Vulnerability Name CVE Severity
Dot CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-3938) CVE-2024-3938
Dot CMS Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2020-18875) CVE-2020-18875
Dot CMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2016-2355) CVE-2016-2355
Dot CMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2016-4040) CVE-2016-4040
Dot CMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2016-8902) CVE-2016-8902
Dot CMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2016-8903) CVE-2016-8903
Dot CMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2016-8904) CVE-2016-8904
Dot CMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2016-8905) CVE-2016-8905
Dot CMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2016-8906) CVE-2016-8906
Dot CMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2016-8907) CVE-2016-8907
Dot CMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2016-8908) CVE-2016-8908
Dot CMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2016-10007) CVE-2016-10007
Dot CMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2016-10008) CVE-2016-10008
Dot CMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2017-5344) CVE-2017-5344
Dot CMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2019-12872) CVE-2019-12872
Dot CMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2020-27848) CVE-2020-27848
Dot CMS Other Vulnerability (CVE-2016-4803) CVE-2016-4803
Dot CMS Other Vulnerability (CVE-2022-26352) CVE-2022-26352
Dot CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-1826) CVE-2012-1826
Dot CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-8600) CVE-2016-8600
Dot CMS Server-Side Request Forgery (SSRF) Vulnerability (CVE-2022-37033) CVE-2022-37033
Dot CMS Uncontrolled Recursion Vulnerability (CVE-2022-37034) CVE-2022-37034
DotCMS unrestricted file upload (CVE-2022-26352) CVE-2022-26352
Dot CMS Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2017-3189) CVE-2017-3189
Dot CMS Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2017-11466) CVE-2017-11466
Dot CMS Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-19138) CVE-2020-19138
Dot CMS URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2018-17422) CVE-2018-17422
Dot CMS Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) Vulnerability (CVE-2022-45782) CVE-2022-45782
Dotenv .env file
DotNetNuke multiple vulnerabilities CVE-2012-1030
Dragonfly Arbitrary File Read/Write (CVE-2021-33564) CVE-2021-33564
Drupal 7 arbitrary PHP code execution and information disclosure CVE-2012-4553 CVE-2012-4554
Drupal 7PK - Security Features Vulnerability (CVE-2016-3163) CVE-2016-3163
Drupal 7PK - Security Features Vulnerability (CVE-2016-3168) CVE-2016-3168
Drupal Backup Migrate directory publicly accessible
Drupal configuration file weak file permissions
Drupal Configuration Vulnerability (CVE-2008-6171) CVE-2008-6171
Drupal Core 4.5.x Cross-Site Scripting (4.5.0 - 4.5.1) CVE-2005-0682
Drupal Core 4.5.x Cross-Site Scripting (4.5.0 - 4.5.5) CVE-2005-3973
Drupal Core 4.5.x Cross-Site Scripting (4.5.0 - 4.5.7) CVE-2006-1226
Drupal Core 4.5.x Mail Header Injection (4.5.0 - 4.5.7)
Drupal Core 4.5.x Multiple Vulnerabilities (4.5.0 - 4.5.5)
Drupal Core 4.5.x Security Bypass (4.5.0 - 4.5.7)
Drupal Core 4.5.x Session Fixation (4.5.0 - 4.5.7)
Drupal Core 4.6.x Arbitrary Code Execution (4.6.0 - 4.6.6) CVE-2006-2743
Drupal Core 4.6.x Arbitrary Code Execution (4.6.0 - 4.6.7) CVE-2006-2831
Drupal Core 4.6.x Cross-Site Request Forgery (4.6.0 - 4.6.9) CVE-2006-5476
Drupal Core 4.6.x Cross-Site Scripting (4.6.0 - 4.6.3) CVE-2005-3973
Drupal Core 4.6.x Cross-Site Scripting (4.6.0 - 4.6.5) CVE-2006-1226
Drupal Core 4.6.x Cross-Site Scripting (4.6.0 - 4.6.7) CVE-2006-2833
Drupal Core 4.6.x Cross-Site Scripting (4.6.0 - 4.6.8) CVE-2006-4002
Drupal Core 4.6.x Cross-Site Scripting (4.6.0 - 4.6.10) CVE-2007-0136
Drupal Core 4.6.x Denial of Service (4.6.0 - 4.6.10) CVE-2007-0124
Drupal Core 4.6.x Form Action Attribute Injection (4.6.0 - 4.6.9) CVE-2006-5477
Drupal Core 4.6.x Mail Header Injection (4.6.0 - 4.6.5)
Drupal Core 4.6.x Multiple Cross-Site Scripting Vulnerabilities (4.6.0 - 4.6.9) CVE-2006-5475
Drupal Core 4.6.x Multiple Vulnerabilities (4.6.0 - 4.6.3)
Drupal Core 4.6.x Security Bypass (4.6.0 - 4.6.3) CVE-2005-3974
Drupal Core 4.6.x Security Bypass (4.6.0 - 4.6.5)
Drupal Core 4.6.x Session Fixation (4.6.0 - 4.6.5)
Drupal Core 4.6.x SQL Injection (4.6.0 - 4.6.6) CVE-2006-2742
Drupal Core 4.7.x Arbitrary Code Execution (4.7.0 - 4.7.5) CVE-2007-0626
Drupal Core 4.7.x Arbitrary Code Execution (4.7.0) CVE-2006-2743
Drupal Core 4.7.x Cross-Site Request Forgery (4.7.0 - 4.7.3) CVE-2006-5476
Drupal Core 4.7.x Cross-Site Request Forgery (4.7.0 - 4.7.10) CVE-2008-0272
Drupal Core 4.7.x Cross-Site Scripting (4.7.0 - 4.7.1) CVE-2006-2833
Drupal Core 4.7.x Cross-Site Scripting (4.7.0 - 4.7.2) CVE-2006-4002
Drupal Core 4.7.x Cross-Site Scripting (4.7.0 - 4.7.4) CVE-2007-0136
Drupal Core 4.7.x Cross-Site Scripting (4.7.0 - 4.7.7) CVE-2007-5596
Drupal Core 4.7.x Cross-Site Scripting (4.7.0 - 4.7.10) CVE-2008-0274
Drupal Core 4.7.x Denial of Service (4.7.0 - 4.7.4) CVE-2007-0124
Drupal Core 4.7.x Form Action Attribute Injection (4.7.0 - 4.7.3) CVE-2006-5477
Drupal Core 4.7.x HTTP Response Splitting (4.7.0 - 4.7.7) CVE-2007-5595
Drupal Core 4.7.x Multiple Cross-Site Scripting Vulnerabilities (4.7.0 - 4.7.3) CVE-2006-5475
Drupal Core 4.7.x Multiple Cross-Site Scripting Vulnerabilities (4.7.0 - 4.7.6) CVE-2007-4064