|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 1, 2026, 6 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 229921 | 6.5 | 警告 | rianxosencabos cms | - | Rianxosencabos CMS の Admin Control Panel におけるユーザの権限を変更される脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2008-4245 | 2012-12-20 18:52 | 2008-09-25 | Show | GitHub Exploit DB Packet Storm |
| 229922 | 7.5 | 危険 | webcms | - | webCMS Portal Edition の index.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-4185 | 2012-12-20 18:52 | 2008-09-23 | Show | GitHub Exploit DB Packet Storm |
| 229923 | 4.3 | 警告 | webcms | - | webCMS Portal Edition の index.php におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2008-4184 | 2012-12-20 18:52 | 2008-09-23 | Show | GitHub Exploit DB Packet Storm |
| 229924 | 7.5 | 危険 | PreProject.com | - | Pre Real Estate Listings の search.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-4177 | 2012-12-20 18:52 | 2008-09-23 | Show | GitHub Exploit DB Packet Storm |
| 229925 | 7.5 | 危険 | proarcadescript | - | ProArcadeScript における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-4173 | 2012-12-20 18:52 | 2008-09-22 | Show | GitHub Exploit DB Packet Storm |
| 229926 | 7.5 | 危険 | rfaah | - | Cars & Vehicle の page.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-4172 | 2012-12-20 18:52 | 2008-09-22 | Show | GitHub Exploit DB Packet Storm |
| 229927 | 4.3 | 警告 | pro2col | - | Pro2col Stingray FTS の verify_login.jsp におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2008-4168 | 2012-12-20 18:52 | 2008-09-22 | Show | GitHub Exploit DB Packet Storm |
| 229928 | 7.5 | 危険 | zanfi solutions | - | Zanfi CMS lite および Jaw Portal の index.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-4159 | 2012-12-20 18:52 | 2008-09-22 | Show | GitHub Exploit DB Packet Storm |
| 229929 | 6.8 | 警告 | zanfi solutions | - | Zanfi CMS lite の index.php におけるディレクトリトラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2008-4158 | 2012-12-20 18:52 | 2008-09-22 | Show | GitHub Exploit DB Packet Storm |
| 229930 | 7.5 | 危険 | Vastal I-Tech & Co. | - | Vastal I-Tech phpVID の groups.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-4157 | 2012-12-20 18:52 | 2008-09-22 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 2, 2026, 4:18 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 201721 | 6.5 |
MEDIUM
Adjacent |
gradle | plugin_publishing | All versions of com.gradle.plugin-publish before 0.11.0 are vulnerable to Insertion of Sensitive Information into Log File. When a plugin author publishes a Gradle plugin while running Gradle with th… |
CWE-532
Inclusion of Sensitive Information in Log Files |
CVE-2020-7599 | 2024-11-21 14:37 | 2020-03-31 | Show | GitHub Exploit DB Packet Storm |
| 201722 | 6.1 |
MEDIUM
Network |
schneider-electric |
andover_continuum_9680_firmware andover_continuum_5740_firmware andover_continuum_5720_firmware andover_continuum_bcx4040_firmware andover_continuum_bcx9640_firmware andover_continuum_… |
A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists Andover Continuum (All versions), which could cause a Reflective Cross-site Scriptin… |
CWE-79
Cross-site Scripting |
CVE-2020-7482 | 2024-11-21 14:37 | 2020-03-24 | Show | GitHub Exploit DB Packet Storm |
| 201723 | 6.1 |
MEDIUM
Network |
schneider-electric |
andover_continuum_9680_firmware andover_continuum_5740_firmware andover_continuum_5720_firmware andover_continuum_bcx4040_firmware andover_continuum_bcx9640_firmware andover_continuum_… |
A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists Andover Continuum (All versions), which could enable a successful Cross-site Scripti… |
CWE-79
Cross-site Scripting |
CVE-2020-7481 | 2024-11-21 14:37 | 2020-03-24 | Show | GitHub Exploit DB Packet Storm |
| 201724 | 9.8 |
CRITICAL
Network |
schneider-electric |
andover_continuum_9680_firmware andover_continuum_5740_firmware andover_continuum_5720_firmware andover_continuum_bcx4040_firmware andover_continuum_bcx9640_firmware andover_continuum_… |
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versions), which could cause files on the application server filesystem to be viewab… |
CWE-94
Code Injection |
CVE-2020-7480 | 2024-11-21 14:37 | 2020-03-24 | Show | GitHub Exploit DB Packet Storm |
| 201725 | 7.8 |
HIGH
Local |
schneider-electric | interactive_graphical_scada_system | A CWE-306: Missing Authentication for Critical Function vulnerability exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a local user to execute processes that ot… |
CWE-306
Missing Authentication for Critical Function |
CVE-2020-7479 | 2024-11-21 14:37 | 2020-03-24 | Show | GitHub Exploit DB Packet Storm |
| 201726 | 7.5 |
HIGH
Network |
schneider-electric | interactive_graphical_scada_system | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a remote unauthenticated attacker to read… |
CWE-22
Path Traversal |
CVE-2020-7478 | 2024-11-21 14:37 | 2020-03-24 | Show | GitHub Exploit DB Packet Storm |
| 201727 | 7.8 |
HIGH
Local |
schneider-electric | ulti_zigbee_installation_toolkit | A CWE-426: Untrusted Search Path vulnerability exists in ZigBee Installation Kit (Versions prior to 1.0.1), which could cause execution of malicious code when a malicious file is put in the search pa… |
CWE-426
Untrusted Search Path |
CVE-2020-7476 | 2024-11-21 14:37 | 2020-03-24 | Show | GitHub Exploit DB Packet Storm |
| 201728 | 7.5 |
HIGH
Network |
schneider-electric |
140noe77101_firmware 140noe77111_firmware tsxh5744m_firmware tsxh5724m_firmware tsxp576634m_firmware tsxp57554m_firmware tsxp575634m_firmware tsxp57454m_firmware tsxp574634m_f… |
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Quantum Ethernet Network module 140NOE771x1 (Versions 7.0 and prior), Quantum processors with integrated Ethern… |
CWE-754
Improper Check for Unusual or Exceptional Conditions |
CVE-2020-7477 | 2024-11-21 14:37 | 2020-03-24 | Show | GitHub Exploit DB Packet Storm |
| 201729 | 9.8 |
CRITICAL
Network |
schneider-electric |
unity_pro ecostruxure_control_expert modicon_m340_firmware modicon_m580_firmware |
A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to… |
CWE-74
Injection |
CVE-2020-7475 | 2024-11-21 14:37 | 2020-03-24 | Show | GitHub Exploit DB Packet Storm |
| 201730 | 7.8 |
HIGH
Local |
schneider-electric | pmepxm0100_prosoft_configurator | A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProSoft Configurator (v1.002 and prior), for the PMEPXM0100 (H) module, which could cause the execution of untrusted code when usin… |
CWE-427
Uncontrolled Search Path Element |
CVE-2020-7474 | 2024-11-21 14:37 | 2020-03-24 | Show | GitHub Exploit DB Packet Storm |