Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
drupal drupal 7.4 vulnerabilities and exploits
(subscribe to this query)
445
VMScore
CVE-2020-36193
Tar.php in Archive_Tar up to and including 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.
Php Archive Tar
Fedoraproject Fedora 32
Fedoraproject Fedora 33
Fedoraproject Fedora 34
Fedoraproject Fedora 35
Debian Debian Linux 9.0
Debian Debian Linux 10.0
Drupal Drupal
606
VMScore
CVE-2020-28948
Archive_Tar up to and including 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
Php Archive Tar
Debian Debian Linux 9.0
Debian Debian Linux 10.0
Fedoraproject Fedora 32
Fedoraproject Fedora 33
Fedoraproject Fedora 34
Fedoraproject Fedora 35
Drupal Drupal
3 Github repositories
606
VMScore
CVE-2020-28949
Archive_Tar up to and including 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
Php Archive Tar
Debian Debian Linux 9.0
Debian Debian Linux 10.0
Fedoraproject Fedora 32
Fedoraproject Fedora 33
Fedoraproject Fedora 34
Fedoraproject Fedora 35
Drupal Drupal
3 Github repositories
516
VMScore
CVE-2015-7943
Open redirect vulnerability in the Overlay module in Drupal 7.x prior to 7.41, the jQuery Update module 7.x-2.x prior to 7.x-2.7 for Drupal, and the LABjs module 7.x-1.x prior to 7.x-1.8 allows remote malicious users to redirect users to arbitrary web sites and conduct phishing a...
Labjs Project Labjs 7.x-1.0
Jquery Update Project Jquery Update 7.x-2.3
Jquery Update Project Jquery Update 7.x-2.4
Jquery Update Project Jquery Update 7.x-2.5
Jquery Update Project Jquery Update 7.x-2.6
Drupal Drupal 7.0
Drupal Drupal 7.1
Drupal Drupal 7.15
Drupal Drupal 7.16
Drupal Drupal 7.17
Drupal Drupal 7.18
Drupal Drupal 7.31
Labjs Project Labjs 7.x-1.2
Labjs Project Labjs 7.x-1.7
Jquery Update Project Jquery Update 7.x-2.1
Drupal Drupal 7.2
Drupal Drupal 7.4
Drupal Drupal 7.11
Drupal Drupal 7.13
Drupal Drupal 7.20
Drupal Drupal 7.22
Drupal Drupal 7.27
516
VMScore
CVE-2015-2749
Open redirect vulnerability in Drupal 6.x prior to 6.35 and 7.x prior to 7.35 allows remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.
Drupal Drupal 7.9
Drupal Drupal 7.10
Drupal Drupal 7.11
Drupal Drupal 7.12
Drupal Drupal 7.25
Drupal Drupal 7.27
Drupal Drupal 7.28
Drupal Drupal 7.29
Drupal Drupal 7.0
Drupal Drupal 6.0
Drupal Drupal 6.1
Drupal Drupal 6.2
Drupal Drupal 6.16
Drupal Drupal 6.17
Drupal Drupal 6.18
Drupal Drupal 6.19
Drupal Drupal 6.32
Drupal Drupal 6.33
Drupal Drupal 6.34
Drupal Drupal 7.6
Drupal Drupal 7.8
Drupal Drupal 7.13
516
VMScore
CVE-2015-2750
Open redirect vulnerability in URL-related API functions in Drupal 6.x prior to 6.35 and 7.x prior to 7.35 allows remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.
Drupal Drupal 7.1
Drupal Drupal 7.2
Drupal Drupal 7.3
Drupal Drupal 7.16
Drupal Drupal 7.17
Drupal Drupal 7.18
Drupal Drupal 7.19
Drupal Drupal 7.33
Drupal Drupal 7.34
Drupal Drupal 7.0
Drupal Drupal 6.0
Drupal Drupal 6.6
Drupal Drupal 6.7
Drupal Drupal 6.8
Drupal Drupal 6.9
Drupal Drupal 6.10
Drupal Drupal 6.23
Drupal Drupal 6.24
Drupal Drupal 6.25
Drupal Drupal 6.26
Drupal Drupal 7.5
Drupal Drupal 7.7
356
VMScore
CVE-2016-9449
The taxonomy module in Drupal 7.x prior to 7.52 and 8.x prior to 8.2.3 might allow remote authenticated users to obtain sensitive information about taxonomy terms by leveraging inconsistent naming of access query tags.
Drupal Drupal 8.2.0
Drupal Drupal 8.0.0
Drupal Drupal 8.2.1
Drupal Drupal 8.0.4
Drupal Drupal 8.0.5
Drupal Drupal 8.1.2
Drupal Drupal 8.1.3
Drupal Drupal 8.0.2
Drupal Drupal 8.0.3
Drupal Drupal 8.1.0
Drupal Drupal 8.1.1
Drupal Drupal 8.1.9
Drupal Drupal 8.0.6
Drupal Drupal 8.1.4
Drupal Drupal 8.1.5
Drupal Drupal 8.2.2
Drupal Drupal 8.1.10
Drupal Drupal 8.0.1
Drupal Drupal 8.1.6
Drupal Drupal 8.1.7
Drupal Drupal 8.1.8
Drupal Drupal 7.0
436
VMScore
CVE-2016-9451
Confirmation forms in Drupal 7.x prior to 7.52 make it easier for remote authenticated users to conduct open redirect attacks via unspecified vectors.
Drupal Drupal 7.0
Drupal Drupal 7.11
Drupal Drupal 7.12
Drupal Drupal 7.19
Drupal Drupal 7.2
Drupal Drupal 7.27
Drupal Drupal 7.28
Drupal Drupal 7.34
Drupal Drupal 7.35
Drupal Drupal 7.42
Drupal Drupal 7.43
Drupal Drupal 7.1
Drupal Drupal 7.10
Drupal Drupal 7.17
Drupal Drupal 7.18
Drupal Drupal 7.24
Drupal Drupal 7.25
Drupal Drupal 7.26
Drupal Drupal 7.32
Drupal Drupal 7.33
Drupal Drupal 7.40
Drupal Drupal 7.41
445
VMScore
CVE-2016-6212
The Views module 7.x-3.x prior to 7.x-3.14 in Drupal 7.x and the Views module in Drupal 8.x prior to 8.1.3 might allow remote authenticated users to bypass intended access restrictions and obtain sensitive Statistics information via unspecified vectors.
Drupal Drupal 7.39
Drupal Drupal 7.0
Drupal Drupal 7.15
Drupal Drupal 7.16
Drupal Drupal 7.23
Drupal Drupal 7.24
Drupal Drupal 7.30
Drupal Drupal 7.31
Drupal Drupal 7.38
Drupal Drupal 7.4
Drupal Drupal 7.9
Drupal Drupal 7.x-dev
Drupal Drupal 7.43
Drupal Drupal 7.1
Drupal Drupal 7.10
Drupal Drupal 7.17
Drupal Drupal 7.18
Drupal Drupal 7.25
Drupal Drupal 7.26
Drupal Drupal 7.32
Drupal Drupal 7.33
Drupal Drupal 7.40
578
VMScore
CVE-2016-6211
The User module in Drupal 7.x prior to 7.44 allows remote authenticated users to gain privileges via vectors involving contributed or custom code that triggers a rebuild of the user profile form.
Drupal Drupal 7.0
Drupal Drupal 7.13
Drupal Drupal 7.14
Drupal Drupal 7.21
Drupal Drupal 7.22
Drupal Drupal 7.29
Drupal Drupal 7.3
Drupal Drupal 7.36
Drupal Drupal 7.37
Drupal Drupal 7.7
Drupal Drupal 7.8
Drupal Drupal 7.39
Drupal Drupal 7.15
Drupal Drupal 7.16
Drupal Drupal 7.23
Drupal Drupal 7.24
Drupal Drupal 7.30
Drupal Drupal 7.31
Drupal Drupal 7.38
Drupal Drupal 7.4
Drupal Drupal 7.9
Drupal Drupal 7.x-dev
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23316
SQL injection
type confusion
CVE-2024-20697
CVE-2024-4344
local
CVE-2024-30043
CVE-2024-3821
CVE-2024-5041
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »