|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 1, 2026, noon
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 228291 | 4.3 | 警告 | サン・マイクロシステムズ | - | Sun Java System Portal Server の Gateway コンポーネントにおけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-4187 | 2012-12-20 19:28 | 2009-12-1 | Show | GitHub Exploit DB Packet Storm |
| 228292 | 4.3 | 警告 | Yahoo! | - | Yahoo! Messenger 用の YahooBridgeLib.dll におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-119
バッファエラー |
CVE-2009-4171 | 2012-12-20 19:28 | 2009-12-2 | Show | GitHub Exploit DB Packet Storm |
| 228293 | 5 | 警告 | roytanck | - | WordPress 用の WP-Cumulus プラグインにおける重要な情報を取得される脆弱性 |
CWE-200
情報漏えい |
CVE-2009-4170 | 2012-12-20 19:28 | 2009-12-2 | Show | GitHub Exploit DB Packet Storm |
| 228294 | 4.3 | 警告 | roytanck | - | WordPress 用の WP-Cumulus プラグインにおけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-4169 | 2012-12-20 19:28 | 2009-09-27 | Show | GitHub Exploit DB Packet Storm |
| 228295 | 4.3 | 警告 | roytanck | - | WordPress、Joomulus モジュール、および Joomla! 用の WP-Cumulus モジュールにおけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-4168 | 2012-12-20 19:28 | 2009-11-15 | Show | GitHub Exploit DB Packet Storm |
| 228296 | 7.5 | 危険 | simple glossar | - | TYPO3 用の simple_glossar エクステンションにおける SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4165 | 2012-12-20 19:28 | 2009-12-2 | Show | GitHub Exploit DB Packet Storm |
| 228297 | 4.3 | 警告 | simple glossar | - | TYPO3 用の simple_glossar エクステンションにおけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-4164 | 2012-12-20 19:28 | 2009-12-2 | Show | GitHub Exploit DB Packet Storm |
| 228298 | 7.5 | 危険 | tw productfinder | - | TYPO3 用の TW Productfinder エクステンションにおける SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4163 | 2012-12-20 19:28 | 2009-12-2 | Show | GitHub Exploit DB Packet Storm |
| 228299 | 7.5 | 危険 | Piwik teethgrinder.co.uk |
- | Piwik などの製品で使用される Open Flash Chart Lug Wyrm Charmer における任意のコードを実行される脆弱性 |
CWE-Other
その他 |
CVE-2009-4140 | 2012-12-20 19:28 | 2009-10-21 | Show | GitHub Exploit DB Packet Storm |
| 228300 | 7.5 | 危険 | Piwik | - | Piwik の core/Cookie.php における任意のコードを実行される脆弱性 |
CWE-20
不適切な入力確認 |
CVE-2009-4137 | 2012-12-20 19:28 | 2009-12-9 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 1, 2026, 4:12 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 194781 | 5.4 |
MEDIUM
Network |
enviragallery | envira_gallery | Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did not properly sanitise the images metadata (namely title) before outputting them… |
CWE-79
Cross-site Scripting |
CVE-2021-24126 | 2024-11-21 14:52 | 2021-03-19 | Show | GitHub Exploit DB Packet Storm |
| 194782 | 7.2 |
HIGH
Network |
contact_form_submissions_project | contact_form_submissions | Unvalidated input in the Contact Form Submissions WordPress plugin before 1.7.1, could lead to SQL injection in the wpcf7_contact_form GET parameter when submitting a filter request as a high privile… |
CWE-89
SQL Injection |
CVE-2021-24125 | 2024-11-21 14:52 | 2021-03-19 | Show | GitHub Exploit DB Packet Storm |
| 194783 | 6.1 |
MEDIUM
Network |
terryl | wp_shieldon | Unvalidated input and lack of output encoding in the WP Shieldon WordPress plugin, version 1.6.3 and below, leads to Unauthenticated Reflected Cross-Site Scripting (XSS) when the CAPTCHA page is show… |
CWE-79
Cross-site Scripting |
CVE-2021-24124 | 2024-11-21 14:52 | 2021-03-19 | Show | GitHub Exploit DB Packet Storm |
| 194784 | 7.2 |
HIGH
Network |
blubrry | powerpress | Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.8, did not verify some of the uploaded feed images (such as the ones from Podcast Artwork section), allowing high privile… |
CWE-434
Unrestricted Upload of File with Dangerous Type |
CVE-2021-24123 | 2024-11-21 14:52 | 2021-03-19 | Show | GitHub Exploit DB Packet Storm |
| 194785 | 7.5 |
HIGH
Network |
proxygen mvfst |
A packet of death scenario is possible in mvfst via a specially crafted message during a QUIC session, which causes a crash via a failed assertion. Per QUIC specification, this particular message sho… |
CWE-617
Reachable Assertion |
CVE-2021-24029 | 2024-11-21 14:52 | 2021-03-16 | Show | GitHub Exploit DB Packet Storm | |
| 194786 | 7.8 |
HIGH
Local |
microsoft | high_efficiency_video_coding | HEVC Video Extensions Remote Code Execution Vulnerability |
NVD-CWE-noinfo
|
CVE-2021-24110 | 2024-11-21 14:52 | 2021-03-12 | Show | GitHub Exploit DB Packet Storm |
| 194787 | 7.8 |
HIGH
Local |
microsoft |
office 365_apps |
Microsoft Office Remote Code Execution Vulnerability |
NVD-CWE-noinfo
|
CVE-2021-24108 | 2024-11-21 14:52 | 2021-03-12 | Show | GitHub Exploit DB Packet Storm |
| 194788 | 5.5 |
MEDIUM
Local |
microsoft |
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_7 windows_rt_8.1 windows_server_2019 |
Windows Event Tracing Information Disclosure Vulnerability |
NVD-CWE-noinfo
|
CVE-2021-24107 | 2024-11-21 14:52 | 2021-03-12 | Show | GitHub Exploit DB Packet Storm |
| 194789 | 4.6 |
MEDIUM
Local |
microsoft |
sharepoint_foundation sharepoint_enterprise_server sharepoint_server |
Microsoft SharePoint Server Spoofing Vulnerability |
NVD-CWE-noinfo
|
CVE-2021-24104 | 2024-11-21 14:52 | 2021-03-12 | Show | GitHub Exploit DB Packet Storm |
| 194790 | 7.0 |
HIGH
Local |
microsoft |
windows_10 windows_server_2019 windows_server_2016 |
DirectX Elevation of Privilege Vulnerability |
CWE-269
Improper Privilege Management |
CVE-2021-24095 | 2024-11-21 14:52 | 2021-03-12 | Show | GitHub Exploit DB Packet Storm |