Vulnerability Name CVE Severity
Drupal Core 9.0.x Information Disclosure (9.0.0 - 9.0.5) CVE-2020-13670
Drupal Core 9.0.x Multiple Cross-Site Scripting Vulnerabilities (9.0.0 - 9.0.5) CVE-2020-13666 CVE-2020-13668 CVE-2020-13669 CVE-2020-13688
Drupal Core 9.0.x Multiple Security Bypass Vulnerabilities (9.0.0 - 9.0.14) CVE-2020-13675 CVE-2020-13676 CVE-2020-13677
Drupal Core 9.0.x Remote Code Execution (9.0.0 - 9.0.7) CVE-2020-13671
Drupal Core 9.0.x Remote Code Execution (9.0.0 - 9.0.8) CVE-2020-28948 CVE-2020-28949
Drupal Core 9.0.x Security Bypass (9.0.0 - 9.0.5) CVE-2020-13667
Drupal Core 9.1.x Arbitrary File Overwrite (9.1.0 - 9.1.2) CVE-2020-36193
Drupal Core 9.1.x Cross-Site Request Forgery (9.1.0 - 9.1.12) CVE-2020-13673 CVE-2020-13674
Drupal Core 9.1.x Cross-Site Scripting (9.1.0 - 9.1.6) CVE-2020-13672
Drupal Core 9.1.x Cross-Site Scripting (9.1.0 - 9.1.8) CVE-2021-33829
Drupal Core 9.1.x Cross-Site Scripting (9.1.0 - 9.1.11)
Drupal Core 9.1.x Cross-Site Scripting (9.1.0 - 9.1.13)
Drupal Core 9.1.x Directory Traversal (9.1.0 - 9.1.10) CVE-2021-32610
Drupal Core 9.1.x Multiple Security Bypass Vulnerabilities (9.1.0 - 9.1.12) CVE-2020-13675 CVE-2020-13676 CVE-2020-13677
Drupal Core 9.2.x Cross-Site Request Forgery (9.2.0 - 9.2.5) CVE-2020-13673 CVE-2020-13674
Drupal Core 9.2.x Cross-Site Scripting (9.2.0 - 9.2.3)
Drupal Core 9.2.x Cross-Site Scripting (9.2.0 - 9.2.8)
Drupal Core 9.2.x Cross-Site Scripting (9.2.0 - 9.2.10) CVE-2021-41184
Drupal Core 9.2.x Directory Traversal (9.2.0 - 9.2.1) CVE-2021-32610
Drupal Core 9.2.x Multiple Security Bypass Vulnerabilities (9.2.0 - 9.2.5) CVE-2020-13675 CVE-2020-13676 CVE-2020-13677
Drupal Core 9.2.x Multiple Vulnerabilities (9.2.0 - 9.2.14) CVE-2022-24728 CVE-2022-24729
Drupal Core 9.2.x Security Bypass (9.2.0 - 9.2.12) CVE-2022-25270
Drupal Core 9.2.x Security Bypass (9.2.0 - 9.2.15) CVE-2022-24775
Drupal Core 9.2.x Security Bypass (9.2.0 - 9.2.17) CVE-2022-25273
Drupal Core 9.2.x Security Bypass (9.2.0 - 9.2.19) CVE-2022-29248
Drupal Core 9.2.x Security Bypass (9.2.0 - 9.2.20) CVE-2022-31042 CVE-2022-31043
Drupal Core 9.3.x Cross-Site Scripting (9.3.0 - 9.3.2) CVE-2021-41184
Drupal Core 9.3.x Cross-Site Scripting (9.3.0 - 9.3.18) CVE-2022-25276
Drupal Core 9.3.x Multiple Vulnerabilities (9.3.0 - 9.3.7) CVE-2022-24728 CVE-2022-24729
Drupal Core 9.3.x Remote Code Execution (9.3.0 - 9.3.18) CVE-2022-25277
Drupal Core 9.3.x Security Bypass (9.3.0 - 9.3.5) CVE-2022-25271
Drupal Core 9.3.x Security Bypass (9.3.0 - 9.3.8) CVE-2022-24775
Drupal Core 9.3.x Security Bypass (9.3.0 - 9.3.11) CVE-2022-25274
Drupal Core 9.3.x Security Bypass (9.3.0 - 9.3.13) CVE-2022-29248
Drupal Core 9.3.x Security Bypass (9.3.0 - 9.3.15) CVE-2022-31042 CVE-2022-31043
Drupal Core 9.3.x Security Bypass (9.3.0 - 9.3.18) CVE-2022-25278
Drupal Core 9.4.x Cross-Site Scripting (9.4.0 - 9.4.2) CVE-2022-25276
Drupal Core 9.4.x Remote Code Execution (9.4.0 - 9.4.2) CVE-2022-25277
Drupal Core 9.4.x Security Bypass (9.4.0 - 9.4.2) CVE-2022-25275
Drupal Core Cross-Site Scripting (8.0.0 - 9.1.15) CVE-2021-41184
Drupal Core Cross-Site Scripting (8.0.0 - 9.2.21) CVE-2022-25276
Drupal Core Multiple Vulnerabilities (8.0.0 - 9.1.15) CVE-2022-24728 CVE-2022-24729
Drupal Core Remote Code Execution (8.0.0 - 9.2.21) CVE-2022-25277
Drupal Core Security Bypass (8.0.0 - 9.1.15) CVE-2022-24775
Drupal Core Security Bypass (8.0.0 - 9.2.21) CVE-2022-25275
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-6379) CVE-2017-6379
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-13663) CVE-2020-13663
Drupal CVE-2008-4793 Vulnerability (CVE-2008-4793) CVE-2008-4793
Drupal CVE-2014-1475 Vulnerability (CVE-2014-1475) CVE-2014-1475
Drupal CVE-2017-6919 Vulnerability (CVE-2017-6919) CVE-2017-6919
Drupal CVE-2017-6930 Vulnerability (CVE-2017-6930) CVE-2017-6930
Drupal Data Processing Errors Vulnerability (CVE-2016-3171) CVE-2016-3171
Drupal Deserialization of Untrusted Data Vulnerability (CVE-2019-6338) CVE-2019-6338
Drupal Deserialization of Untrusted Data Vulnerability (CVE-2019-6340) CVE-2019-6340
Drupal Deserialization of Untrusted Data Vulnerability (CVE-2020-28948) CVE-2020-28948
Drupal Exposure of Resource to Wrong Sphere Vulnerability (CVE-2020-13670) CVE-2020-13670
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-6926) CVE-2017-6926
Drupal Improper Access Control Vulnerability (CVE-2016-3162) CVE-2016-3162
Drupal Improper Access Control Vulnerability (CVE-2016-3165) CVE-2016-3165
Drupal Improper Access Control Vulnerability (CVE-2016-5385) CVE-2016-5385
Drupal Improper Access Control Vulnerability (CVE-2020-13677) CVE-2020-13677
Drupal Improper Authentication Vulnerability (CVE-2019-10911) CVE-2019-10911
Drupal Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2005-1921) CVE-2005-1921
Drupal Improper Input Validation Vulnerability (CVE-2007-6299) CVE-2007-6299
Drupal Improper Input Validation Vulnerability (CVE-2022-24775) CVE-2022-24775
Drupal Improper Input Validation Vulnerability (CVE-2022-25271) CVE-2022-25271
Drupal Improper Input Validation Vulnerability (CVE-2022-25273) CVE-2022-25273
Drupal Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2020-36193) CVE-2020-36193
Drupal Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2022-39261) CVE-2022-39261
Drupal Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2020-28949) CVE-2020-28949
Drupal Improper Neutralization of Special Elements used in a Command ('Command Injection') Vulnerability (CVE-2020-13664) CVE-2020-13664
Drupal Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2008-2999) CVE-2008-2999
Drupal Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2008-3223) CVE-2008-3223
Drupal Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2014-3704) CVE-2014-3704
Drupal Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2015-6659) CVE-2015-6659