Search Results (1029 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-7602 2 Debian, Drupal 2 Debian Linux, Drupal 2026-10-01 8.1 High
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.
CVE-2026-81158 2 Drupal, Entity Api Project 2 Entity Api, Entity Api 2026-10-01 5.3 Medium
Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0.
CVE-2026-81160 2 Drupal, Slick Carousel Project 2 Slick Carousel, Slick Carousel 2026-10-01 6.1 Medium
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Slick Carousel allows Stored XSS. This issue affects Slick Carousel versions: from 0.0.0 to 2.1.0.
CVE-2026-15917 1 Drupal 1 Drupal Core 2026-09-28 4.7 Medium
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.2.*.
CVE-2026-81161 2 Content Moderation Notifications Project, Drupal 2 Content Moderation Notifications, Content Moderation Notifications 2026-09-24 3.3 Low
Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0.
CVE-2026-76757 1 Drupal 1 Gammu Sms Daemon 2026-09-19 5.9 Medium
Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
CVE-2026-76756 1 Drupal 1 Gammu Sms Daemon 2026-09-19 5.9 Medium
Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
CVE-2026-76755 1 Drupal 1 Gammu Sms Daemon 2026-09-19 5.9 Medium
Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
CVE-2026-81159 2 Centarro, Drupal 2 Commerce Cybersource, Commerce Cybersource 2026-09-16 3.7 Low
Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0.
CVE-2026-81165 2 Blazy Project, Drupal 2 Blazy, Blazy 2026-09-16 5.3 Medium
Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18.
CVE-2026-81166 2 Drupal, Lakedrops 2 Digital Signage Framework, Digital Signage Framework 2026-09-16 5.3 Medium
Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1.
CVE-2026-73478 2 Diff Project, Drupal 2 Diff, Diff 2026-09-16 5.3 Medium
Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1.
CVE-2026-81205 2 Drupal, Miniorange 2 Ldap / Active Directory Integration, Ldap \/ Active Directory Integration 2026-09-16 5.3 Medium
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1.
CVE-2026-73477 2 Drupal, Quick Tabs Project 2 Quick Tabs, Quick Tabs 2026-09-16 5.3 Medium
Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versions: from 0.0.0 to 4.3.1.
CVE-2026-81201 2 Drupal, Monster Menus Project 2 Monster Menus, Monster Menus 2026-09-16 6.1 Medium
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Monster Menus allows Stored XSS. This issue affects Monster Menus versions: from 0.0.0 to 9.5.3.
CVE-2026-73476 2 Drupal, External Authentication Project 2 External Authentication, External Authentication 2026-09-15 5.4 Medium
Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13.
CVE-2026-81168 2 Captcha Protected Page Project, Drupal 2 Captcha Protected Page, Captcha Protected Page 2026-09-09 3.7 Low
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.
CVE-2026-81167 2 Address Suggestion Project, Drupal 2 Address Suggestion, Address Suggestion 2026-09-09 4.8 Medium
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site Scripting (XSS). This issue affects Address Suggestion versions: from 0.0.0 to 1.0.25.
CVE-2026-81162 2 Drupal, Dxpr Builder Project 2 Dxpr Builder: The Best Editing (ai) Experience For Drupal, Dxpr Builder 2026-09-09 5.3 Medium
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1.
CVE-2026-81269 2 Data Field Project, Drupal 2 Data Field, Data Field 2026-09-09 5.3 Medium
Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13.