|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 1, 2026, 6 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 228371 | 7.5 | 危険 | santostefano giovanni | - | ToyLog の read.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-3750 | 2012-12-20 19:28 | 2009-10-22 | Show | GitHub Exploit DB Packet Storm |
| 228372 | 5 | 警告 | ウェブセンス | - | Websense Personal Email Manager および Email Security の Web Administrator サービスにおけるサービス運用妨害 (DoS) の脆弱性 |
CWE-Other
その他 |
CVE-2009-3749 | 2012-12-20 19:28 | 2009-10-22 | Show | GitHub Exploit DB Packet Storm |
| 228373 | 4.3 | 警告 | ウェブセンス | - | Websense Personal Email Manager および Email Security の Web Administrator におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-3748 | 2012-12-20 19:28 | 2009-10-22 | Show | GitHub Exploit DB Packet Storm |
| 228374 | 4.3 | 警告 | tbmnet | - | TBmnetCMS の index.php におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-3747 | 2012-12-20 19:28 | 2009-10-22 | Show | GitHub Exploit DB Packet Storm |
| 228375 | 10 | 危険 | riorey | - | RioRey RIOS における権限を取得される脆弱性 |
CWE-255
証明書・パスワード管理 |
CVE-2009-3710 | 2012-12-20 19:28 | 2009-10-16 | Show | GitHub Exploit DB Packet Storm |
| 228376 | 5 | 警告 | zoiper | - | ZoIPer におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-Other
その他 |
CVE-2009-3704 | 2012-12-20 19:28 | 2009-10-16 | Show | GitHub Exploit DB Packet Storm |
| 228377 | 7.5 | 危険 | php-calendar project | - | PHP-Calendar における絶対パストラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2009-3702 | 2012-12-20 19:28 | 2009-12-22 | Show | GitHub Exploit DB Packet Storm |
| 228378 | 5 | 警告 | squidguard | - | squidGuard の sgLog.c におけるバッファオーバーフローの脆弱性 |
CWE-119
バッファエラー |
CVE-2009-3700 | 2012-12-20 19:28 | 2009-10-28 | Show | GitHub Exploit DB Packet Storm |
| 228379 | 7.5 | 危険 | The phpMyAdmin Project | - | phpMyAdmin の PDF スキーマジェネレータ機能における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-3697 | 2012-12-20 19:28 | 2009-10-13 | Show | GitHub Exploit DB Packet Storm |
| 228380 | 4.3 | 警告 | The phpMyAdmin Project | - | phpMyAdmin におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-3696 | 2012-12-20 19:28 | 2009-10-13 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 1, 2026, 4:12 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 194781 | 5.4 |
MEDIUM
Network |
enviragallery | envira_gallery | Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did not properly sanitise the images metadata (namely title) before outputting them… |
CWE-79
Cross-site Scripting |
CVE-2021-24126 | 2024-11-21 14:52 | 2021-03-19 | Show | GitHub Exploit DB Packet Storm |
| 194782 | 7.2 |
HIGH
Network |
contact_form_submissions_project | contact_form_submissions | Unvalidated input in the Contact Form Submissions WordPress plugin before 1.7.1, could lead to SQL injection in the wpcf7_contact_form GET parameter when submitting a filter request as a high privile… |
CWE-89
SQL Injection |
CVE-2021-24125 | 2024-11-21 14:52 | 2021-03-19 | Show | GitHub Exploit DB Packet Storm |
| 194783 | 6.1 |
MEDIUM
Network |
terryl | wp_shieldon | Unvalidated input and lack of output encoding in the WP Shieldon WordPress plugin, version 1.6.3 and below, leads to Unauthenticated Reflected Cross-Site Scripting (XSS) when the CAPTCHA page is show… |
CWE-79
Cross-site Scripting |
CVE-2021-24124 | 2024-11-21 14:52 | 2021-03-19 | Show | GitHub Exploit DB Packet Storm |
| 194784 | 7.2 |
HIGH
Network |
blubrry | powerpress | Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.8, did not verify some of the uploaded feed images (such as the ones from Podcast Artwork section), allowing high privile… |
CWE-434
Unrestricted Upload of File with Dangerous Type |
CVE-2021-24123 | 2024-11-21 14:52 | 2021-03-19 | Show | GitHub Exploit DB Packet Storm |
| 194785 | 7.5 |
HIGH
Network |
proxygen mvfst |
A packet of death scenario is possible in mvfst via a specially crafted message during a QUIC session, which causes a crash via a failed assertion. Per QUIC specification, this particular message sho… |
CWE-617
Reachable Assertion |
CVE-2021-24029 | 2024-11-21 14:52 | 2021-03-16 | Show | GitHub Exploit DB Packet Storm | |
| 194786 | 7.8 |
HIGH
Local |
microsoft | high_efficiency_video_coding | HEVC Video Extensions Remote Code Execution Vulnerability |
NVD-CWE-noinfo
|
CVE-2021-24110 | 2024-11-21 14:52 | 2021-03-12 | Show | GitHub Exploit DB Packet Storm |
| 194787 | 7.8 |
HIGH
Local |
microsoft |
office 365_apps |
Microsoft Office Remote Code Execution Vulnerability |
NVD-CWE-noinfo
|
CVE-2021-24108 | 2024-11-21 14:52 | 2021-03-12 | Show | GitHub Exploit DB Packet Storm |
| 194788 | 5.5 |
MEDIUM
Local |
microsoft |
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_7 windows_rt_8.1 windows_server_2019 |
Windows Event Tracing Information Disclosure Vulnerability |
NVD-CWE-noinfo
|
CVE-2021-24107 | 2024-11-21 14:52 | 2021-03-12 | Show | GitHub Exploit DB Packet Storm |
| 194789 | 4.6 |
MEDIUM
Local |
microsoft |
sharepoint_foundation sharepoint_enterprise_server sharepoint_server |
Microsoft SharePoint Server Spoofing Vulnerability |
NVD-CWE-noinfo
|
CVE-2021-24104 | 2024-11-21 14:52 | 2021-03-12 | Show | GitHub Exploit DB Packet Storm |
| 194790 | 7.0 |
HIGH
Local |
microsoft |
windows_10 windows_server_2019 windows_server_2016 |
DirectX Elevation of Privilege Vulnerability |
CWE-269
Improper Privilege Management |
CVE-2021-24095 | 2024-11-21 14:52 | 2021-03-12 | Show | GitHub Exploit DB Packet Storm |