|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 13, 2026, 6 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 226341 | 5 | 警告 | ViewVC | - | ViewVC における脆弱性 |
CWE-noinfo
情報不足 |
CVE-2009-3619 | 2012-12-20 19:28 | 2009-08-11 | Show | GitHub Exploit DB Packet Storm |
| 226342 | 4.3 | 警告 | ViewVC | - | ViewVC の viewvc.py におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-3618 | 2012-12-20 19:28 | 2009-08-11 | Show | GitHub Exploit DB Packet Storm |
| 226343 | 7.6 | 危険 | tatsuhiro tsujikawa | - | aria の src/AbstractCommand.cc におけるフォーマットストリングの脆弱性 |
CWE-134
書式文字列の問題 |
CVE-2009-3617 | 2012-12-20 19:28 | 2009-10-20 | Show | GitHub Exploit DB Packet Storm |
| 226344 | 8.5 | 危険 | Fabrice Bellard | - | QEMU の VNC server におけるホストの OS 上で任意のコードを実行される脆弱性 |
CWE-399
リソース管理の問題 |
CVE-2009-3616 | 2012-12-20 19:28 | 2009-10-23 | Show | GitHub Exploit DB Packet Storm |
| 226345 | 9.3 | 危険 | freedesktop.org | - | Poppler の glib/poppler-page.cc における整数オーバーフローの脆弱性 |
CWE-189
数値処理の問題 |
CVE-2009-3607 | 2012-12-20 19:28 | 2009-10-21 | Show | GitHub Exploit DB Packet Storm |
| 226346 | 4.3 | 警告 | Scriptsez.net | - | Scriptsez Ultimate Poll の demo_page.php におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-3601 | 2012-12-20 19:28 | 2009-10-8 | Show | GitHub Exploit DB Packet Storm |
| 226347 | 7.5 | 危険 | vspanel | - | VS PANEL の results.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-3595 | 2012-12-20 19:28 | 2009-10-8 | Show | GitHub Exploit DB Packet Storm |
| 226348 | 4.3 | 警告 | qtmsoft | - | Qualiteam X-Cart の customer/home.php におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-3592 | 2012-12-20 19:28 | 2009-10-8 | Show | GitHub Exploit DB Packet Storm |
| 226349 | 7.5 | 危険 | vspanel | - | VS PANEL の showcat.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-3590 | 2012-12-20 19:28 | 2009-10-8 | Show | GitHub Exploit DB Packet Storm |
| 226350 | 5 | 警告 | sql-ledger | - | SQL-Ledger におけるクッキーをキャプチャされる脆弱性 |
CWE-16
環境設定 |
CVE-2009-3584 | 2012-12-20 19:28 | 2009-12-23 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 14, 2026, 4 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 210631 | 6.5 |
MEDIUM
Network |
gnome canonical fedoraproject netapp broadcom |
balsa glib-networking ubuntu_linux fedora cloud_backup fabric_operating_system |
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server… |
CWE-295
Improper Certificate Validation |
CVE-2020-13645 | 2024-11-21 14:01 | 2020-05-28 | Show | GitHub Exploit DB Packet Storm |
| 210632 | 5.4 |
MEDIUM
Network |
pickplugins | accordion | An issue was discovered in the Accordion plugin before 2.2.9 for WordPress. The unprotected AJAX wp_ajax_accordions_ajax_import_json action allowed any authenticated user with Subscriber or higher pe… |
CWE-79
Cross-site Scripting |
CVE-2020-13644 | 2024-11-21 14:01 | 2020-05-28 | Show | GitHub Exploit DB Packet Storm |
| 210633 | 8.8 |
HIGH
Network |
siteorigin | page_builder | An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification, allowing for requests to be forged on behalf of … |
CWE-352
Origin Validation Error |
CVE-2020-13643 | 2024-11-21 14:01 | 2020-05-28 | Show | GitHub Exploit DB Packet Storm |
| 210634 | 8.8 |
HIGH
Network |
siteorigin | page_builder | An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce verification, allowing for requests to be forged o… |
CWE-352
Origin Validation Error |
CVE-2020-13642 | 2024-11-21 14:01 | 2020-05-28 | Show | GitHub Exploit DB Packet Storm |
| 210635 | 8.8 |
HIGH
Network |
infolific | real-time_find_and_replace | An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page function did not do any nonce verification, allowing for requests to be forged on beh… |
CWE-352
Origin Validation Error |
CVE-2020-13641 | 2024-11-21 14:01 | 2020-05-28 | Show | GitHub Exploit DB Packet Storm |
| 210636 | 6.1 |
MEDIUM
Network |
fork-cms | fork_cms | Fork before 5.8.3 allows XSS via navigation_title or title. |
CWE-79
Cross-site Scripting |
CVE-2020-13633 | 2024-11-21 14:01 | 2020-05-28 | Show | GitHub Exploit DB Packet Storm |
| 210637 | 6.1 |
MEDIUM
Network |
centreon |
centreon_host-monitoring_widget centreon_tactical-overview_widget centreon_service-monitoring_widget |
Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to host-monitoring/src/toolbar.php. This vulnerability is fixed in v… |
CWE-79
Cross-site Scripting |
CVE-2020-13628 | 2024-11-21 14:01 | 2020-05-28 | Show | GitHub Exploit DB Packet Storm |
| 210638 | 6.1 |
MEDIUM
Network |
centreon |
centreon_host-monitoring_widget centreon_tactical-overview_widget centreon_service-monitoring_widget |
Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to service-monitoring/src/index.php. This vulnerability is fixed in … |
CWE-79
Cross-site Scripting |
CVE-2020-13627 | 2024-11-21 14:01 | 2020-05-28 | Show | GitHub Exploit DB Packet Storm |
| 210639 | 5.5 |
MEDIUM
Local |
sqlite fedoraproject canonical netapp brocade debian siemens oracle |
sqlite fedora ubuntu_linux cloud_backup solidfire\ _enterprise_sds_\&_hci_storage_node fabric_operating_system hci_compute_node_firmware debian_linux sinec_infrastructu… |
ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query. |
CWE-476
NULL Pointer Dereference |
CVE-2020-13632 | 2024-11-21 14:01 | 2020-05-28 | Show | GitHub Exploit DB Packet Storm |
| 210640 | 5.5 |
MEDIUM
Local |
sqlite fedoraproject canonical netapp brocade siemens apple oracle |
sqlite fedora ubuntu_linux cloud_backup solidfire\ _enterprise_sds_\&_hci_storage_node fabric_operating_system hci_compute_node_firmware sinec_infrastructure_network_servi… |
SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c. |
NVD-CWE-noinfo
|
CVE-2020-13631 | 2024-11-21 14:01 | 2020-05-28 | Show | GitHub Exploit DB Packet Storm |