эксплойта нет | Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects sdrupal · drupal · CWE-19 | Критическая9,8 | — | 20,5 % | 6 авг. 2018 г. |
43В плане | CVE-2018-14773Эксплойта нет | An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13sensiolabs · symfony | Средняя6,5 | — | 58,1 % | 3 авг. 2018 г. |
41В плане | CVE-2019-10910Эксплойта нет | In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user inpsensiolabs · symfony · CWE-89 | Критическая9,8 | — | 6,0 % | 16 мая 2019 г. |
41В плане | CVE-2019-11831Эксплойта нет | The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversaltypo3 · pharstreamwrapper · CWE-22 | Критическая9,8 | — | 5,4 % | 9 мая 2019 г. |
41В плане | CVE-2008-0568Эксплойта нет | Unspecified vulnerability in the IP-authentication feature in the Secure Site 5.x-1.0 and 4.7.x-1.0 module for Drupal allows remote attackerdrupal · secure site module | Критическая10,0 | — | 2,4 % | 4 февр. 2008 г. |
41В плане | CVE-2008-0823Эксплойта нет | Unspecified vulnerability in the Header Image Module before 5.x-1.1 for Drupal allows remote attackers to access the administration pages vidrupal · header image · CWE-287 | Критическая10,0 | — | 2,2 % | 19 февр. 2008 г. |
41В плане | CVE-2013-0318Эксплойта нет | The admin page in the Banckle Chat module for Drupal does not properly restrict access, which allows remote attackers to bypass intended resdrupal · drupal · CWE-264 | Критическая10,0 | — | 2,0 % | 27 мар. 2013 г. |
41В плане | CVE-2009-3352Эксплойта нет | Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.drupal · drupal | Критическая10,0 | — | 2,0 % | 24 сент. 2009 г. |
- CVE-2018-760099Срочно
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because o
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %drupal · drupal29 мар. 2018 г.
- CVE-2018-760299Срочно
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %drupal · drupal19 июл. 2018 г.
- CVE-2019-634090Срочно
Drupal core - Highly critical - Remote Code Execution
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 92 %drupal · drupal21 февр. 2019 г.
- CVE-2020-2894986Срочно
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as fil
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 85 %php · archive tar19 нояб. 2020 г.
- CVE-2020-3619381Срочно
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a relat
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 71 %php · archive tar18 янв. 2021 г.
- CVE-2020-1102379На этой неделе
Potential XSS vulnerability in jQuery
СредняяCVSS 6,1KEVГотовый эксплойтEPSS 85 %jquery · jquery29 апр. 2020 г.
- CVE-2020-1367176На этой неделе
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect exten
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 35 %drupal · drupal20 нояб. 2020 г.
- CVE-2026-908274На этой неделе
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 16 %drupal · drupal20 мая 2026 г.
- CVE-2014-370460На этой неделе
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements,
ВысокаяCVSS 7,5Готовый эксплойтEPSS 100 %drupal · drupal15 окт. 2014 г.
- CVE-2020-1102254В плане
jQuery has a potential XSS vulnerability
СредняяCVSS 6,1Proof of conceptEPSS 99 %jquery · jquery29 апр. 2020 г.
- CVE-2005-192154В плане
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1
ВысокаяCVSS 7,5Готовый эксплойтEPSS 79 %php · xml rpc5 июл. 2005 г.
- CVE-2019-1135850В плане
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototyp
СредняяCVSS 6,1Proof of conceptEPSS 87 %jquery · jquery19 апр. 2019 г.
- CVE-2019-633950В плане
PHAR stream wrapper Arbitrary PHP code execution
КритическаяCVSS 9,8Proof of conceptEPSS 36 %drupal · drupal22 янв. 2019 г.
- CVE-2018-920547В плане
Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.
ВысокаяCVSS 7,5Proof of conceptEPSS 55 %drupal · avatar uploader4 апр. 2018 г.
- CVE-2016-538547В плане
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from t
ВысокаяCVSS 8,1Эксплойта нетEPSS 50 %hp · storeever msl6480 tape library firmware18 июл. 2016 г.
- CVE-2014-901645В плане
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allo
СредняяCVSS 5,0Готовый эксплойтEPSS 82 %drupal · drupal24 нояб. 2014 г.
- CVE-2020-2894845В плане
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
ВысокаяCVSS 7,8Proof of conceptEPSS 47 %php · archive tar19 нояб. 2020 г.
- CVE-2017-692045В плане
Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects s
КритическаяCVSS 9,8Эксплойта нетEPSS 20 %drupal · drupal6 авг. 2018 г.
- CVE-2018-1477343В плане
An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13
СредняяCVSS 6,5Эксплойта нетEPSS 58 %sensiolabs · symfony3 авг. 2018 г.
- CVE-2019-1091041В плане
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user inp
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %sensiolabs · symfony16 мая 2019 г.
- CVE-2019-1183141В плане
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %typo3 · pharstreamwrapper9 мая 2019 г.
- CVE-2008-056841В плане
Unspecified vulnerability in the IP-authentication feature in the Secure Site 5.x-1.0 and 4.7.x-1.0 module for Drupal allows remote attacker
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %drupal · secure site module4 февр. 2008 г.
- CVE-2008-082341В плане
Unspecified vulnerability in the Header Image Module before 5.x-1.1 for Drupal allows remote attackers to access the administration pages vi
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %drupal · header image19 февр. 2008 г.
- CVE-2013-031841В плане
The admin page in the Banckle Chat module for Drupal does not properly restrict access, which allows remote attackers to bypass intended res
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %drupal · drupal27 мар. 2013 г.
- CVE-2009-335241В плане
Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %drupal · drupal24 сент. 2009 г.