CVE-2021-41183
- EPSS 8.53%
- Veröffentlicht 26.10.2021 15:15:10
- Zuletzt bearbeitet 25.08.2026 16:28:27
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The v...
CVE-2021-41184
- EPSS 40.77%
- Veröffentlicht 26.10.2021 15:15:10
- Zuletzt bearbeitet 25.08.2026 16:28:27
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string v...
CVE-2020-13663
- EPSS 0.7%
- Veröffentlicht 11.06.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 05:01:43
Cross Site Request Forgery vulnerability in Drupal Core Form API does not properly handle certain form input from cross-site requests, which can lead to other vulnerabilities.
CVE-2020-13688
- EPSS 0.66%
- Veröffentlicht 11.06.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 05:01:44
Cross-site scripting vulnerability in l Drupal Core allows an attacker could leverage the way that HTML is rendered for affected forms in order to exploit the vulnerability. This issue affects: Drupal Core 8.8.X versions prior to 8.8.10; 8.9.X versio...
CVE-2021-33829
- EPSS 3.19%
- Veröffentlicht 09.06.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:09:38
A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.
CVE-2020-13667
- EPSS 0.93%
- Veröffentlicht 17.05.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:01:43
Access bypass vulnerability in of Drupal Core Workspaces allows an attacker to access data without correct permissions. The Workspaces module doesn't sufficiently check access permissions when switching workspaces, leading to an access bypass vulnera...
CVE-2020-13662
- EPSS 0.86%
- Veröffentlicht 05.05.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 05:01:42
Open Redirect vulnerability in Drupal Core allows a user to be tricked into visiting a specially crafted link which would redirect them to an arbitrary external URL. This issue affects: Drupal Drupal Core 7 version 7.70 and prior versions.
CVE-2020-13664
- EPSS 2.98%
- Veröffentlicht 05.05.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 05:01:43
Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an administrator into visiting a malicious site that could result in creating a carefully named directory on the file system. With this dir...
CVE-2020-13665
- EPSS 1.28%
- Veröffentlicht 05.05.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 05:01:43
Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in read/write mode. Only sites that have the read_only set to FALSE under jsonapi.settings config are vulnerable. This issue affects: Drupal Drupal Core 8.8.x versions prior ...
CVE-2020-13666
- EPSS 2.93%
- Veröffentlicht 05.05.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 05:01:43
Cross-site scripting vulnerability in Drupal Core. Drupal AJAX API does not disable JSONP by default, allowing for an XSS attack. This issue affects: Drupal Drupal Core 7.x versions prior to 7.73; 8.8.x versions prior to 8.8.10; 8.9.x versions prior ...