You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
|
Update Date":Nov. 20, 2024, 2:02 p.m.
No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
---|---|---|---|---|---|---|---|---|---|---|---|
204271 | 4 | 警告 | IBM | - | IBM DB2 の DRDA Services コンポーネントにおけるサービス運用妨害 (DoS) の脆弱性 |
CWE-noinfo
情報不足 |
CVE-2009-4328 | 2010-02-4 11:19 | 2009-12-16 | Show | GitHub Exploit DB Packet Storm |
204272 | 7.2 | 危険 | IBM | - | IBM DB2 の Install コンポーネントにおける脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2009-4331 | 2010-02-4 11:19 | 2009-12-16 | Show | GitHub Exploit DB Packet Storm |
204273 | 7.5 | 危険 | IBM | - | IBM DB2 の Relational Data Services コンポーネントにおけるパスワードの引数を取得される脆弱性 |
CWE-200
情報漏えい |
CVE-2009-4333 | 2010-02-4 11:19 | 2009-12-16 | Show | GitHub Exploit DB Packet Storm |
204274 | 7.2 | 危険 | IBM | - | IBM DB2 の Engine Utilities コンポーネントの db2licm における脆弱性 |
CWE-noinfo
情報不足 |
CVE-2009-4330 | 2010-02-4 11:18 | 2009-12-16 | Show | GitHub Exploit DB Packet Storm |
204275 | 4 | 警告 | IBM | - | IBM DB2 の Engine Utilities コンポーネントにおけるサービス運用妨害 (DoS) の脆弱性 |
CWE-noinfo
情報不足 |
CVE-2009-4329 | 2010-02-4 11:18 | 2009-12-16 | Show | GitHub Exploit DB Packet Storm |
204276 | 7.2 | 危険 | サイバートラスト株式会社 Linux |
- | Linux kernel の kvm_dev_ioctl_get_supported_cpuid 関数における整数オーバーフローの脆弱性 |
CWE-189
数値処理の問題 |
CVE-2009-3638 | 2010-02-3 14:35 | 2009-10-29 | Show | GitHub Exploit DB Packet Storm |
204277 | 5 | 警告 | Linear LLC S2 Security |
- | Linear eMerge のマネージメントコンポーネントにおけるサービス運用妨害 (DoS) |
CWE-noinfo
情報不足 |
CVE-2009-3734 | 2010-02-3 14:35 | 2010-01-5 | Show | GitHub Exploit DB Packet Storm |
204278 | 7.5 | 危険 | The PHP Group LibGD project サイバートラスト株式会社 レッドハット |
- | PHP および GD Graphics Library の _gdGetColors 関数におけるバッファオーバーフローの脆弱性 |
CWE-Other
その他 |
CVE-2009-3546 | 2010-02-3 14:34 | 2009-10-19 | Show | GitHub Exploit DB Packet Storm |
204279 | 6.8 | 警告 | GNU Project XEmacs サイバートラスト株式会社 |
- | Emacs および XEmacs における .flc ファイルの処理に関する任意のコードを実行される脆弱性 |
CWE-DesignError
|
CVE-2008-2142 | 2010-02-2 11:43 | 2008-05-12 | Show | GitHub Exploit DB Packet Storm |
204280 | 3.5 | 注意 | Drupal サイバートラスト株式会社 |
- | Drupal の Menu モジュールにおけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-4370 | 2010-02-2 11:43 | 2009-12-16 | Show | GitHub Exploit DB Packet Storm |
Update Date:Nov. 20, 2024, 12:18 p.m.
No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
---|---|---|---|---|---|---|---|---|---|---|---|
121 | 6.1 |
MEDIUM
Network |
tripetto | tripetto | The Tripetto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up to, and including, 8.0.3 due to insufficient input sanitization and output escaping.… Update |
CWE-79
Cross-site Scripting |
CVE-2024-10260 | 2024-11-20 06:20 | 2024-11-15 | Show | GitHub Exploit DB Packet Storm |
122 | 4.3 |
MEDIUM
Network |
smartwpress | music_player_for_elementor | The Music Player for Elementor – Audio Player & Podcast Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the import_mpfe_template() … Update |
CWE-862
Missing Authorization |
CVE-2024-10582 | 2024-11-20 06:17 | 2024-11-15 | Show | GitHub Exploit DB Packet Storm |
123 | 6.1 |
MEDIUM
Network |
melapress | wp_activity_log | The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and including, 5.2.1 due to insufficient input sanitization and … Update |
CWE-79
Cross-site Scripting |
CVE-2024-10793 | 2024-11-20 06:13 | 2024-11-15 | Show | GitHub Exploit DB Packet Storm |
124 | 6.1 |
MEDIUM
Network |
glpi-project | glpi | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An unauthenticated user can provide a malicious link… Update |
CWE-79
Cross-site Scripting |
CVE-2024-45610 | 2024-11-20 06:07 | 2024-11-16 | Show | GitHub Exploit DB Packet Storm |
125 | 5.4 |
MEDIUM
Network |
glpi-project | glpi | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can bypass the access control … Update |
CWE-79
Cross-site Scripting |
CVE-2024-45611 | 2024-11-20 05:57 | 2024-11-16 | Show | GitHub Exploit DB Packet Storm |
126 | 8.1 |
HIGH
Network |
microsoft | windows_server_2022 | Windows SMBv3 Server Remote Code Execution Vulnerability Update |
NVD-CWE-noinfo
|
CVE-2024-43447 | 2024-11-20 05:52 | 2024-11-13 | Show | GitHub Exploit DB Packet Storm |
127 | 5.9 |
MEDIUM
Network |
microsoft |
windows_server_2025 windows_11_22h2 windows_11_23h2 windows_server_2022_23h2 windows_11_24h2 |
Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability Update |
NVD-CWE-noinfo
|
CVE-2024-38264 | 2024-11-20 05:52 | 2024-11-13 | Show | GitHub Exploit DB Packet Storm |
128 | 7.5 |
HIGH
Network |
microsoft |
windows_server_2008 windows_server_2012 windows_server_2025 windows_server_2019 windows_server_2022 windows_server_2022_23h2 windows_server_2016 |
Windows DNS Spoofing Vulnerability Update |
NVD-CWE-noinfo
|
CVE-2024-43450 | 2024-11-20 05:49 | 2024-11-13 | Show | GitHub Exploit DB Packet Storm |
129 | 6.8 |
MEDIUM
Physics |
microsoft |
windows_server_2008 windows_server_2012 windows_server_2025 windows_10_1809 windows_server_2019 windows_server_2022 windows_10_21h2 windows_11_22h2 windows_10_22h2 windows_… |
Windows USB Video Class System Driver Elevation of Privilege Vulnerability Update |
NVD-CWE-noinfo
|
CVE-2024-43449 | 2024-11-20 05:49 | 2024-11-13 | Show | GitHub Exploit DB Packet Storm |
130 | 7.5 |
HIGH
Network |
microsoft |
windows_server_2008 windows_server_2025 windows_10_1809 windows_server_2019 windows_server_2022 windows_10_21h2 windows_11_22h2 windows_10_22h2 windows_11_23h2 windows_serv… |
Windows Registry Elevation of Privilege Vulnerability Update |
NVD-CWE-noinfo
|
CVE-2024-43452 | 2024-11-20 05:48 | 2024-11-13 | Show | GitHub Exploit DB Packet Storm |