İçeriğe atla
Noroxi

drupal kayıtları

drupal üreticisine ait 863 yayımlanmış kayıt.

Tüm kayıtlar

863 kayıt
  • Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because o

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    drupal · drupal29 Mar 2018

  • Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    drupal · drupal19 Tem 2018

  • Drupal core - Highly critical - Remote Code Execution

    YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %92

    drupal · drupal21 Şub 2019

  • Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as fil

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %85

    php · archive tar19 Kas 2020

  • Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a relat

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %71

    php · archive tar18 Oca 2021

  • CVE-2020-11023
    79Bu hafta

    Potential XSS vulnerability in jQuery

    OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %85

    jquery · jquery29 Nis 2020

  • CVE-2020-13671
    76Bu hafta

    Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect exten

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %35

    drupal · drupal20 Kas 2020

  • CVE-2026-9082
    74Bu hafta

    Drupal core - Highly critical - SQL injection - SA-CORE-2026-004

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %16

    drupal · drupal20 May 2026

  • CVE-2014-3704
    60Bu hafta

    The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements,

    YüksekCVSS 7,5SilahlaştırılmışEPSS %100

    drupal · drupal15 Eki 2014

  • CVE-2020-11022
    54Planlayın

    jQuery has a potential XSS vulnerability

    OrtaCVSS 6,1Kavram kanıtıEPSS %99

    jquery · jquery29 Nis 2020

  • CVE-2005-1921
    54Planlayın

    Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1

    YüksekCVSS 7,5SilahlaştırılmışEPSS %79

    php · xml rpc5 Tem 2005

  • CVE-2019-11358
    50Planlayın

    jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototyp

    OrtaCVSS 6,1Kavram kanıtıEPSS %87

    jquery · jquery19 Nis 2019

  • CVE-2019-6339
    50Planlayın

    PHAR stream wrapper Arbitrary PHP code execution

    KritikCVSS 9,8Kavram kanıtıEPSS %36

    drupal · drupal22 Oca 2019

  • CVE-2018-9205
    47Planlayın

    Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.

    YüksekCVSS 7,5Kavram kanıtıEPSS %55

    drupal · avatar uploader4 Nis 2018

  • CVE-2016-5385
    47Planlayın

    PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from t

    YüksekCVSS 8,1İstismar yokEPSS %50

    hp · storeever msl6480 tape library firmware18 Tem 2016

  • CVE-2014-9016
    45Planlayın

    The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allo

    OrtaCVSS 5,0SilahlaştırılmışEPSS %82

    drupal · drupal24 Kas 2014

  • CVE-2020-28948
    45Planlayın

    Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

    YüksekCVSS 7,8Kavram kanıtıEPSS %47

    php · archive tar19 Kas 2020

  • CVE-2017-6920
    45Planlayın

    Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects s

    KritikCVSS 9,8İstismar yokEPSS %20

    drupal · drupal6 Ağu 2018

  • CVE-2018-14773
    43Planlayın

    An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13

    OrtaCVSS 6,5İstismar yokEPSS %58

    sensiolabs · symfony3 Ağu 2018

  • CVE-2019-10910
    41Planlayın

    In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user inp

    KritikCVSS 9,8İstismar yokEPSS %6

    sensiolabs · symfony16 May 2019

  • CVE-2019-11831
    41Planlayın

    The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal

    KritikCVSS 9,8İstismar yokEPSS %5

    typo3 · pharstreamwrapper9 May 2019

  • CVE-2008-0568
    41Planlayın

    Unspecified vulnerability in the IP-authentication feature in the Secure Site 5.x-1.0 and 4.7.x-1.0 module for Drupal allows remote attacker

    KritikCVSS 10,0İstismar yokEPSS %2

    drupal · secure site module4 Şub 2008

  • CVE-2008-0823
    41Planlayın

    Unspecified vulnerability in the Header Image Module before 5.x-1.1 for Drupal allows remote attackers to access the administration pages vi

    KritikCVSS 10,0İstismar yokEPSS %2

    drupal · header image19 Şub 2008

  • CVE-2013-0318
    41Planlayın

    The admin page in the Banckle Chat module for Drupal does not properly restrict access, which allows remote attackers to bypass intended res

    KritikCVSS 10,0İstismar yokEPSS %2

    drupal · drupal27 Mar 2013

  • CVE-2009-3352
    41Planlayın

    Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.

    KritikCVSS 10,0İstismar yokEPSS %2

    drupal · drupal24 Eyl 2009