Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
drupal drupal 7.0 vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2010-5312
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI prior to 1.10.0 allows remote malicious users to inject arbitrary web script or HTML via the title option.
Debian Debian Linux 7.0
Jqueryui Jquery Ui
Fedoraproject Fedora 35
Fedoraproject Fedora 36
Netapp Snapcenter -
Apache Drill 1.16.0
Drupal Drupal
Debian Debian Linux 9.0
1 Github repository
3.5
CVSSv2
CVE-2009-3652
Cross-site scripting (XSS) vulnerability in Organic Groups (OG) 5.x-7.x prior to 5.x-7.4, 5.x-8.x prior to 5.x-8.1, and 6.x-1.x prior to 6.x-1.4, a module for Drupal, allows remote authenticated users, with create or edit group nodes permissions, to inject arbitrary web script or...
Moshe Weitzman Organic Groups 5.x-7.0-rc2
Moshe Weitzman Organic Groups 5.x-7.0-rc1
Moshe Weitzman Organic Groups 6.x-1.0
Moshe Weitzman Organic Groups 6.x-1.0-rc9
Moshe Weitzman Organic Groups 6.x-1.0-rc8
Moshe Weitzman Organic Groups 6.x-1.0-rc1
Moshe Weitzman Organic Groups 6.x-1.0-beta1
Moshe Weitzman Organic Groups 5.x-7.0
Moshe Weitzman Organic Groups 5.x-7.0-rc5
Moshe Weitzman Organic Groups 5.x-7.2
Moshe Weitzman Organic Groups 6.x-1.3
Moshe Weitzman Organic Groups 6.x-1.0-rc5
Moshe Weitzman Organic Groups 6.x-1.0-rc4
Moshe Weitzman Organic Groups 5.x-7.0-rc4
Moshe Weitzman Organic Groups 5.x-7.0-rc3
Moshe Weitzman Organic Groups 6.x-1.2
Moshe Weitzman Organic Groups 6.x-1.1
Moshe Weitzman Organic Groups 6.x-1.0-rc3
Moshe Weitzman Organic Groups 6.x-1.0-rc2
Moshe Weitzman Organic Groups 5.x-7.1
Moshe Weitzman Organic Groups 5.x-7.3
Moshe Weitzman Organic Groups 5.x-8.0
4.3
CVSSv2
CVE-2008-3094
The Organic Groups (OG) module 5.x prior to 5.x-7.3 and 6.x prior to 6.x-1.0-RC1, a module for Drupal, allows remote malicious users to obtain sensitive information (private group names) via unspecified vectors.
Organic Groups Project Organic Groups 5.x-5.x-7.2
Organic Groups Project Organic Groups 5.x-7.0
Organic Groups Project Organic Groups 5.x-7.1
Organic Groups Project Organic Groups 6.x-1.0
Organic Groups Project Organic Groups 6.x-1.x
4.3
CVSSv2
CVE-2020-11023
In jQuery versions greater than or equal to 1.0.3 and prior to 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted c...
Jquery Jquery
Debian Debian Linux 9.0
Fedoraproject Fedora 31
Fedoraproject Fedora 32
Fedoraproject Fedora 33
Drupal Drupal
Oracle Weblogic Server 12.1.3.0.0
Oracle Hyperion Financial Reporting 11.1.2.4
Oracle Weblogic Server 12.2.1.3.0
Oracle Webcenter Sites 12.2.1.3.0
Oracle Application Testing Suite 13.3.0.1
Oracle Communications Operations Monitor 3.4
Oracle Weblogic Server 12.2.1.4.0
Oracle Webcenter Sites 12.2.1.4.0
Oracle Weblogic Server 14.1.1.0.0
Oracle Communications Interactive Session Recorder
Oracle Communications Element Manager 8.2.0
Oracle Communications Element Manager 8.2.1
Oracle Communications Element Manager 8.1.1
Oracle Application Express
Oracle Rest Data Services 12.2.0.1
Oracle Rest Data Services 12.1.0.2
13 Github repositories
4.3
CVSSv2
CVE-2009-2078
Multiple cross-site scripting (XSS) vulnerabilities in Booktree 5.x prior to 5.x-7.3 and 6.x prior to 6.x-1.1, a module for Drupal, allow remote malicious users to inject arbitrary web script or HTML via the (1) node title and (2) node body in a tree root page.
Heine.familiedeelstra Booktree 6.x-1.x
Heine.familiedeelstra Booktree 6.x-1.0
Heine.familiedeelstra Booktree 5.x-1.9
Heine.familiedeelstra Booktree 5.x-1.3
Heine.familiedeelstra Booktree 5.x-1.1
Heine.familiedeelstra Booktree 5.x-1.x
Heine.familiedeelstra Booktree 5.x-7.2
Heine.familiedeelstra Booktree 5.x-7.1
Heine.familiedeelstra Booktree 5.x-7.0
Heine.familiedeelstra Booktree 5.x-1.4
Heine.familiedeelstra Booktree 5.x-1.2
4.3
CVSSv2
CVE-2020-11022
In jQuery versions greater than or equal to 1.2 and prior to 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuer...
Jquery Jquery
Drupal Drupal
Debian Debian Linux 9.0
Fedoraproject Fedora 31
Fedoraproject Fedora 32
Fedoraproject Fedora 33
Oracle Weblogic Server 12.1.3.0.0
Oracle Jdeveloper 11.1.1.9.0
Oracle Retail Back Office 14.1
Oracle Retail Back Office 14.0
Oracle Peoplesoft Enterprise Peopletools 8.56
Oracle Weblogic Server 10.3.6.0.0
Oracle Communications Webrtc Session Controller 7.2
Oracle Weblogic Server 12.2.1.3.0
Oracle Agile Product Lifecycle Management For Process 6.2.0.0
Oracle Peoplesoft Enterprise Peopletools 8.57
Oracle Application Testing Suite 13.3.0.1
Oracle Retail Returns Management 14.0
Oracle Retail Returns Management 14.1
Oracle Jdeveloper 12.2.1.3.0
Oracle Policy Automation Connector For Siebel 10.4.6
Oracle Financial Services Market Risk Measurement And Management 8.0.6
13 Github repositories
4.3
CVSSv2
CVE-2019-11358
jQuery prior to 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
Jquery Jquery
Debian Debian Linux 8.0
Debian Debian Linux 9.0
Debian Debian Linux 10.0
Drupal Drupal
Backdropcms Backdrop
Fedoraproject Fedora 28
Fedoraproject Fedora 29
Fedoraproject Fedora 30
Opensuse Leap 15.1
Opensuse Backports Sle 15.0
Netapp Snapcenter -
Netapp Oncommand System Manager
Redhat Cloudforms 4.7
Redhat Virtualization Manager 4.3
Oracle Service Bus 12.1.3.0.0
Oracle Primavera Unifier 16.2
Oracle Jd Edwards Enterpriseone Tools 9.2
Oracle Weblogic Server 12.1.3.0.0
Oracle Service Bus 11.1.1.9.0
Oracle Jdeveloper 11.1.1.9.0
Oracle Primavera Unifier 16.1
150 Github repositories
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8