drupal kayıtları
drupal üreticisine ait 863 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 8 · %0,9
- Silahlaştırılmış
- 13 · %1,5
- Pre-auth RCE
- 60
- Düzeltme kaydı olan
- %24,6
- Yayından KEV’e ortanca
- 886 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')360
- CWE-264 Permissions, Privileges, and Access Controls130
- CWE-352 Cross-Site Request Forgery (CSRF)67
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')33
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor30
- CWE-20 Improper Input Validation29
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
863 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2018-7600Silahlaştırılmış | Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because odrupal · drupal · CWE-20 | Kritik9,8 | KEV | %100,0 | 29 Mar 2018 |
99Hemen | CVE-2018-7602Silahlaştırılmış | Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004drupal · drupal · CWE-94 | Kritik9,8 | KEV | %99,2 | 19 Tem 2018 |
90Hemen | CVE-2019-6340Silahlaştırılmış | Drupal core - Highly critical - Remote Code Executiondrupal · drupal · CWE-502 | Yüksek8,1 | KEV | %92,0 | 21 Şub 2019 |
86Hemen | CVE-2020-28949Silahlaştırılmış | Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as filphp · archive tar | Yüksek7,8 | KEV | %84,6 | 19 Kas 2020 |
81Hemen | CVE-2020-36193Silahlaştırılmış | Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a relatphp · archive tar · CWE-22 | Yüksek7,5 | KEV | %70,6 | 18 Oca 2021 |
79Bu hafta | CVE-2020-11023Silahlaştırılmış | Potential XSS vulnerability in jQueryjquery · jquery · CWE-79 | Orta6,1 | KEV | %84,9 | 29 Nis 2020 |
76Bu hafta | CVE-2020-13671Silahlaştırılmış | Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extendrupal · drupal · CWE-434 | Yüksek8,8 | KEV | %35,4 | 20 Kas 2020 |
74Bu hafta | CVE-2026-9082Silahlaştırılmış | Drupal core - Highly critical - SQL injection - SA-CORE-2026-004drupal · drupal · CWE-89 | Kritik9,8 | KEV | %15,7 | 20 May 2026 |
60Bu hafta | CVE-2014-3704Silahlaştırılmış | The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements,drupal · drupal · CWE-89 | Yüksek7,5 | — | %100,0 | 15 Eki 2014 |
54Planlayın | CVE-2020-11022Kavram kanıtı | jQuery has a potential XSS vulnerabilityjquery · jquery · CWE-79 | Orta6,1 | — | %99,2 | 29 Nis 2020 |
54Planlayın | CVE-2005-1921Silahlaştırılmış | Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1php · xml rpc · CWE-94 | Yüksek7,5 | — | %79,1 | 5 Tem 2005 |
50Planlayın | CVE-2019-11358Kavram kanıtı | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototypjquery · jquery · CWE-1321 | Orta6,1 | — | %87,2 | 19 Nis 2019 |
50Planlayın | CVE-2019-6339Kavram kanıtı | PHAR stream wrapper Arbitrary PHP code executiondrupal · drupal · CWE-20 | Kritik9,8 | — | %35,6 | 22 Oca 2019 |
47Planlayın | CVE-2018-9205Kavram kanıtı | Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.drupal · avatar uploader · CWE-22 | Yüksek7,5 | — | %55,1 | 4 Nis 2018 |
47Planlayın | CVE-2016-5385İstismar yok | PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from thp · storeever msl6480 tape library firmware · CWE-601 | Yüksek8,1 | — | %50,4 | 18 Tem 2016 |
45Planlayın | CVE-2014-9016Silahlaştırılmış | The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allodrupal · drupal | Orta5,0 | — | %82,2 | 24 Kas 2014 |
45Planlayın | CVE-2020-28948Kavram kanıtı | Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.php · archive tar · CWE-502 | Yüksek7,8 | — | %47,5 | 19 Kas 2020 |
45Planlayın | CVE-2017-6920İstismar yok | Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects sdrupal · drupal · CWE-19 | Kritik9,8 | — | %20,5 | 6 Ağu 2018 |
43Planlayın | CVE-2018-14773İstismar yok | An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13sensiolabs · symfony | Orta6,5 | — | %58,1 | 3 Ağu 2018 |
41Planlayın | CVE-2019-10910İstismar yok | In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user inpsensiolabs · symfony · CWE-89 | Kritik9,8 | — | %6,0 | 16 May 2019 |
41Planlayın | CVE-2019-11831İstismar yok | The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversaltypo3 · pharstreamwrapper · CWE-22 | Kritik9,8 | — | %5,4 | 9 May 2019 |
41Planlayın | CVE-2008-0568İstismar yok | Unspecified vulnerability in the IP-authentication feature in the Secure Site 5.x-1.0 and 4.7.x-1.0 module for Drupal allows remote attackerdrupal · secure site module | Kritik10,0 | — | %2,4 | 4 Şub 2008 |
41Planlayın | CVE-2008-0823İstismar yok | Unspecified vulnerability in the Header Image Module before 5.x-1.1 for Drupal allows remote attackers to access the administration pages vidrupal · header image · CWE-287 | Kritik10,0 | — | %2,2 | 19 Şub 2008 |
41Planlayın | CVE-2013-0318İstismar yok | The admin page in the Banckle Chat module for Drupal does not properly restrict access, which allows remote attackers to bypass intended resdrupal · drupal · CWE-264 | Kritik10,0 | — | %2,0 | 27 Mar 2013 |
41Planlayın | CVE-2009-3352İstismar yok | Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.drupal · drupal | Kritik10,0 | — | %2,0 | 24 Eyl 2009 |
- CVE-2018-760099Hemen
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because o
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100drupal · drupal29 Mar 2018
- CVE-2018-760299Hemen
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99drupal · drupal19 Tem 2018
- CVE-2019-634090Hemen
Drupal core - Highly critical - Remote Code Execution
YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %92drupal · drupal21 Şub 2019
- CVE-2020-2894986Hemen
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as fil
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %85php · archive tar19 Kas 2020
- CVE-2020-3619381Hemen
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a relat
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %71php · archive tar18 Oca 2021
- CVE-2020-1102379Bu hafta
Potential XSS vulnerability in jQuery
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %85jquery · jquery29 Nis 2020
- CVE-2020-1367176Bu hafta
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect exten
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %35drupal · drupal20 Kas 2020
- CVE-2026-908274Bu hafta
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %16drupal · drupal20 May 2026
- CVE-2014-370460Bu hafta
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements,
YüksekCVSS 7,5SilahlaştırılmışEPSS %100drupal · drupal15 Eki 2014
- CVE-2020-1102254Planlayın
jQuery has a potential XSS vulnerability
OrtaCVSS 6,1Kavram kanıtıEPSS %99jquery · jquery29 Nis 2020
- CVE-2005-192154Planlayın
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1
YüksekCVSS 7,5SilahlaştırılmışEPSS %79php · xml rpc5 Tem 2005
- CVE-2019-1135850Planlayın
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototyp
OrtaCVSS 6,1Kavram kanıtıEPSS %87jquery · jquery19 Nis 2019
- CVE-2019-633950Planlayın
PHAR stream wrapper Arbitrary PHP code execution
KritikCVSS 9,8Kavram kanıtıEPSS %36drupal · drupal22 Oca 2019
- CVE-2018-920547Planlayın
Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.
YüksekCVSS 7,5Kavram kanıtıEPSS %55drupal · avatar uploader4 Nis 2018
- CVE-2016-538547Planlayın
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from t
YüksekCVSS 8,1İstismar yokEPSS %50hp · storeever msl6480 tape library firmware18 Tem 2016
- CVE-2014-901645Planlayın
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allo
OrtaCVSS 5,0SilahlaştırılmışEPSS %82drupal · drupal24 Kas 2014
- CVE-2020-2894845Planlayın
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
YüksekCVSS 7,8Kavram kanıtıEPSS %47php · archive tar19 Kas 2020
- CVE-2017-692045Planlayın
Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects s
KritikCVSS 9,8İstismar yokEPSS %20drupal · drupal6 Ağu 2018
- CVE-2018-1477343Planlayın
An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13
OrtaCVSS 6,5İstismar yokEPSS %58sensiolabs · symfony3 Ağu 2018
- CVE-2019-1091041Planlayın
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user inp
KritikCVSS 9,8İstismar yokEPSS %6sensiolabs · symfony16 May 2019
- CVE-2019-1183141Planlayın
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal
KritikCVSS 9,8İstismar yokEPSS %5typo3 · pharstreamwrapper9 May 2019
- CVE-2008-056841Planlayın
Unspecified vulnerability in the IP-authentication feature in the Secure Site 5.x-1.0 and 4.7.x-1.0 module for Drupal allows remote attacker
KritikCVSS 10,0İstismar yokEPSS %2drupal · secure site module4 Şub 2008
- CVE-2008-082341Planlayın
Unspecified vulnerability in the Header Image Module before 5.x-1.1 for Drupal allows remote attackers to access the administration pages vi
KritikCVSS 10,0İstismar yokEPSS %2drupal · header image19 Şub 2008
- CVE-2013-031841Planlayın
The admin page in the Banckle Chat module for Drupal does not properly restrict access, which allows remote attackers to bypass intended res
KritikCVSS 10,0İstismar yokEPSS %2drupal · drupal27 Mar 2013
- CVE-2009-335241Planlayın
Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.
KritikCVSS 10,0İstismar yokEPSS %2drupal · drupal24 Eyl 2009