|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 31, 2026, 4 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 228241 | 4.3 | 警告 | Scriptsez.net | - | Scriptsez.net EPH におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-4384 | 2012-12-20 19:28 | 2009-12-22 | Show | GitHub Exploit DB Packet Storm |
| 228242 | 4.3 | 警告 | phpfaber | - | PHPFABER CMS の module.php におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-4382 | 2012-12-20 19:28 | 2009-12-22 | Show | GitHub Exploit DB Packet Storm |
| 228243 | 4.3 | 警告 | texmedia | - | texmedia Million Pixel Script の index.php におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-4381 | 2012-12-20 19:28 | 2009-12-22 | Show | GitHub Exploit DB Packet Storm |
| 228244 | 7.5 | 危険 | Wafer | - | Valarsoft Webmatic における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4380 | 2012-12-20 19:28 | 2009-12-14 | Show | GitHub Exploit DB Packet Storm |
| 228245 | 4.3 | 警告 | Wafer | - | Valarsoft Webmatic におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-4379 | 2012-12-20 19:28 | 2009-12-14 | Show | GitHub Exploit DB Packet Storm |
| 228246 | 4.3 | 警告 | Wireshark | - | Windows 上で稼動している Wireshark の IPMI 解析子におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-Other
その他 |
CVE-2009-4378 | 2012-12-20 19:28 | 2009-12-17 | Show | GitHub Exploit DB Packet Storm |
| 228247 | 9.3 | 危険 | Wireshark | - | Wireshark の Daintree SNA ファイルパーサーにおけるバッファオーバーフローの脆弱性 |
CWE-119
バッファエラー |
CVE-2009-4376 | 2012-12-20 19:28 | 2009-12-4 | Show | GitHub Exploit DB Packet Storm |
| 228248 | 6.8 | 警告 | Sitecore | - | Sitecore Staging Module の Staging Webservice における認証を回避される脆弱性 |
CWE-287
不適切な認証 |
CVE-2009-4367 | 2012-12-20 19:28 | 2009-12-21 | Show | GitHub Exploit DB Packet Storm |
| 228249 | 4.3 | 警告 | Scriptsez.net | - | ScriptsEz Ez Blog の index.php におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-4366 | 2012-12-20 19:28 | 2009-12-21 | Show | GitHub Exploit DB Packet Storm |
| 228250 | 4.3 | 警告 | Scriptsez.net | - | ScriptsEz Ez Blog の admin.php におけるクロスサイトリクエストフォージェリの脆弱性 |
CWE-352
同一生成元ポリシー違反 |
CVE-2009-4365 | 2012-12-20 19:28 | 2009-12-21 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 31, 2026, 4:16 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 194821 | 9.1 |
CRITICAL
Network |
apache netapp debian oracle |
xmlbeans snap_creator_framework snapmanager oncommand_unified_manager_core_package debian_linux peoplesoft_enterprise_peopletools middleware_common_libraries_and_tools |
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion att… |
CWE-776
XML Entity Expansion |
CVE-2021-23926 | 2024-11-21 14:52 | 2021-01-15 | Show | GitHub Exploit DB Packet Storm |
| 194822 | 5.9 |
MEDIUM
Network |
apache debian oracle |
tomcat debian_linux agile_plm |
When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to … |
CWE-706
Use of Incorrectly-Resolved Name or Reference |
CVE-2021-24122 | 2024-11-21 14:52 | 2021-01-15 | Show | GitHub Exploit DB Packet Storm |
| 194823 | 7.5 |
HIGH
Network |
owasp | json-sanitizer | OWASP json-sanitizer before 1.2.2 can output invalid JSON or throw an undeclared exception for crafted input. This may lead to denial of service if the application is not prepared to handle these sit… |
NVD-CWE-noinfo
|
CVE-2021-23900 | 2024-11-21 14:52 | 2021-01-14 | Show | GitHub Exploit DB Packet Storm |
| 194824 | 9.8 |
CRITICAL
Network |
owasp | json-sanitizer | OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allows an attacker to inject arbitrary HTML or XML into embedding documents. |
CWE-611
XXE |
CVE-2021-23899 | 2024-11-21 14:52 | 2021-01-14 | Show | GitHub Exploit DB Packet Storm |
| 194825 | 6.1 |
MEDIUM
Network |
open-xchange | open-xchange_appsuite | OX App Suite through 7.10.4 allows XSS via the subject of a task. |
CWE-79
Cross-site Scripting |
CVE-2021-23936 | 2024-11-21 14:52 | 2021-01-13 | Show | GitHub Exploit DB Packet Storm |
| 194826 | 6.1 |
MEDIUM
Network |
open-xchange | open-xchange_appsuite | OX App Suite through 7.10.4 allows XSS via an appointment in which the location contains JavaScript code. |
CWE-79
Cross-site Scripting |
CVE-2021-23935 | 2024-11-21 14:52 | 2021-01-13 | Show | GitHub Exploit DB Packet Storm |
| 194827 | 6.1 |
MEDIUM
Network |
open-xchange | open-xchange_appsuite | OX App Suite through 7.10.4 allows XSS via a contact whose name contains JavaScript code. |
CWE-79
Cross-site Scripting |
CVE-2021-23934 | 2024-11-21 14:52 | 2021-01-13 | Show | GitHub Exploit DB Packet Storm |
| 194828 | 6.1 |
MEDIUM
Network |
open-xchange | open-xchange_appsuite | OX App Suite through 7.10.4 allows XSS via JavaScript in a Note referenced by a mail:// URL. |
CWE-79
Cross-site Scripting |
CVE-2021-23933 | 2024-11-21 14:52 | 2021-01-13 | Show | GitHub Exploit DB Packet Storm |
| 194829 | 6.1 |
MEDIUM
Network |
open-xchange | open-xchange_appsuite | OX App Suite through 7.10.4 allows XSS via an inline image with a crafted filename. |
CWE-79
Cross-site Scripting |
CVE-2021-23932 | 2024-11-21 14:52 | 2021-01-13 | Show | GitHub Exploit DB Packet Storm |
| 194830 | 6.1 |
MEDIUM
Network |
open-xchange | open-xchange_appsuite | OX App Suite through 7.10.4 allows XSS via an inline binary file. |
CWE-79
Cross-site Scripting |
CVE-2021-23931 | 2024-11-21 14:52 | 2021-01-13 | Show | GitHub Exploit DB Packet Storm |