|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 28, 2026, 6 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 228971 | 6.8 | 警告 | 日立 | - | 日立の Windows 版 COBOL GUIオプションの開発環境における任意のコードを実行される脆弱性 |
CWE-noinfo
情報不足 |
CVE-2012-4274 | 2013-06-26 14:16 | 2012-04-27 | Show | GitHub Exploit DB Packet Storm |
| 228972 | 4.3 | 警告 | Nathan Haug | - | Drupal 用 Webform モジュールにおけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2013-2129 | 2013-06-26 14:03 | 2013-05-29 | Show | GitHub Exploit DB Packet Storm |
| 228973 | 4.3 | 警告 | Yoran Brault | - | Drupal 用 Filebrowser モジュールにおけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2013-2036 | 2013-06-26 14:00 | 2013-04-30 | Show | GitHub Exploit DB Packet Storm |
| 228974 | 4.3 | 警告 | Alexey Sukhotin | - | Drupal 用 elFinder file manager モジュールにおけるクロスサイトリクエストフォージェリの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2013-1972 | 2013-06-26 14:00 | 2013-04-16 | Show | GitHub Exploit DB Packet Storm |
| 228975 | 4.3 | 警告 | drunomics | - | Drupal 用 Rules モジュールにおけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2013-1906 | 2013-06-26 13:57 | 2013-03-27 | Show | GitHub Exploit DB Packet Storm |
| 228976 | 4.3 | 警告 | Opera Software ASA | - | Opera におけるアドレスバー詐称の脆弱性 |
CWE-Other
その他 |
CVE-2012-4010 | 2013-06-26 13:47 | 2012-08-30 | Show | GitHub Exploit DB Packet Storm |
| 228977 | 7.5 | 危険 | D-Link Systems, Inc. | - | D-Link DIR-685 Xtreme N Storage Router の暗号化通信に脆弱性 |
CWE-310
暗号の問題 |
CVE-2011-4507 | 2013-06-26 13:44 | 2011-10-11 | Show | GitHub Exploit DB Packet Storm |
| 228978 | 2.6 | 注意 | サイボウズ | - | サイボウズLive for Android における WebView クラスに関する脆弱性 |
CWE-Other
その他 |
CVE-2013-3647 | 2013-06-26 13:41 | 2013-06-18 | Show | GitHub Exploit DB Packet Storm |
| 228979 | 3.3 | 注意 | ASUSTeK Computer Inc. | - | RT-N56U における管理パスワード漏えいの脆弱性 |
CWE-200
情報漏えい |
CVE-2011-4497 | 2013-06-26 13:41 | 2011-08-26 | Show | GitHub Exploit DB Packet Storm |
| 228980 | 5.8 | 警告 | サイボウズ | - | サイボウズLive for Android において任意の Java のメソッドが実行される脆弱性 |
CWE-DesignError
|
CVE-2013-3646 | 2013-06-26 13:39 | 2013-06-18 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 29, 2026, 4:19 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 207021 | 7.5 |
HIGH
Network |
rubyonrails debian opensuse |
rails debian_linux leap backports_sle |
A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters. |
CWE-502
Deserialization of Untrusted Data |
CVE-2020-8164 | 2024-11-21 14:38 | 2020-06-20 | Show | GitHub Exploit DB Packet Storm |
| 207022 | 7.5 |
HIGH
Network |
rubyonrails debian |
rails debian_linux |
A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be m… |
CWE-434
Unrestricted Upload of File with Dangerous Type |
CVE-2020-8162 | 2024-11-21 14:38 | 2020-06-20 | Show | GitHub Exploit DB Packet Storm |
| 207023 | 5.7 |
MEDIUM
Network |
openmicroscopy | omero.web | OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a user into clicking a malicious link in OMERO.web, … |
CWE-200
Information Exposure |
CVE-2020-7932 | 2024-11-21 14:38 | 2020-06-18 | Show | GitHub Exploit DB Packet Storm |
| 207024 | 6.5 |
MEDIUM
Network |
open-xchange | open-xchange_appsuite | OX App Suite through 7.10.3 allows XXE attacks. |
CWE-611
XXE |
CVE-2020-8541 | 2024-11-21 14:38 | 2020-06-16 | Show | GitHub Exploit DB Packet Storm |
| 207025 | 6.7 |
MEDIUM
Local |
synaptics | smart_audio_uwp | An unquoted search path vulnerability was reported in versions prior to 1.0.83.0 of the Synaptics Smart Audio UWP app associated with the DCHU audio drivers on Lenovo platforms that could allow an ad… |
CWE-428
Unquoted Search Path or Element |
CVE-2020-8337 | 2024-11-21 14:38 | 2020-06-10 | Show | GitHub Exploit DB Packet Storm |
| 207026 | 6.8 |
MEDIUM
Physics |
lenovo |
thinkpad_e14_firmware thinkpad_e15_firmware thinkpad_r14_firmware thinkpad_s3_gen_2_firmware thinkpad_e490s_firmware thinkpad_s3_firmware thinkpad_e490_firmware thinkpad_e590_fir… |
Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmware in flash. |
NVD-CWE-noinfo
|
CVE-2020-8336 | 2024-11-21 14:38 | 2020-06-10 | Show | GitHub Exploit DB Packet Storm |
| 207027 | 6.8 |
MEDIUM
Physics |
lenovo |
thinkpad_t495s_firmware thinkpad_x395_firmware thinkpad_t495_firmware thinkpad_a485_firmware thinkpad_a285_firmware thinkpad_a475_firmware thinkpad_a275_firmware |
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T495s, X395, T495, A485, A285, A475, A275 which may allow for unauthorized access. |
CWE-754
Improper Check for Unusual or Exceptional Conditions |
CVE-2020-8334 | 2024-11-21 14:38 | 2020-06-10 | Show | GitHub Exploit DB Packet Storm |
| 207028 | 6.7 |
MEDIUM
Local |
lenovo |
330-14ast_firmware 330-15ast_firmware 330-17ast_firmware 340c-15api_firmware 340c-15ast_firmware 720s_touch-15ikb_firmware 720s-15ikb_firmware 730s-13iwl_firmware c640-iml_fir… |
A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution. |
NVD-CWE-noinfo
|
CVE-2020-8323 | 2024-11-21 14:38 | 2020-06-10 | Show | GitHub Exploit DB Packet Storm |
| 207029 | 6.7 |
MEDIUM
Local |
lenovo |
330-14ast_firmware 330-15ast_firmware 330-17ast_firmware 340c-15api_firmware 340c-15ast_firmware 720s_touch-15ikb_firmware 720s-15ikb_firmware 730s-13iwl_firmware c640-iml_fir… |
A potential vulnerability in the SMI callback function used in the Legacy USB driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution. |
NVD-CWE-noinfo
|
CVE-2020-8322 | 2024-11-21 14:38 | 2020-06-10 | Show | GitHub Exploit DB Packet Storm |
| 207030 | 6.7 |
MEDIUM
Local |
lenovo |
130-14ast_firmware 130-14ikb_firmware 130-15ast_firmware 130-15ikb_firmware 320c-15ikb_firmware 330-14igm_firmware 330-14ikb_firmware 330-14ikbr_firmware 330-15arr_firmware | A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution. |
NVD-CWE-noinfo
|
CVE-2020-8321 | 2024-11-21 14:38 | 2020-06-10 | Show | GitHub Exploit DB Packet Storm |