|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 28, 2026, 6 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 229291 | 6.8 | 警告 | tbmnet | - | TBmnetCMS の index.php におけるディレクトリトラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2008-6271 | 2012-12-20 19:10 | 2009-02-25 | Show | GitHub Exploit DB Packet Storm |
| 229292 | 7.5 | 危険 | sadi samami | - | WEBBDOMAIN Multi Languages WebShop Online の detail.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-6268 | 2012-12-20 19:10 | 2009-02-25 | Show | GitHub Exploit DB Packet Storm |
| 229293 | 7.5 | 危険 | ultrastats | - | Ultrastats の index.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-6260 | 2012-12-20 19:10 | 2009-02-24 | Show | GitHub Exploit DB Packet Storm |
| 229294 | 4.3 | 警告 | quadcomm | - | QuadComm Q-Shop の search.asp におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2008-6259 | 2012-12-20 19:10 | 2009-02-24 | Show | GitHub Exploit DB Packet Storm |
| 229295 | 7.5 | 危険 | quadcomm | - | QuadComm Q-Shop の users.asp における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-6258 | 2012-12-20 19:10 | 2009-02-24 | Show | GitHub Exploit DB Packet Storm |
| 229296 | 6.5 | 警告 | vBulletin Solutions, Inc. | - | vBulletin の admincp/admincalendar.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-6256 | 2012-12-20 19:10 | 2009-02-24 | Show | GitHub Exploit DB Packet Storm |
| 229297 | 6.5 | 警告 | vBulletin Solutions, Inc. | - | vBulletin における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-6255 | 2012-12-20 19:10 | 2009-02-24 | Show | GitHub Exploit DB Packet Storm |
| 229298 | 6.8 | 警告 | Pluck CMS | - | Pluck の data/inc/lib/pcltar.lib.php におけるディレクトリトラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2008-6253 | 2012-12-20 19:10 | 2009-02-24 | Show | GitHub Exploit DB Packet Storm |
| 229299 | 7.2 | 危険 | smcfancontrol | - | smcFanControl の smc プログラムにおけるスタックベースのバッファオーバーフローの脆弱性 |
CWE-119
バッファエラー |
CVE-2008-6252 | 2012-12-20 19:10 | 2009-02-24 | Show | GitHub Exploit DB Packet Storm |
| 229300 | 6.8 | 警告 | scripts | - | phpFan の includes/init.php における PHP リモートファイルインクルージョンの脆弱性 |
CWE-94
コード・インジェクション |
CVE-2008-6251 | 2012-12-20 19:10 | 2009-02-24 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 28, 2026, 4:16 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 195591 | 8.6 |
HIGH
Network |
xstream_project debian fedoraproject oracle |
xstream debian_linux fedora banking_platform webcenter_portal communications_unified_inventory_management communications_policy_management banking_virtual_account_management c… |
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resour… | - | CVE-2021-21349 | 2024-11-21 14:48 | 2021-03-23 | Show | GitHub Exploit DB Packet Storm |
| 195592 | 7.5 |
HIGH
Network |
xstream_project debian fedoraproject oracle |
xstream debian_linux fedora banking_platform webcenter_portal communications_unified_inventory_management communications_policy_management banking_virtual_account_management c… |
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes max… |
CWE-400
Uncontrolled Resource Consumption |
CVE-2021-21348 | 2024-11-21 14:48 | 2021-03-23 | Show | GitHub Exploit DB Packet Storm |
| 195593 | 9.8 |
CRITICAL
Network |
xstream_project debian fedoraproject oracle |
xstream debian_linux fedora banking_platform weblogic_server webcenter_portal communications_unified_inventory_management communications_policy_management banking_virtual_acco… |
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code f… | - | CVE-2021-21347 | 2024-11-21 14:48 | 2021-03-23 | Show | GitHub Exploit DB Packet Storm |
| 195594 | 9.8 |
CRITICAL
Network |
xstream_project debian fedoraproject oracle |
xstream debian_linux fedora banking_platform webcenter_portal bi_publisher communications_unified_inventory_management communications_policy_management banking_virtual_account… |
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code f… | - | CVE-2021-21346 | 2024-11-21 14:48 | 2021-03-23 | Show | GitHub Exploit DB Packet Storm |
| 195595 | 9.9 |
CRITICAL
Network |
xstream_project debian fedoraproject oracle |
xstream debian_linux fedora banking_platform webcenter_portal communications_unified_inventory_management communications_policy_management peoplesoft_enterprise_peopletools ba… |
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute… |
CWE-78
OS Command |
CVE-2021-21345 | 2024-11-21 14:48 | 2021-03-23 | Show | GitHub Exploit DB Packet Storm |
| 195596 | 9.8 |
CRITICAL
Network |
xstream_project debian fedoraproject oracle |
xstream debian_linux fedora banking_platform webcenter_portal communications_unified_inventory_management communications_policy_management banking_virtual_account_management c… |
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code f… | - | CVE-2021-21344 | 2024-11-21 14:48 | 2021-03-23 | Show | GitHub Exploit DB Packet Storm |
| 195597 | 7.5 |
HIGH
Network |
xstream_project debian fedoraproject oracle |
xstream debian_linux fedora banking_platform webcenter_portal communications_unified_inventory_management communications_policy_management banking_virtual_account_management c… |
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type informa… | - | CVE-2021-21343 | 2024-11-21 14:48 | 2021-03-23 | Show | GitHub Exploit DB Packet Storm |
| 195598 | 9.1 |
CRITICAL
Network |
xstream_project debian fedoraproject oracle |
xstream debian_linux fedora banking_platform webcenter_portal communications_unified_inventory_management communications_policy_management banking_virtual_account_management b… |
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type informa… | - | CVE-2021-21342 | 2024-11-21 14:48 | 2021-03-23 | Show | GitHub Exploit DB Packet Storm |
| 195599 | 7.5 |
HIGH
Network |
xstream_project debian fedoraproject oracle |
xstream debian_linux fedora banking_platform webcenter_portal communications_unified_inventory_management communications_billing_and_revenue_management_elastic_charging_engine bu… |
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the targe… | - | CVE-2021-21341 | 2024-11-21 14:48 | 2021-03-23 | Show | GitHub Exploit DB Packet Storm |
| 195600 | 4.3 |
MEDIUM
Network |
otrs |
faq otrs |
Agents are able to see linked FAQ articles without permissions (defined in FAQ Category). This issue affects: FAQ version 6.0.29 and prior versions, OTRS version 7.0.24 and prior versions. |
CWE-276
Incorrect Default Permissions |
CVE-2021-21438 | 2024-11-21 14:48 | 2021-03-22 | Show | GitHub Exploit DB Packet Storm |