Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
drupal drupal 7.0 vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2014-9015
Drupal 6.x prior to 6.34 and 7.x prior to 7.34 allows remote malicious users to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.
Drupal Drupal
Debian Debian Linux 7.0
6.8
CVSSv2
CVE-2014-5267
modules/openid/xrds.inc in Drupal 6.x prior to 6.33 and 7.x prior to 7.31 allows remote malicious users to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document.
Drupal Drupal 7.6
Drupal Drupal 7.5
Drupal Drupal 7.26
Drupal Drupal 7.25
Drupal Drupal 7.19
Drupal Drupal 7.18
Drupal Drupal 7.10
Drupal Drupal 7.1
Drupal Drupal 7.0
Drupal Drupal 6.31
Drupal Drupal 6.30
Drupal Drupal 6.24
Drupal Drupal 6.23
Drupal Drupal 6.17
Drupal Drupal 6.16
Drupal Drupal 6.0
Drupal Drupal 7.4
Drupal Drupal 7.30
Drupal Drupal 7.24
Drupal Drupal 7.23
Drupal Drupal 7.17
Drupal Drupal 7.16
6.8
CVSSv2
CVE-2013-6386
Drupal 6.x prior to 6.29 and 7.x prior to 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote malicious users to predict security strings and bypass intended restrictions via a brute force attack.
Drupal Drupal 7.0
Drupal Drupal 7.11
Drupal Drupal 7.12
Drupal Drupal 7.19
Drupal Drupal 7.2
Drupal Drupal 7.x-dev
Drupal Drupal 7.23
Drupal Drupal 7.13
Drupal Drupal 7.14
Drupal Drupal 7.3
Drupal Drupal 7.4
Drupal Drupal 7.5
Drupal Drupal 7.22
Drupal Drupal 7.21
Drupal Drupal 7.15
Drupal Drupal 7.16
Drupal Drupal 7.6
Drupal Drupal 7.7
Drupal Drupal 7.20
Drupal Drupal 7.1
Drupal Drupal 7.10
Drupal Drupal 7.17
6.8
CVSSv2
CVE-2012-0825
Drupal 6.x prior to 6.23 and 7.x prior to 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote malicious users to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.
Drupal Drupal 7.9
Drupal Drupal 7.8
Drupal Drupal 7.7
Drupal Drupal 7.0
Drupal Drupal 6.0
Drupal Drupal 6.1
Drupal Drupal 6.16
Drupal Drupal 6.17
Drupal Drupal 7.4
Drupal Drupal 7.3
Drupal Drupal 6.12
Drupal Drupal 6.13
Drupal Drupal 6.2
Drupal Drupal 6.20
Drupal Drupal 7.6
Drupal Drupal 7.5
Drupal Drupal 6.10
Drupal Drupal 6.11
Drupal Drupal 6.18
Drupal Drupal 6.19
Drupal Drupal 7.x-dev
Drupal Drupal 7.10
6.8
CVSSv2
CVE-2012-0826
Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x prior to 6.23 and 7.x prior to 7.11 allows remote malicious users to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss...
Drupal Drupal 6.6
Drupal Drupal 6.7
Drupal Drupal 6.0
Drupal Drupal 6.11
Drupal Drupal 6.12
Drupal Drupal 6.2
Drupal Drupal 6.20
Drupal Drupal 6.3
Drupal Drupal 6.16
Drupal Drupal 6.17
Drupal Drupal 6.8
Drupal Drupal 6.9
Drupal Drupal 6.13
Drupal Drupal 6.14
Drupal Drupal 6.15
Drupal Drupal 6.21
Drupal Drupal 6.22
Drupal Drupal 6.4
Drupal Drupal 6.5
Drupal Drupal 6.1
Drupal Drupal 6.10
Drupal Drupal 6.18
6.8
CVSSv2
CVE-2012-4553
Drupal 7.x prior to 7.16 allows remote malicious users to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an external database server, related to "transient conditions."
Drupal Drupal 7.0
Drupal Drupal 7.6
Drupal Drupal 7.7
Drupal Drupal 7.8
Drupal Drupal 7.9
Drupal Drupal 7.14
Drupal Drupal 7.15
Drupal Drupal 7.1
Drupal Drupal 7.3
Drupal Drupal 7.5
Drupal Drupal 7.10
Drupal Drupal 7.12
Drupal Drupal 7.2
Drupal Drupal 7.4
Drupal Drupal 7.11
Drupal Drupal 7.13
6.8
CVSSv2
CVE-2007-6752
Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and previous versions allows remote malicious users to hijack the authentication of arbitrary users for requests that end a session via the user/logout URI. NOTE: the vendor disputes the significance of this issue, by...
Drupal Drupal 4.6.0
Drupal Drupal 4.6
Drupal Drupal 7.0
Drupal Drupal 5.10
Drupal Drupal 5.4
Drupal Drupal 4.6.5
Drupal Drupal 4.5.4
Drupal Drupal 6.0
Drupal Drupal 4.7.2
Drupal Drupal 4.6.10
Drupal Drupal 6.2
Drupal Drupal 5.17
Drupal Drupal 4.6.9
Drupal Drupal 5.13
Drupal Drupal 6.14
Drupal Drupal 6.24
Drupal Drupal 6.13
Drupal Drupal 4.5.0
Drupal Drupal 5.12
Drupal Drupal 6.18
Drupal Drupal 5.2
Drupal Drupal 7.3
1 EDB exploit
6.5
CVSSv2
CVE-2016-6211
The User module in Drupal 7.x prior to 7.44 allows remote authenticated users to gain privileges via vectors involving contributed or custom code that triggers a rebuild of the user profile form.
Drupal Drupal 7.0
Drupal Drupal 7.13
Drupal Drupal 7.14
Drupal Drupal 7.21
Drupal Drupal 7.22
Drupal Drupal 7.29
Drupal Drupal 7.3
Drupal Drupal 7.36
Drupal Drupal 7.37
Drupal Drupal 7.7
Drupal Drupal 7.8
Drupal Drupal 7.39
Drupal Drupal 7.15
Drupal Drupal 7.16
Drupal Drupal 7.23
Drupal Drupal 7.24
Drupal Drupal 7.30
Drupal Drupal 7.31
Drupal Drupal 7.38
Drupal Drupal 7.4
Drupal Drupal 7.9
Drupal Drupal 7.x-dev
6.5
CVSSv2
CVE-2016-3162
The File module in Drupal 7.x prior to 7.43 and 8.x prior to 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveraging permission to create content or comment and upload fil...
Drupal Drupal 8.0.3
Drupal Drupal 8.0.2
Drupal Drupal 8.0.1
Drupal Drupal 7.37
Drupal Drupal 7.36
Drupal Drupal 7.35
Drupal Drupal 7.34
Drupal Drupal 7.2
Drupal Drupal 7.19
Drupal Drupal 7.18
Drupal Drupal 7.17
Drupal Drupal 7.0
Drupal Drupal 7.x-dev
Drupal Drupal 7.9
Drupal Drupal 7.8
Drupal Drupal 7.7
Drupal Drupal 7.28
Drupal Drupal 7.27
Drupal Drupal 7.26
Drupal Drupal 7.25
Drupal Drupal 7.12
Drupal Drupal 7.11
6.4
CVSSv2
CVE-2016-3167
Open redirect vulnerability in the drupal_goto function in Drupal 6.x prior to 6.38, when used with PHP prior to 5.4.7, allows remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in the "destination" para...
Drupal Drupal 6.36
Drupal Drupal 6.35
Drupal Drupal 6.34
Drupal Drupal 6.33
Drupal Drupal 6.20
Drupal Drupal 6.2
Drupal Drupal 6.19
Drupal Drupal 6.18
Drupal Drupal 6.0
Drupal Drupal 6.6
Drupal Drupal 6.4
Drupal Drupal 6.32
Drupal Drupal 6.30
Drupal Drupal 6.29
Drupal Drupal 6.24
Drupal Drupal 6.22
Drupal Drupal 6.16
Drupal Drupal 6.14
Drupal Drupal 6.37
Drupal Drupal 6.9
Drupal Drupal 6.8
Drupal Drupal 6.28
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-40673
CVE-2024-36674
CVE-2024-27348
unspecified
CVE-2024-24919
CVE-2024-4870
malicious code
CVE-2024-2019
hard-coded
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »