CVE-2018-7602Critical· 9.8▾ Hadal⚠ Exploited in the wildPoC availableA remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This …
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 53.9 · likelihood 19.8 · exploitation 25 · ransomware 5
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 3 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due May 4, 2022
Last analysed / modified upstream
99%
Exploit-DB · 5 GitHub repos · Nuclei ×1 (last check)
Added to the CISA catalog on Apr 13, 2022. Federal remediation due May 4, 2022. View catalog ↗
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.
drupal >= 7.0, < 7.59drupal >= 8.4.0, < 8.4.8drupal >= 8.5.0, < 8.5.3debian_linux = 7.0debian_linux = 8.0debian_linux = 9.0Upgrade past the affected range:
drupal 8.5.3Connected by shared product, vendor, weakness, or advisory.
CVE-2023-3519Critical· 9.8Unauthenticated remote code execution
CVE-2021-44529Critical· 9.8A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
CVE-2021-22205Critical· 10.0An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9
CVE-2025-14576High· 7.8Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick
CVE-2025-62593CriticalRay is an AI compute engine
CVE-2024-23692Critical· 9.8Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability