|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 11, 2026, 6:13 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 229611 | 7.5 | 危険 | script-shop24 | - | LM Starmail Paidmail の home.php における PHP リモートファイルインクルージョンの脆弱性 |
CWE-94
コード・インジェクション |
CVE-2009-4993 | 2012-12-20 19:28 | 2010-08-25 | Show | GitHub Exploit DB Packet Storm |
| 229612 | 7.5 | 危険 | script-shop24 | - | LM Starmail Paidmail の paidbanner.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4992 | 2012-12-20 19:28 | 2010-08-25 | Show | GitHub Exploit DB Packet Storm |
| 229613 | 10 | 危険 | SAP | - | SAP Business One の NT_Naming_Service.exe におけるスタックベースのバッファオーバーフローの脆弱性 |
CWE-119
バッファエラー |
CVE-2009-4988 | 2012-12-20 19:28 | 2010-08-25 | Show | GitHub Exploit DB Packet Storm |
| 229614 | 7.5 | 危険 | scripteen | - | Scripteen Free Image Hosting Script の admin/header.php における認証を回避される脆弱性 |
CWE-287
不適切な認証 |
CVE-2009-4987 | 2012-12-20 19:28 | 2010-08-25 | Show | GitHub Exploit DB Packet Storm |
| 229615 | 7.5 | 危険 | websitesrus | - | Accessories Me PHP Affiliate Script の browse.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4985 | 2012-12-20 19:28 | 2010-08-25 | Show | GitHub Exploit DB Packet Storm |
| 229616 | 4.3 | 警告 | websitesrus | - | Accessories Me PHP Affiliate Script におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-4984 | 2012-12-20 19:28 | 2010-08-25 | Show | GitHub Exploit DB Packet Storm |
| 229617 | 4.3 | 警告 | snowhall | - | Silurus Classifieds におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-4983 | 2012-12-20 19:28 | 2010-08-25 | Show | GitHub Exploit DB Packet Storm |
| 229618 | 5 | 警告 | tufat | - | MyBackup の down.php におけるディレクトリトラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2009-4978 | 2012-12-20 19:28 | 2010-08-25 | Show | GitHub Exploit DB Packet Storm |
| 229619 | 6.5 | 警告 | tufat | - | MyBackup の index.php における PHP リモートファイルインクルージョンの脆弱性 |
CWE-94
コード・インジェクション |
CVE-2009-4977 | 2012-12-20 19:28 | 2010-08-25 | Show | GitHub Exploit DB Packet Storm |
| 229620 | 7.5 | 危険 | sweetphp | - | TotalCalendar の box_display.php におけるディレクトリトラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2009-4974 | 2012-12-20 19:28 | 2010-07-28 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 12, 2026, 4:20 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 208231 | 6.1 |
MEDIUM
Network |
rails_admin_project | rails_admin | RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms. |
CWE-79
Cross-site Scripting |
CVE-2020-36190 | 2024-11-21 14:28 | 2021-01-13 | Show | GitHub Exploit DB Packet Storm |
| 208232 | 7.5 |
HIGH
Network |
socket | socket.io-parser | socket.io-parser before 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet because a concatenation approach is used. |
CWE-770
Allocation of Resources Without Limits or Throttling |
CVE-2020-36049 | 2024-11-21 14:28 | 2021-01-8 | Show | GitHub Exploit DB Packet Storm |
| 208233 | 7.5 |
HIGH
Network |
socket | engine.io | Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport. |
CWE-400
Uncontrolled Resource Consumption |
CVE-2020-36048 | 2024-11-21 14:28 | 2021-01-8 | Show | GitHub Exploit DB Packet Storm |
| 208234 | 8.1 |
HIGH
Network |
fasterxml netapp debian oracle |
jackson-databind cloud_backup service_level_manager debian_linux webcenter_portal primavera_unifier application_testing_suite agile_plm communications_policy_management com… |
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool. |
CWE-502
Deserialization of Untrusted Data |
CVE-2020-36183 | 2024-11-21 14:28 | 2021-01-7 | Show | GitHub Exploit DB Packet Storm |
| 208235 | 8.1 |
HIGH
Network |
fasterxml netapp debian oracle |
jackson-databind cloud_backup service_level_manager debian_linux webcenter_portal primavera_unifier application_testing_suite agile_plm communications_policy_management com… |
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS. |
CWE-502
Deserialization of Untrusted Data |
CVE-2020-36182 | 2024-11-21 14:28 | 2021-01-7 | Show | GitHub Exploit DB Packet Storm |
| 208236 | 8.1 |
HIGH
Network |
netapp debian oracle fasterxml |
cloud_backup service_level_manager debian_linux webcenter_portal primavera_unifier application_testing_suite agile_plm communications_policy_management communications_billing_… |
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS. |
CWE-502
Deserialization of Untrusted Data |
CVE-2020-36180 | 2024-11-21 14:28 | 2021-01-7 | Show | GitHub Exploit DB Packet Storm |
| 208237 | 8.1 |
HIGH
Network |
netapp debian oracle fasterxml |
cloud_backup service_level_manager debian_linux webcenter_portal application_testing_suite primavera_unifier agile_plm communications_policy_management communications_billing_… |
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS. |
CWE-502
Deserialization of Untrusted Data |
CVE-2020-36179 | 2024-11-21 14:28 | 2021-01-7 | Show | GitHub Exploit DB Packet Storm |
| 208238 | 8.1 |
HIGH
Network |
fasterxml netapp debian oracle |
jackson-databind cloud_backup service_level_manager debian_linux webcenter_portal application_testing_suite banking_platform primavera_unifier agile_plm communications_bill… |
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSo… |
CWE-502
Deserialization of Untrusted Data |
CVE-2020-36189 | 2024-11-21 14:28 | 2021-01-7 | Show | GitHub Exploit DB Packet Storm |
| 208239 | 8.1 |
HIGH
Network |
fasterxml netapp debian oracle |
jackson-databind cloud_backup service_level_manager debian_linux webcenter_portal primavera_unifier application_testing_suite agile_plm communications_policy_management com… |
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource. |
CWE-502
Deserialization of Untrusted Data |
CVE-2020-36188 | 2024-11-21 14:28 | 2021-01-7 | Show | GitHub Exploit DB Packet Storm |
| 208240 | 8.1 |
HIGH
Network |
fasterxml netapp debian oracle |
jackson-databind cloud_backup service_level_manager debian_linux webcenter_portal primavera_unifier application_testing_suite agile_plm communications_policy_management com… |
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource. |
CWE-502
Deserialization of Untrusted Data |
CVE-2020-36187 | 2024-11-21 14:28 | 2021-01-7 | Show | GitHub Exploit DB Packet Storm |