|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 11, 2026, 6:01 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 226461 | 7.5 | 危険 | torrenttrader | - | TorrentTrader Classic の account-recover.php におけるパスワードを取得される脆弱性 |
CWE-255
証明書・パスワード管理 |
CVE-2009-2158 | 2012-12-20 19:10 | 2009-06-22 | Show | GitHub Exploit DB Packet Storm |
| 226462 | 6.5 | 警告 | torrenttrader | - | TorrentTrader Classic における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-2157 | 2012-12-20 19:10 | 2009-06-22 | Show | GitHub Exploit DB Packet Storm |
| 226463 | 3.5 | 注意 | torrenttrader | - | TorrentTrader Classic におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-2156 | 2012-12-20 19:10 | 2009-06-22 | Show | GitHub Exploit DB Packet Storm |
| 226464 | 4.3 | 警告 | Zoho Corporation | - | WebNMS Free の report/ReportViewAction.do におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-2155 | 2012-12-20 19:10 | 2009-06-22 | Show | GitHub Exploit DB Packet Storm |
| 226465 | 6.8 | 警告 | sappy.dk | - | Impleo Music Collection の admin/login.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-2154 | 2012-12-20 19:10 | 2009-06-22 | Show | GitHub Exploit DB Packet Storm |
| 226466 | 4.3 | 警告 | sappy.dk | - | Impleo Music Collection の index.php におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-2153 | 2012-12-20 19:10 | 2009-06-22 | Show | GitHub Exploit DB Packet Storm |
| 226467 | 7.5 | 危険 | phpwebthings | - | phpWebThings の fdown.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-2147 | 2012-12-20 19:10 | 2009-06-22 | Show | GitHub Exploit DB Packet Storm |
| 226468 | 6 | 警告 | SugarCRM | - | Sugar Community Edition の Emails モジュールにおける任意のコードを実行される脆弱性 |
CWE-Other
その他 |
CVE-2009-2146 | 2012-12-20 19:10 | 2009-06-22 | Show | GitHub Exploit DB Packet Storm |
| 226469 | 7.5 | 危険 | zipstore | - | Zip Store Chat の admin/index.asp における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-2142 | 2012-12-20 19:10 | 2009-06-22 | Show | GitHub Exploit DB Packet Storm |
| 226470 | 4.3 | 警告 | tbdev | - | TBDev.NET におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-2141 | 2012-12-20 19:10 | 2009-06-22 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 12, 2026, 5:06 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 210661 | 8.2 |
HIGH
Local |
intel |
s2600stqr_firmware s2600stbr_firmware s2600bpsr_firmware s2600bpbr_firmware s2600bpqr_firmware s2600wftr_firmware s2600wf0r_firmware s2600wfqr_firmware |
Improper input validation in BIOS firmware for Intel(R) Server Board Families S2600ST, S2600BP and S2600WF may allow a privileged user to potentially enable escalation of privilege via local access. |
CWE-20
Improper Input Validation |
CVE-2020-12299 | 2024-11-21 13:59 | 2020-08-13 | Show | GitHub Exploit DB Packet Storm |
| 210662 | 8.2 |
HIGH
Local |
intel |
s2600cw2_firmware s2600cw2s_firmware s2600cwt_firmware s2600cwts_firmware s2600cw2r_firmware s2600cw2sr_firmware s2600cwtr_firmware s2600cwtsr_firmware s2600kp_firmware s26… |
Uninitialized pointer in BIOS firmware for Intel(R) Server Board Families S2600CW, S2600KP, S2600TP, and S2600WT may allow a privileged user to potentially enable escalation of privilege via local ac… |
CWE-824
Access of Uninitialized Pointer |
CVE-2020-12300 | 2024-11-21 13:59 | 2020-08-13 | Show | GitHub Exploit DB Packet Storm |
| 210663 | 7.8 |
HIGH
Local |
intel | distribution_of_openvino_toolkit | Incorrect permissions in the Intel(R) Distribution of OpenVINO(TM) Toolkit before version 2020.2 may allow an authenticated user to potentially enable escalation of privilege via local access. |
CWE-276
Incorrect Default Permissions |
CVE-2020-12287 | 2024-11-21 13:59 | 2020-08-13 | Show | GitHub Exploit DB Packet Storm |
| 210664 | 9.8 |
CRITICAL
Network |
stengg | vpncrypt_m10_firmware | The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows command injection via a text field, which allow full control over this module's Operating System. |
CWE-78
OS Command |
CVE-2020-12107 | 2024-11-21 13:59 | 2020-08-13 | Show | GitHub Exploit DB Packet Storm |
| 210665 | 9.8 |
CRITICAL
Network |
stengg | vpncrypt_m10_firmware | The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to several critical Administrative functions such as, changing credentials of the Admini… |
CWE-306
Missing Authentication for Critical Function |
CVE-2020-12106 | 2024-11-21 13:59 | 2020-08-13 | Show | GitHub Exploit DB Packet Storm |
| 210666 | 7.5 |
HIGH
Network |
dovecot debian fedoraproject canonical |
dovecot debian_linux fedora ubuntu_linux |
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply ne… |
CWE-674
Uncontrolled Recursion |
CVE-2020-12100 | 2024-11-21 13:59 | 2020-08-13 | Show | GitHub Exploit DB Packet Storm |
| 210667 | 7.5 |
HIGH
Network |
apache |
wicket fortress |
By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually r… |
CWE-552
Files or Directories Accessible to External Parties |
CVE-2020-11976 | 2024-11-21 13:59 | 2020-08-12 | Show | GitHub Exploit DB Packet Storm |
| 210668 | 7.5 |
HIGH
Network |
apache netapp canonical opensuse debian fedoraproject oracle |
http_server clustered_data_ontap ubuntu_linux leap debian_linux fedora instantis_enterprisetrack hyperion_infrastructure_technology enterprise_manager_ops_center communicat… |
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing con… |
CWE-444
HTTP Request Smuggling |
CVE-2020-11993 | 2024-11-21 13:59 | 2020-08-8 | Show | GitHub Exploit DB Packet Storm |
| 210669 | 5.3 |
MEDIUM
Network |
apache | http_server | IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for lo… |
CWE-345
Insufficient Verification of Data Authenticity |
CVE-2020-11985 | 2024-11-21 13:59 | 2020-08-8 | Show | GitHub Exploit DB Packet Storm |
| 210670 | 9.8 |
CRITICAL
Network |
apache netapp canonical debian fedoraproject opensuse oracle |
http_server clustered_data_ontap ubuntu_linux debian_linux fedora leap instantis_enterprisetrack hyperion_infrastructure_technology enterprise_manager_ops_center communicat… |
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE |
CWE-120
Classic Buffer Overflow |
CVE-2020-11984 | 2024-11-21 13:59 | 2020-08-8 | Show | GitHub Exploit DB Packet Storm |