|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 8, 2026, 2:21 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 228311 | 4.3 | 警告 | Real Time Logic | - | BarracudaDrive Web Server におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2007-6316 | 2012-12-20 18:34 | 2007-12-11 | Show | GitHub Exploit DB Packet Storm |
| 228312 | 4 | 警告 | Real Time Logic | - | Group Chat の BarracudaDrive Web Server におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-119
バッファエラー |
CVE-2007-6315 | 2012-12-20 18:34 | 2007-12-11 | Show | GitHub Exploit DB Packet Storm |
| 228313 | 5 | 警告 | Real Time Logic | - | BarracudaDrive Web Server における Web スクリプトに対するソースコードを読まれる脆弱性 |
CWE-20
不適切な入力確認 |
CVE-2007-6314 | 2012-12-20 18:34 | 2007-12-11 | Show | GitHub Exploit DB Packet Storm |
| 228314 | 4.3 | 警告 | ウェブセンス | - | Websense Enterprise および Web Security Suite の Web Reporting Tools portal におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2007-6312 | 2012-12-20 18:34 | 2007-12-11 | Show | GitHub Exploit DB Packet Storm |
| 228315 | 4.3 | 警告 | webSPELL | - | webSPELL の index.php におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2007-6309 | 2012-12-20 18:34 | 2007-12-11 | Show | GitHub Exploit DB Packet Storm |
| 228316 | 5 | 警告 | phpmychat | - | phpMyChat の users_popupL.php3 における PHP リモートファイルインクルージョンの脆弱性 |
CWE-94
コード・インジェクション |
CVE-2007-6296 | 2012-12-20 18:34 | 2007-12-10 | Show | GitHub Exploit DB Packet Storm |
| 228317 | 7.5 | 危険 | xigla | - | Xigla Absolute Banner Manager .NET の abm.aspx における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2007-6291 | 2012-12-20 18:34 | 2007-12-10 | Show | GitHub Exploit DB Packet Storm |
| 228318 | 7.5 | 危険 | tecnick.com | - | TCExam における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2007-6288 | 2012-12-20 18:34 | 2007-12-10 | Show | GitHub Exploit DB Packet Storm |
| 228319 | 10 | 危険 | stbernard | - | St. Bernard Open File Manager の Open File Manager service におけるヒープベースのバッファオーバーフローの脆弱性 |
CWE-119
バッファエラー |
CVE-2007-6281 | 2012-12-20 18:34 | 2007-12-19 | Show | GitHub Exploit DB Packet Storm |
| 228320 | 9.3 | 危険 | SonicWALL | - | SonicWALL GLobal VPN Client のコンフィギュレーションファイルにおけるフォーマットストリングの脆弱性 |
CWE-134
書式文字列の問題 |
CVE-2007-6273 | 2012-12-20 18:34 | 2007-12-7 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 8, 2026, 4:54 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 209691 | 7.8 |
HIGH
Local |
wago pepperl-fuchs emerson weidmueller |
fdtcontainer_component pactware rosemount_transmitter_interface_software dtminspector_3 fdtcontainer_application wi_manager io-link_master_firmware |
M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage. |
CWE-502
Deserialization of Untrusted Data |
CVE-2020-12525 | 2024-11-21 13:59 | 2021-01-23 | Show | GitHub Exploit DB Packet Storm |
| 209692 | 4.9 |
MEDIUM
Network |
pepperl-fuchs |
io-link_master_4-eip_firmware io-link_master_8-eip_firmware io-link_master_8-eip-l_firmware io-link_master_dr-8-eip_firmware io-link_master_dr-8-eip-p_firmware io-link_master_dr-8-eip-… |
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a NULL Pointer Dereference that leads to a DoS in discoveryd |
CWE-476
NULL Pointer Dereference |
CVE-2020-12514 | 2024-11-21 13:59 | 2021-01-23 | Show | GitHub Exploit DB Packet Storm |
| 209693 | 8.8 |
HIGH
Network |
pepperl-fuchs |
io-link_master_4-eip_firmware io-link_master_8-eip_firmware io-link_master_8-eip-l_firmware io-link_master_dr-8-eip_firmware io-link_master_dr-8-eip-p_firmware io-link_master_dr-8-eip-… |
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection. |
CWE-78
OS Command |
CVE-2020-12513 | 2024-11-21 13:59 | 2021-01-23 | Show | GitHub Exploit DB Packet Storm |
| 209694 | 5.4 |
MEDIUM
Network |
pepperl-fuchs |
io-link_master_4-eip_firmware io-link_master_8-eip_firmware io-link_master_8-eip-l_firmware io-link_master_dr-8-eip_firmware io-link_master_dr-8-eip-p_firmware io-link_master_dr-8-eip-… |
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting |
CWE-79
Cross-site Scripting |
CVE-2020-12512 | 2024-11-21 13:59 | 2021-01-23 | Show | GitHub Exploit DB Packet Storm |
| 209695 | 8.8 |
HIGH
Network |
pepperl-fuchs |
io-link_master_4-eip_firmware io-link_master_8-eip_firmware io-link_master_8-eip-l_firmware io-link_master_dr-8-eip_firmware io-link_master_dr-8-eip-p_firmware io-link_master_dr-8-eip-… |
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface. |
CWE-352
Origin Validation Error |
CVE-2020-12511 | 2024-11-21 13:59 | 2021-01-23 | Show | GitHub Exploit DB Packet Storm |
| 209696 | 4.3 |
MEDIUM
Network |
apache | guacamole | Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. If multiple users share access to the same connection, those users may be able t… |
CWE-276
Incorrect Default Permissions |
CVE-2020-11997 | 2024-11-21 13:59 | 2021-01-20 | Show | GitHub Exploit DB Packet Storm |
| 209697 | 9.8 |
CRITICAL
Network |
apache | dubbo | A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserializati… |
CWE-502
Deserialization of Untrusted Data |
CVE-2020-11995 | 2024-11-21 13:59 | 2021-01-11 | Show | GitHub Exploit DB Packet Storm |
| 209698 | 9.8 |
CRITICAL
Network |
apache | dolphinscheduler | In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database. |
NVD-CWE-noinfo
|
CVE-2020-11974 | 2024-11-21 13:59 | 2020-12-19 | Show | GitHub Exploit DB Packet Storm |
| 209699 | 6.5 |
MEDIUM
Adjacent |
phoenixcontact | plcnext_firmware | On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS a specially crafted LLDP packet may lead to a high system load in the PROFINET stack. An attacker can cause failure of system ser… |
CWE-20
Improper Input Validation |
CVE-2020-12521 | 2024-11-21 13:59 | 2020-12-18 | Show | GitHub Exploit DB Packet Storm |
| 209700 | 9.8 |
CRITICAL
Network |
phoenixcontact | plcnext_firmware | On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use this vulnerability i.e. to open a reverse shell with root privileges. |
CWE-269
Improper Privilege Management |
CVE-2020-12519 | 2024-11-21 13:59 | 2020-12-18 | Show | GitHub Exploit DB Packet Storm |