|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 1, 2026, 6 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 228131 | 6.8 | 警告 | Ubercart | - | Drupal 用の Ubercart モジュールにおけるクロスサイトリクエストフォージェリの脆弱性 |
CWE-352
同一生成元ポリシー違反 |
CVE-2009-4773 | 2012-12-20 19:28 | 2009-11-18 | Show | GitHub Exploit DB Packet Storm |
| 228132 | 4.3 | 警告 | Ubercart | - | Drupal 用の Ubercart モジュールにおける重要な情報を取得される脆弱性 |
CWE-noinfo
情報不足 |
CVE-2009-4772 | 2012-12-20 19:28 | 2009-11-18 | Show | GitHub Exploit DB Packet Storm |
| 228133 | 5 | 警告 | Ubercart | - | Drupal 用の Ubercart モジュールにおける不特定の "複製操作" を誘発される脆弱性 |
CWE-20
不適切な入力確認 |
CVE-2009-4771 | 2012-12-20 19:28 | 2009-11-18 | Show | GitHub Exploit DB Packet Storm |
| 228134 | 9 | 危険 | Codeorigin | - | Sysax Multi Server におけるディレクトリトラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2009-4790 | 2012-12-20 19:28 | 2010-04-22 | Show | GitHub Exploit DB Packet Storm |
| 228135 | 7.2 | 危険 | tukeva | - | TUKEVA Password Reminder における資格情報を発見される脆弱性 |
CWE-255
証明書・パスワード管理 |
CVE-2009-4781 | 2012-12-20 19:28 | 2010-04-21 | Show | GitHub Exploit DB Packet Storm |
| 228136 | 7.5 | 危険 | robert garrigos | - | NukeHall における PHP リモートファイルインクルージョンの脆弱性 |
CWE-94
コード・インジェクション |
CVE-2009-4779 | 2012-12-20 19:28 | 2010-04-21 | Show | GitHub Exploit DB Packet Storm |
| 228137 | 4.3 | 警告 | Plohni | - | Plohni Shoutbox の index.php におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-4767 | 2012-12-20 19:28 | 2010-04-20 | Show | GitHub Exploit DB Packet Storm |
| 228138 | 5 | 警告 | yasirpro | - | YP Portal MS-Pro Surumu におけるデータベースをダウンロードされる脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2009-4766 | 2012-12-20 19:28 | 2010-04-13 | Show | GitHub Exploit DB Packet Storm |
| 228139 | 6.8 | 警告 | phpmyvisites | - | phpMyVisites に使用されている ClickHeat プラグインにおける脆弱性 |
CWE-noinfo
情報不足 |
CVE-2009-4763 | 2012-12-20 19:28 | 2010-03-30 | Show | GitHub Exploit DB Packet Storm |
| 228140 | 5 | 警告 | Winn GuestBook | - | Winn ASP Guestbook におけるデータベースをダウンロードされる脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2009-4760 | 2012-12-20 19:28 | 2010-03-29 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 2, 2026, 4:18 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 220411 | 8.8 |
HIGH
Network |
libsdl debian opensuse fedoraproject canonical |
simple_directmedia_layer debian_linux leap fedora ubuntu_linux |
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (inside the wNumCoef loop). |
CWE-125
Out-of-bounds Read |
CVE-2019-7573 | 2024-11-21 13:48 | 2019-02-7 | Show | GitHub Exploit DB Packet Storm |
| 220412 | 8.8 |
HIGH
Network |
libsdl debian opensuse canonical fedoraproject |
simple_directmedia_layer debian_linux leap ubuntu_linux fedora |
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c. |
CWE-125
Out-of-bounds Read |
CVE-2019-7572 | 2024-11-21 13:48 | 2019-02-7 | Show | GitHub Exploit DB Packet Storm |
| 220413 | 6.5 |
MEDIUM
Network |
pbootcms | pbootcms | A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI. |
CWE-352
Origin Validation Error |
CVE-2019-7570 | 2024-11-21 13:48 | 2019-02-7 | Show | GitHub Exploit DB Packet Storm |
| 220414 | 8.8 |
HIGH
Network |
wdoyo | doyo | An issue was discovered in DOYO (aka doyocms) 2.3(20140425 update). There is a CSRF vulnerability that can add a super administrator account via admin.php?c=a_adminuser&a=add&run=1. |
CWE-352
Origin Validation Error |
CVE-2019-7569 | 2024-11-21 13:48 | 2019-02-7 | Show | GitHub Exploit DB Packet Storm |
| 220415 | 9.8 |
CRITICAL
Network |
baijiacms_project | baijiacms | An issue was discovered in baijiacms V4 that can result in time-based blind SQL injection to get data via the cate parameter in an index.php?act=index request. |
CWE-89
SQL Injection |
CVE-2019-7568 | 2024-11-21 13:48 | 2019-02-7 | Show | GitHub Exploit DB Packet Storm |
| 220416 | 6.1 |
MEDIUM
Network |
bijiadao | waimai_super_cms | An issue was discovered in Waimai Super Cms 20150505. admin.php?m=Member&a=adminaddsave has XSS via the username or password parameter. |
CWE-79
Cross-site Scripting |
CVE-2019-7567 | 2024-11-21 13:48 | 2019-02-7 | Show | GitHub Exploit DB Packet Storm |
| 220417 | 8.8 |
HIGH
Network |
cszcms | csz_cms | CSZ CMS 1.1.8 has CSRF via admin/users/new/add. |
CWE-352
Origin Validation Error |
CVE-2019-7566 | 2024-11-21 13:48 | 2019-02-7 | Show | GitHub Exploit DB Packet Storm |
| 220418 | 5.5 |
MEDIUM
Local |
boolector_project | boolector | In parser/btorsmt2.c in Boolector 3.0.0, opening a specially crafted input file leads to a use after free in get_failed_assumptions or btor_delete. |
CWE-416
Use After Free |
CVE-2019-7560 | 2024-11-21 13:48 | 2019-02-7 | Show | GitHub Exploit DB Packet Storm |
| 220419 | 5.5 |
MEDIUM
Local |
btor2tools_project | btor2tools | In btor2parser/btor2parser.c in Boolector Btor2Tools before 2019-01-15, opening a specially crafted input file leads to an out of bounds write in pusht_bfr. |
CWE-787
Out-of-bounds Write |
CVE-2019-7559 | 2024-11-21 13:48 | 2019-02-7 | Show | GitHub Exploit DB Packet Storm |
| 220420 | 7.8 |
HIGH
Local |
sqlalchemy debian opensuse redhat oracle |
sqlalchemy debian_linux leap backports_sle enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux communications_operations_monitor |
SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled. |
CWE-89
SQL Injection |
CVE-2019-7548 | 2024-11-21 13:48 | 2019-02-7 | Show | GitHub Exploit DB Packet Storm |