|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 28, 2026, 10 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 228051 | 4.3 | 警告 | TYPO3 Association | - | TYPO3 の t3lib_div::quoteJSvalue API 関数におけるクロスサイトスクリプティングの脆弱性 |
CWE-352
同一生成元ポリシー違反 |
CVE-2009-3633 | 2012-12-20 19:28 | 2009-11-2 | Show | GitHub Exploit DB Packet Storm |
| 228052 | 6.5 | 警告 | TYPO3 Association | - | TYPO3 の Frontend Editing サブコンポーネントにおける SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-3632 | 2012-12-20 19:28 | 2009-11-2 | Show | GitHub Exploit DB Packet Storm |
| 228053 | 8.5 | 危険 | TYPO3 Association | - | TYPO3 の Backend サブコンポーネントにおける任意のコマンドを実行される脆弱性 |
CWE-94
コード・インジェクション |
CVE-2009-3631 | 2012-12-20 19:28 | 2009-11-2 | Show | GitHub Exploit DB Packet Storm |
| 228054 | 5.5 | 警告 | TYPO3 Association | - | TYPO3 の Backend サブコンポーネントにおける任意の Web サイトを配置される脆弱性 |
CWE-Other
その他 |
CVE-2009-3630 | 2012-12-20 19:28 | 2009-11-2 | Show | GitHub Exploit DB Packet Storm |
| 228055 | 3.5 | 注意 | TYPO3 Association | - | TYPO3 の Backend サブコンポーネントにおけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-3629 | 2012-12-20 19:28 | 2009-11-2 | Show | GitHub Exploit DB Packet Storm |
| 228056 | 4 | 警告 | TYPO3 Association | - | TYPO3 の Backend サブコンポーネントにおける暗号鍵を特定される脆弱性 |
CWE-200
情報漏えい |
CVE-2009-3628 | 2012-12-20 19:28 | 2009-11-2 | Show | GitHub Exploit DB Packet Storm |
| 228057 | 7.5 | 危険 | sahana | - | Sahana の www/index.php におけるディレクトリトラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2009-3625 | 2012-12-20 19:28 | 2009-06-25 | Show | GitHub Exploit DB Packet Storm |
| 228058 | 4.3 | 警告 | WordPress.org | - | WordPress の wp-trackback.php におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-310
暗号の問題 |
CVE-2009-3622 | 2012-12-20 19:28 | 2009-10-20 | Show | GitHub Exploit DB Packet Storm |
| 228059 | 5 | 警告 | ViewVC | - | ViewVC における脆弱性 |
CWE-noinfo
情報不足 |
CVE-2009-3619 | 2012-12-20 19:28 | 2009-08-11 | Show | GitHub Exploit DB Packet Storm |
| 228060 | 4.3 | 警告 | ViewVC | - | ViewVC の viewvc.py におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-3618 | 2012-12-20 19:28 | 2009-08-11 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 28, 2026, 4:16 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 317681 | 7.5 |
HIGH
Network |
f5 | nginx_plus | When the NGINX Plus is configured to use the MQTT pre-read module, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Techni… |
CWE-672
Operation on a Resource after Expiration or Release |
CVE-2024-39792 | 2024-08-20 01:20 | 2024-08-15 | Show | GitHub Exploit DB Packet Storm |
| 317682 | 7.5 |
HIGH
Network |
f5 |
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_advanced_web_application_firewall big-ip_analytics big-ip_application_acceleration_manager big-ip_application_secur… |
When a stateless virtual server is configured on BIG-IP system with a High-Speed Bridge (HSB), undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Te… |
NVD-CWE-noinfo
|
CVE-2024-39778 | 2024-08-20 01:20 | 2024-08-15 | Show | GitHub Exploit DB Packet Storm |
| 317683 | 8.8 |
HIGH
Network |
f5 | big-ip_next_central_manager | The Central Manager user session refresh token does not expire when a user logs out. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated |
CWE-613
Insufficient Session Expiration |
CVE-2024-39809 | 2024-08-20 01:19 | 2024-08-15 | Show | GitHub Exploit DB Packet Storm |
| 317684 | 7.5 |
HIGH
Network |
dahuasecurity |
nvr4104-4ks2\/l_firmware nvr4108-4ks2\/l_firmware nvr4116-4ks2\/l_firmware nvr4104-p-4ks2\/l_firmware nvr4108-p-4ks2\/l_firmware nvr4108-8p-4ks2\/l_firmware nvr4116-8p-4ks2\/l_firmw… |
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash. |
NVD-CWE-noinfo
|
CVE-2024-39949 | 2024-08-20 01:18 | 2024-07-31 | Show | GitHub Exploit DB Packet Storm |
| 317685 | 7.8 |
HIGH
Local |
adobe | indesign | InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Ex… |
CWE-787
Out-of-bounds Write |
CVE-2024-39389 | 2024-08-20 01:17 | 2024-08-15 | Show | GitHub Exploit DB Packet Storm |
| 317686 | 7.5 |
HIGH
Network |
dahuasecurity |
nvr4104-4ks2\/l_firmware nvr4108-4ks2\/l_firmware nvr4116-4ks2\/l_firmware nvr4104-p-4ks2\/l_firmware nvr4108-p-4ks2\/l_firmware nvr4108-8p-4ks2\/l_firmware nvr4116-8p-4ks2\/l_firmw… |
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash. |
NVD-CWE-noinfo
|
CVE-2024-39948 | 2024-08-20 01:17 | 2024-07-31 | Show | GitHub Exploit DB Packet Storm |
| 317687 | 6.5 |
MEDIUM
Network |
dahuasecurity |
nvr4104-4ks2\/l_firmware nvr4108-4ks2\/l_firmware nvr4116-4ks2\/l_firmware nvr4104-p-4ks2\/l_firmware nvr4108-p-4ks2\/l_firmware nvr4108-8p-4ks2\/l_firmware nvr4116-8p-4ks2\/l_firmw… |
A vulnerability has been found in Dahua products.After obtaining the ordinary user's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities… |
NVD-CWE-noinfo
|
CVE-2024-39947 | 2024-08-20 01:17 | 2024-07-31 | Show | GitHub Exploit DB Packet Storm |
| 317688 | 4.9 |
MEDIUM
Network |
dahuasecurity |
nvr4104-4ks2\/l_firmware nvr4108-4ks2\/l_firmware nvr4116-4ks2\/l_firmware nvr4104-p-4ks2\/l_firmware nvr4108-p-4ks2\/l_firmware nvr4108-8p-4ks2\/l_firmware nvr4116-8p-4ks2\/l_firmw… |
A vulnerability has been found in Dahua products. After obtaining the administrator's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabiliti… |
NVD-CWE-noinfo
|
CVE-2024-39945 | 2024-08-20 01:17 | 2024-07-31 | Show | GitHub Exploit DB Packet Storm |
| 317689 | 5.3 |
MEDIUM
Network |
online_railway_reservation_system_project | online_railway_reservation_system | A vulnerability was found in CodeAstro Online Railway Reservation System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/assets/. The manipulation… |
NVD-CWE-Other
|
CVE-2024-7912 | 2024-08-20 01:16 | 2024-08-19 | Show | GitHub Exploit DB Packet Storm |
| 317690 | 7.2 |
HIGH
Network |
dahuasecurity |
nvr4104-4ks2\/l_firmware nvr4108-4ks2\/l_firmware nvr4116-4ks2\/l_firmware nvr4104-p-4ks2\/l_firmware nvr4108-p-4ks2\/l_firmware nvr4108-8p-4ks2\/l_firmware nvr4116-8p-4ks2\/l_firmw… |
A vulnerability has been found in Dahua products.After obtaining the administrator's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities… |
NVD-CWE-noinfo
|
CVE-2024-39946 | 2024-08-20 01:16 | 2024-07-31 | Show | GitHub Exploit DB Packet Storm |