|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 6, 2026, 6 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 228691 | 7.5 | 危険 | VirtueMart | - | VirtueMart の index.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4430 | 2012-12-20 19:28 | 2009-12-28 | Show | GitHub Exploit DB Packet Storm |
| 228692 | 7.5 | 危険 | weentech | - | weenCompany の index.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4423 | 2012-12-20 19:28 | 2009-12-24 | Show | GitHub Exploit DB Packet Storm |
| 228693 | 5 | 警告 | Zend Technologies Ltd. | - | Zend Framework の Zend_Log_Writer_Mail クラスにおける任意の電子メールメッセージを送信される脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2009-4417 | 2012-12-20 19:28 | 2009-12-24 | Show | GitHub Exploit DB Packet Storm |
| 228694 | 4.3 | 警告 | phpgroupware | - | phpGroupWare の login.php におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-4416 | 2012-12-20 19:28 | 2009-12-24 | Show | GitHub Exploit DB Packet Storm |
| 228695 | 7.5 | 危険 | phpgroupware | - | phpGroupWare におけるディレクトリトラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2009-4415 | 2012-12-20 19:28 | 2009-12-24 | Show | GitHub Exploit DB Packet Storm |
| 228696 | 6.8 | 警告 | phpgroupware | - | phpGroupWare の phpgwapi /inc/class.auth_sql.inc.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4414 | 2012-12-20 19:28 | 2009-12-24 | Show | GitHub Exploit DB Packet Storm |
| 228697 | 5 | 警告 | pps.jussieu | - | Polipo の client.c におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-189
数値処理の問題 |
CVE-2009-4413 | 2012-12-20 19:28 | 2009-12-24 | Show | GitHub Exploit DB Packet Storm |
| 228698 | 6 | 警告 | s9y | - | Serendipity における任意のコードを実行される脆弱性 |
CWE-Other
その他 |
CVE-2009-4412 | 2012-12-20 19:28 | 2009-12-21 | Show | GitHub Exploit DB Packet Storm |
| 228699 | 3.7 | 注意 | xfs | - | XFS acl の setfacl および getfacl コマンドにおける任意のファイルなど対する ACL を変更される脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2009-4411 | 2012-12-20 19:28 | 2009-12-24 | Show | GitHub Exploit DB Packet Storm |
| 228700 | 4.3 | 警告 | pyforum | - | PyForum および zForum の models.parser におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-4408 | 2012-12-20 19:28 | 2009-12-23 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 7, 2026, 4:13 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 194431 | 6.1 |
MEDIUM
Network |
zettlr | zettlr | No filtering of cross-site scripting (XSS) payloads in the markdown-editor in Zettlr 1.8.7 allows attackers to perform remote code execution via a crafted file. |
CWE-79
Cross-site Scripting |
CVE-2021-26835 | 2024-11-21 14:56 | 2021-06-18 | Show | GitHub Exploit DB Packet Storm |
| 194432 | 5.4 |
MEDIUM
Network |
znote | znote | A cross-site scripting (XSS) vulnerability exists in Znote 0.5.2. An attacker can insert payloads, and the code execution will happen immediately on markdown view mode. |
CWE-79
Cross-site Scripting |
CVE-2021-26834 | 2024-11-21 14:56 | 2021-06-18 | Show | GitHub Exploit DB Packet Storm |
| 194433 | 7.5 |
HIGH
Network |
hitachienergy | esoms | Information Exposure vulnerability in Hitachi ABB Power Grids eSOMS allows unauthorized user to gain access to report data if the URL used to access the report is discovered. This issue affects: Hita… |
CWE-863
Incorrect Authorization |
CVE-2021-26845 | 2024-11-21 14:56 | 2021-06-15 | Show | GitHub Exploit DB Packet Storm |
| 194434 | 5.4 |
MEDIUM
Network |
openplcproject | scadabr | OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm. |
CWE-79
Cross-site Scripting |
CVE-2021-26829 | 2024-11-21 14:56 | 2021-06-11 | Show | GitHub Exploit DB Packet Storm |
| 194435 | 8.8 |
HIGH
Network |
openplcproject | scadabr | OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm. |
CWE-434
Unrestricted Upload of File with Dangerous Type |
CVE-2021-26828 | 2024-11-21 14:56 | 2021-06-11 | Show | GitHub Exploit DB Packet Storm |
| 194436 | 9.8 |
CRITICAL
Network |
apache debian fedoraproject oracle netapp |
http_server debian_linux fedora instantis_enterprisetrack enterprise_manager_ops_center zfs_storage_appliance_kit secure_backup cloud_backup |
In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow |
CWE-787
Out-of-bounds Write |
CVE-2021-26691 | 2024-11-21 14:56 | 2021-06-10 | Show | GitHub Exploit DB Packet Storm |
| 194437 | 7.5 |
HIGH
Network |
apache debian fedoraproject oracle |
http_server debian_linux fedora instantis_enterprisetrack enterprise_manager_ops_center zfs_storage_appliance_kit |
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service |
CWE-476
NULL Pointer Dereference |
CVE-2021-26690 | 2024-11-21 14:56 | 2021-06-10 | Show | GitHub Exploit DB Packet Storm |
| 194438 | 5.5 |
MEDIUM
Local |
xen arm broadcom intel fedoraproject |
xen cortex-a72 bcm2711 core_i7-7700k xeon_silver_4214 core_i9-9900k core_i7-10700k fedora |
Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause… |
CWE-203
Information Exposure Through Discrepancy |
CVE-2021-26314 | 2024-11-21 14:56 | 2021-06-9 | Show | GitHub Exploit DB Packet Storm |
| 194439 | 5.5 |
MEDIUM
Local |
xen arm broadcom intel debian |
xen cortex-a72 bcm2711 core_i7-7700k xeon_silver_4214 core_i9-9900k core_i7-10700k debian_linux |
Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorre… |
CWE-203
Information Exposure Through Discrepancy |
CVE-2021-26313 | 2024-11-21 14:56 | 2021-06-9 | Show | GitHub Exploit DB Packet Storm |
| 194440 | 7.1 |
HIGH
Network |
microsoft |
sharepoint_foundation sharepoint_enterprise_server sharepoint_server |
Microsoft SharePoint Server Remote Code Execution Vulnerability |
NVD-CWE-noinfo
|
CVE-2021-26420 | 2024-11-21 14:56 | 2021-06-9 | Show | GitHub Exploit DB Packet Storm |