Drupal Core is prone to a denial of service vulnerability. Exploiting this issue may allow an attacker to cause the affected website to consume memory and CPU resources or to fill up the server disk space, thus denying service to legitimate users. Drupal Core versions 7.x ranging from 7.0 and up to and including 7.19 are vulnerable.
Update to Drupal Core version 7.20 or latest
WordPress Plugin Invoicing with InvoiceXpress for WooCommerce-Free Cross-Site Scripting (3.0.2)
WordPress Plugin FormBuilder Cross-Site Scripting (1.05)
Drupal Core 9.4.x Remote Code Execution (9.4.0 - 9.4.2)
WordPress Plugin Newsletter Cross-Site Scripting (3.2.6)
WordPress Plugin The Post Grid-Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid Cross-Site Request Forgery (5.0.4)