Vulnerabilities

Summary — last 7 days

New vulnerabilities2,722▼ 518 vs. last week
Critical / high1,296▼ 206 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)226▼ 276 vs. last week
–

2 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (5.5)1.4%—DrupalDrupal Upload Module8/27/20086/16/2026
The Upload module in Drupal 6.x before 6.4 allows remote authenticated users to edit nodes, delete files, and download unauthorized attachments via unspecified vectors.
ModifiedMedium (6.4)2.5%—Drupal Comment Upload Module2/5/20086/16/2026
The Comment Upload 4.7.x before 4.7.x-0.1 and 5.x before 5.x-0.1 module for Drupal does not properly use functions in the upload module, which allows remote attackers to bypass upload validation, and upload arbitrary files and possibly execute arbitrary code, via unspecified vectors.
Orbitaley — Vulnerabilities