|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 24, 2026, 6 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 225091 | 7.5 | 危険 | シーメンス | - | SIMATIC PCS 7 で使用される Siemens WinCC の Web Navigator における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2013-3957 | 2013-06-18 11:16 | 2013-06-14 | Show | GitHub Exploit DB Packet Storm |
| 225092 | 10 | 危険 | オラクル | - | Oracle Java SE の Java Runtime Environment におけるセキュリティ・レベルを回避される脆弱性 |
CWE-noinfo
情報不足 |
CVE-2013-1489 | 2013-06-17 17:01 | 2013-02-1 | Show | GitHub Exploit DB Packet Storm |
| 225093 | 5 | 警告 | ヒューレット・パッカード | - | HP Insight Diagnostics の hpdiags/frontend2/help/pageview.php における任意の HTML ファイルをインクルードされる脆弱性 |
CWE-20
不適切な入力確認 |
CVE-2013-3575 | 2013-06-17 14:25 | 2013-06-10 | Show | GitHub Exploit DB Packet Storm |
| 225094 | 7.8 | 危険 | ヒューレット・パッカード | - | HP Insight Diagnostics の hpdiags/frontend2/commands/saveCompareConfig.php における絶対パストラバーサルの脆弱性 |
CWE-20
不適切な入力確認 |
CVE-2013-3574 | 2013-06-17 14:23 | 2013-06-10 | Show | GitHub Exploit DB Packet Storm |
| 225095 | 10 | 危険 | ヒューレット・パッカード | - | HP Insight Diagnostics における不特定のインジェクション攻撃を実行される脆弱性 |
CWE-20
不適切な入力確認 |
CVE-2013-3573 | 2013-06-17 14:22 | 2013-06-10 | Show | GitHub Exploit DB Packet Storm |
| 225096 | 4.3 | 警告 | シスコシステムズ | - | Cisco Video Surveillance Operations Manager におけるオープンリダイレクトの脆弱性 |
CWE-20
不適切な入力確認 |
CVE-2013-3376 | 2013-06-17 14:22 | 2013-06-14 | Show | GitHub Exploit DB Packet Storm |
| 225097 | 4.3 | 警告 | シスコシステムズ | - | Cisco Prime Central for Hosted Collaboration Solution におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2013-3375 | 2013-06-17 14:21 | 2013-06-14 | Show | GitHub Exploit DB Packet Storm |
| 225098 | 4.3 | 警告 | Orchard Project | - | Orchard におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2013-3645 | 2013-06-17 11:59 | 2013-06-13 | Show | GitHub Exploit DB Packet Storm |
| 225099 | 10 | 危険 | オラクル | - | Oracle Java SE の Java Runtime Environment および JavaFX における 2D の処理に関する脆弱性 |
CWE-noinfo
情報不足 |
CVE-2013-0437 | 2013-06-14 19:15 | 2013-02-1 | Show | GitHub Exploit DB Packet Storm |
| 225100 | 10 | 危険 | オラクル | - | Oracle Java SE の JavaFX における脆弱性 |
CWE-noinfo
情報不足 |
CVE-2013-0436 | 2013-06-14 19:11 | 2013-02-1 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 24, 2026, 4:05 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 199241 | 6.5 |
MEDIUM
Adjacent |
gradle | plugin_publishing | All versions of com.gradle.plugin-publish before 0.11.0 are vulnerable to Insertion of Sensitive Information into Log File. When a plugin author publishes a Gradle plugin while running Gradle with th… |
CWE-532
Inclusion of Sensitive Information in Log Files |
CVE-2020-7599 | 2024-11-21 14:37 | 2020-03-31 | Show | GitHub Exploit DB Packet Storm |
| 199242 | 6.1 |
MEDIUM
Network |
schneider-electric |
andover_continuum_9680_firmware andover_continuum_5740_firmware andover_continuum_5720_firmware andover_continuum_bcx4040_firmware andover_continuum_bcx9640_firmware andover_continuum_… |
A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists Andover Continuum (All versions), which could cause a Reflective Cross-site Scriptin… |
CWE-79
Cross-site Scripting |
CVE-2020-7482 | 2024-11-21 14:37 | 2020-03-24 | Show | GitHub Exploit DB Packet Storm |
| 199243 | 6.1 |
MEDIUM
Network |
schneider-electric |
andover_continuum_9680_firmware andover_continuum_5740_firmware andover_continuum_5720_firmware andover_continuum_bcx4040_firmware andover_continuum_bcx9640_firmware andover_continuum_… |
A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists Andover Continuum (All versions), which could enable a successful Cross-site Scripti… |
CWE-79
Cross-site Scripting |
CVE-2020-7481 | 2024-11-21 14:37 | 2020-03-24 | Show | GitHub Exploit DB Packet Storm |
| 199244 | 9.8 |
CRITICAL
Network |
schneider-electric |
andover_continuum_9680_firmware andover_continuum_5740_firmware andover_continuum_5720_firmware andover_continuum_bcx4040_firmware andover_continuum_bcx9640_firmware andover_continuum_… |
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versions), which could cause files on the application server filesystem to be viewab… |
CWE-94
Code Injection |
CVE-2020-7480 | 2024-11-21 14:37 | 2020-03-24 | Show | GitHub Exploit DB Packet Storm |
| 199245 | 7.8 |
HIGH
Local |
schneider-electric | interactive_graphical_scada_system | A CWE-306: Missing Authentication for Critical Function vulnerability exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a local user to execute processes that ot… |
CWE-306
Missing Authentication for Critical Function |
CVE-2020-7479 | 2024-11-21 14:37 | 2020-03-24 | Show | GitHub Exploit DB Packet Storm |
| 199246 | 7.5 |
HIGH
Network |
schneider-electric | interactive_graphical_scada_system | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a remote unauthenticated attacker to read… |
CWE-22
Path Traversal |
CVE-2020-7478 | 2024-11-21 14:37 | 2020-03-24 | Show | GitHub Exploit DB Packet Storm |
| 199247 | 7.8 |
HIGH
Local |
schneider-electric | ulti_zigbee_installation_toolkit | A CWE-426: Untrusted Search Path vulnerability exists in ZigBee Installation Kit (Versions prior to 1.0.1), which could cause execution of malicious code when a malicious file is put in the search pa… |
CWE-426
Untrusted Search Path |
CVE-2020-7476 | 2024-11-21 14:37 | 2020-03-24 | Show | GitHub Exploit DB Packet Storm |
| 199248 | 7.5 |
HIGH
Network |
schneider-electric |
140noe77101_firmware 140noe77111_firmware tsxh5744m_firmware tsxh5724m_firmware tsxp576634m_firmware tsxp57554m_firmware tsxp575634m_firmware tsxp57454m_firmware tsxp574634m_f… |
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Quantum Ethernet Network module 140NOE771x1 (Versions 7.0 and prior), Quantum processors with integrated Ethern… |
CWE-754
Improper Check for Unusual or Exceptional Conditions |
CVE-2020-7477 | 2024-11-21 14:37 | 2020-03-24 | Show | GitHub Exploit DB Packet Storm |
| 199249 | 9.8 |
CRITICAL
Network |
schneider-electric |
unity_pro ecostruxure_control_expert modicon_m340_firmware modicon_m580_firmware |
A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to… |
CWE-74
Injection |
CVE-2020-7475 | 2024-11-21 14:37 | 2020-03-24 | Show | GitHub Exploit DB Packet Storm |
| 199250 | 7.8 |
HIGH
Local |
schneider-electric | pmepxm0100_prosoft_configurator | A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProSoft Configurator (v1.002 and prior), for the PMEPXM0100 (H) module, which could cause the execution of untrusted code when usin… |
CWE-427
Uncontrolled Search Path Element |
CVE-2020-7474 | 2024-11-21 14:37 | 2020-03-24 | Show | GitHub Exploit DB Packet Storm |