|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 12, 2026, 6 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 230041 | 4.3 | 警告 | xeroxer | - | XeroXer Simple one-file gallery の gallery.php におけるクロスサイトスクリプティングの脆弱性 | - | CVE-2007-1125 | 2012-12-20 18:19 | 2007-02-26 | Show | GitHub Exploit DB Packet Storm |
| 230042 | 5 | 警告 | xeroxer | - | XeroXer Simple one-file gallery の gallery.php におけるディレクトリトラバーサルの脆弱性 | - | CVE-2007-1124 | 2012-12-20 18:19 | 2007-02-26 | Show | GitHub Exploit DB Packet Storm |
| 230043 | 7.5 | 危険 | ZPanel Project | - | ZPanel における PHP リモートファイルインクルージョンの脆弱性 | - | CVE-2007-1123 | 2012-12-20 18:19 | 2007-02-26 | Show | GitHub Exploit DB Packet Storm |
| 230044 | 6.4 | 警告 | zephyrsoft toolbox | - | Mathis Dirksen-Thedens ZephyrSoft Toolbox ABC における SQL インジェクションの脆弱性 | - | CVE-2007-1122 | 2012-12-20 18:19 | 2007-02-26 | Show | GitHub Exploit DB Packet Storm |
| 230045 | 6.4 | 警告 | zephyrsoft toolbox | - | Mathis Dirksen-Thedens ZephyrSoft Toolbox ABC における SQL インジェクションの脆弱性 | - | CVE-2007-1121 | 2012-12-20 18:19 | 2007-02-26 | Show | GitHub Exploit DB Packet Storm |
| 230046 | 9.3 | 危険 | steema software | - | TeeChart Pro ActiveX コントロールにおける .tee ファイルをダウンロードされる脆弱性 | - | CVE-2007-1120 | 2012-12-20 18:19 | 2007-02-26 | Show | GitHub Exploit DB Packet Storm |
| 230047 | 4.3 | 警告 | phpwebgallery | - | Phpwebgallery におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2007-1109 | 2012-12-20 18:19 | 2007-02-26 | Show | GitHub Exploit DB Packet Storm |
| 230048 | 4.3 | 警告 | The Tor Project | - | Tor における超過リソースを不当要求される脆弱性 | - | CVE-2007-1103 | 2012-12-20 18:19 | 2007-02-26 | Show | GitHub Exploit DB Packet Storm |
| 230049 | 7.8 | 危険 | pickle | - | Ahmet Sacan Pickle の download.php におけるディレクトリトラバーサルの脆弱性 | - | CVE-2007-1100 | 2012-12-20 18:19 | 2007-02-26 | Show | GitHub Exploit DB Packet Storm |
| 230050 | 7.8 | 危険 | scrymud | - | ScryMUD における脆弱性 | - | CVE-2007-1098 | 2012-12-20 18:19 | 2007-02-26 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 13, 2026, 5:05 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 200101 | 7.8 |
HIGH
Local |
qualcomm |
kamorta_firmware qcs605_firmware rennell_firmware saipan_firmware sdm670_firmware sdm710_firmware sdm845_firmware sm6150_firmware sm7150_firmware sm8150_firmware sm8250_… |
Use after free issue in camera applications when used randomly over multiple operations due to pointer not set to NULL after free/destroy of the object in Snapdragon Consumer IOT, Snapdragon Mobile i… |
CWE-416
Use After Free |
CVE-2020-3642 | 2024-11-21 14:31 | 2020-06-22 | Show | GitHub Exploit DB Packet Storm |
| 200102 | 7.8 |
HIGH
Local |
qualcomm |
apq8053_firmware apq8096au_firmware apq8098_firmware msm8909w_firmware msm8917_firmware msm8920_firmware msm8937_firmware msm8940_firmware msm8953_firmware msm8996au_firmwa… |
Stack based overflow If the maximum number of arguments allowed per request in perflock exceeds in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon … |
CWE-787
Out-of-bounds Write |
CVE-2020-3635 | 2024-11-21 14:31 | 2020-06-22 | Show | GitHub Exploit DB Packet Storm |
| 200103 | 7.8 |
HIGH
Local |
qualcomm |
apq8053_firmware apq8096au_firmware apq8098_firmware msm8905_firmware msm8909w_firmware msm8917_firmware msm8920_firmware msm8937_firmware msm8940_firmware msm8953_firmware… |
Any application can bind to it and exercise the APIs due to no protection for AIDL uimlpaservice in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… |
CWE-276
Incorrect Default Permissions |
CVE-2020-3626 | 2024-11-21 14:31 | 2020-06-22 | Show | GitHub Exploit DB Packet Storm |
| 200104 | 9.8 |
CRITICAL
Network |
qualcomm |
apq8009_firmware apq8017_firmware apq8053_firmware apq8076_firmware apq8096_firmware apq8096au_firmware apq8098_firmware ipq6018_firmware ipq8074_firmware mdm9206_firmware<… |
Possible buffer overflow while copying the frame to local buffer due to lack of check of length before copying in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Ele… |
CWE-120
Classic Buffer Overflow |
CVE-2020-3614 | 2024-11-21 14:31 | 2020-06-22 | Show | GitHub Exploit DB Packet Storm |
| 200105 | 3.3 |
LOW
Local |
geovision | gv-gf192x_firmware | GeoVision Door Access Control device family improperly stores and controls access to system logs, any users can read these logs. |
CWE-532
Inclusion of Sensitive Information in Log Files |
CVE-2020-3930 | 2024-11-21 14:31 | 2020-06-12 | Show | GitHub Exploit DB Packet Storm |
| 200106 | 5.9 |
MEDIUM
Network |
usavisionsys |
geovision_gv-as210_firmware geovision_gv-as410_firmware geovision_gv-as810_firmware geovision_gv-as1010_firmware geovision_gv-gf192x_firmware |
GeoVision Door Access Control device family employs shared cryptographic private keys for SSH and HTTPS. Attackers may conduct MITM attack with the derived keys and plaintext recover of encrypted mes… |
CWE-326
Inadequate Encryption Strength |
CVE-2020-3929 | 2024-11-21 14:31 | 2020-06-12 | Show | GitHub Exploit DB Packet Storm |
| 200107 | 9.8 |
CRITICAL
Network |
usavisionsys |
geovision_gv-as210_firmware geovision_gv-as410_firmware geovision_gv-as810_firmware geovision_gv-as1010_firmware geovision_gv-gf192x_firmware |
GeoVision Door Access Control device family is hardcoded with a root password, which adopting an identical password in all devices. |
CWE-798
Use of Hard-coded Credentials |
CVE-2020-3928 | 2024-11-21 14:31 | 2020-06-12 | Show | GitHub Exploit DB Packet Storm |
| 200108 | 6.5 |
MEDIUM
Network |
apple | mac_os_x | This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. Importing a maliciously crafted calendar invitation may exfiltrate user information. |
NVD-CWE-noinfo
|
CVE-2020-3882 | 2024-11-21 14:31 | 2020-06-10 | Show | GitHub Exploit DB Packet Storm |
| 200109 | 7.0 |
HIGH
Local |
qualcomm |
apq8009_firmware apq8053_firmware msm8909w_firmware msm8917_firmware msm8953_firmware qcs605_firmware qm215_firmware sa415m_firmware sdm429_firmware sdm429w_firmware sdm… |
A race condition can occur when using the fastrpc memory mapping API. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearabl… |
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition |
CVE-2020-3680 | 2024-11-21 14:31 | 2020-06-3 | Show | GitHub Exploit DB Packet Storm |
| 200110 | 7.8 |
HIGH
Local |
qualcomm |
sm8250_firmware sxr2130_firmware |
When making query to DSP capabilities, Stack out of bounds occurs due to wrong buffer length configured for DSP attributes in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile in SM8250, SX… |
CWE-120
Classic Buffer Overflow |
CVE-2020-3625 | 2024-11-21 14:31 | 2020-06-3 | Show | GitHub Exploit DB Packet Storm |