|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 6, 2026, 2 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 230311 | 1.9 | 注意 | シトリックス・システムズ | - | Xen におけるサービス運用妨害 (Xen の無限ループおよび物理 CPU の消費) の脆弱性 |
CWE-399
リソース管理の問題 |
CVE-2012-4535 | 2012-12-17 12:28 | 2012-11-13 | Show | GitHub Exploit DB Packet Storm |
| 230312 | 4.3 | 警告 | Wikka Development Team | - | WikkaWiki におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
- | 2012-12-17 12:15 | 2012-12-17 | Show | GitHub Exploit DB Packet Storm |
| 230313 | 4.3 | 警告 | Netsweeper, Inc. | - | Netsweeper の WebAdmin Portal におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2012-2446 | 2012-12-17 11:02 | 2012-07-9 | Show | GitHub Exploit DB Packet Storm |
| 230314 | 10 | 危険 | Netsweeper, Inc. | - | Netsweeper の WebAdmin Portal における脆弱性 |
CWE-noinfo
情報不足 |
CVE-2012-3859 | 2012-12-17 10:56 | 2012-07-9 | Show | GitHub Exploit DB Packet Storm |
| 230315 | 9.3 | 危険 | マイクロソフト | - | 複数の Microsoft Windows 製品におけるヒープベースのバッファオーバーフローの脆弱性 |
CWE-119
バッファエラー |
CVE-2012-1537 | 2012-12-17 10:56 | 2012-12-11 | Show | GitHub Exploit DB Packet Storm |
| 230316 | 9.3 | 危険 | マイクロソフト | - | 複数の Microsoft 製品における任意のコードを実行される脆弱性 |
CWE-399
リソース管理の問題 |
CVE-2012-2539 | 2012-12-17 10:55 | 2012-12-11 | Show | GitHub Exploit DB Packet Storm |
| 230317 | 6.8 | 警告 | Netsweeper, Inc. | - | Netsweeper の WebAdmin Portal におけるクロスサイトリクエストフォージェリの脆弱性 |
CWE-352
同一生成元ポリシー違反 |
CVE-2012-2447 | 2012-12-17 10:53 | 2012-07-9 | Show | GitHub Exploit DB Packet Storm |
| 230318 | 9.3 | 危険 | マイクロソフト | - | Microsoft Internet Explorer 6 から 10 における任意のコードを実行される脆弱性 |
CWE-94
コード・インジェクション |
CVE-2012-4781 | 2012-12-17 10:52 | 2012-12-11 | Show | GitHub Exploit DB Packet Storm |
| 230319 | 10 | 危険 | マイクロソフト | - | 複数の Microsoft Windows 製品のカーネルモードドライバにおける任意のコードを実行される脆弱性 |
CWE-94
コード・インジェクション |
CVE-2012-4786 | 2012-12-17 10:50 | 2012-12-11 | Show | GitHub Exploit DB Packet Storm |
| 230320 | 10 | 危険 | マイクロソフト | - | Microsoft Internet Explorer 9 および 10 における任意のコードを実行される脆弱性 |
CWE-94
コード・インジェクション |
CVE-2012-4787 | 2012-12-17 10:49 | 2012-12-11 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 6, 2026, 4:08 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 212011 | 10.0 |
CRITICAL
Network |
envoyproxy | envoy | Envoy 1.9.0 and before does not normalize HTTP URL paths. A remote attacker may craft a relative path, e.g., something/../admin, to bypass access control, e.g., a block on /admin. A backend server co… |
CWE-706
Use of Incorrectly-Resolved Name or Reference |
CVE-2019-9901 | 2024-11-21 13:52 | 2019-04-26 | Show | GitHub Exploit DB Packet Storm |
| 212012 | 8.3 |
HIGH
Network |
envoyproxy redhat |
envoy openshift_service_mesh |
When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL char… |
CWE-74
Injection |
CVE-2019-9900 | 2024-11-21 13:52 | 2019-04-26 | Show | GitHub Exploit DB Packet Storm |
| 212013 | 6.5 |
MEDIUM
Network |
tensorflow | NULL pointer dereference in Google TensorFlow before 1.12.2 could cause a denial of service via an invalid GIF file. |
CWE-476
NULL Pointer Dereference |
CVE-2019-9635 | 2024-11-21 13:52 | 2019-04-25 | Show | GitHub Exploit DB Packet Storm | |
| 212014 | 9.8 |
CRITICAL
Network |
western_digital |
my_cloud_mirror_gen_2_firmware my_cloud_ex2_ultra_firmware my_cloud_ex2100_firmware my_cloud_ex4100 my_cloud_dl2100 my_cloud_dl4100_firmware my_cloud_pr2100_firmware my_cloud_pr4… |
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is… |
CWE-434
Unrestricted Upload of File with Dangerous Type |
CVE-2019-9951 | 2024-11-21 13:52 | 2019-04-25 | Show | GitHub Exploit DB Packet Storm |
| 212015 | 9.8 |
CRITICAL
Network |
westerndigital |
my_cloud_firmware my_cloud_mirror_gen2_firmware my_cloud_ex2_ultra_firmware my_cloud_ex2100_firmware my_cloud_ex4100_firmware my_cloud_dl2100_firmware my_cloud_dl4100_firmware my… |
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is… |
CWE-521
Weak Password Requirements |
CVE-2019-9950 | 2024-11-21 13:52 | 2019-04-25 | Show | GitHub Exploit DB Packet Storm |
| 212016 | 8.8 |
HIGH
Network |
gstreamer_project debian canonical |
gstreamer debian_linux ubuntu_linux |
GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution. |
CWE-787
Out-of-bounds Write |
CVE-2019-9928 | 2024-11-21 13:52 | 2019-04-25 | Show | GitHub Exploit DB Packet Storm |
| 212017 | 7.5 |
HIGH
Network |
aquaverde | aquarius_cms | Aquarius CMS through 4.3.5 writes POST and GET parameters (including passwords) to a log file due to an overwriting of configuration parameters under certain circumstances. |
CWE-532
Inclusion of Sensitive Information in Log Files |
CVE-2019-9734 | 2024-11-21 13:52 | 2019-04-25 | Show | GitHub Exploit DB Packet Storm |
| 212018 | 7.5 |
HIGH
Network |
aquaverde | aquarius_cms | aquaverde Aquarius CMS through 4.3.5 allows Information Exposure through Log Files because of an error in the Log-File writer component. |
CWE-532
Inclusion of Sensitive Information in Log Files |
CVE-2019-9724 | 2024-11-21 13:52 | 2019-04-24 | Show | GitHub Exploit DB Packet Storm |
| 212019 | 6.1 |
MEDIUM
Network |
vestacp | control_panel | Vesta Control Panel 0.9.8-23 allows XSS via a crafted URL. |
CWE-79
Cross-site Scripting |
CVE-2019-9841 | 2024-11-21 13:52 | 2019-04-20 | Show | GitHub Exploit DB Packet Storm |
| 212020 | 6.1 |
MEDIUM
Network |
zyxel |
atp200_firmware atp500_firmware atp800_firmware usg20-vpn_firmware usg20w-vpn_firmware usg40_firmware usg40w_firmware usg60_firmware usg60w_firmware usg110_firmware usg2… |
On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security … |
CWE-79
Cross-site Scripting |
CVE-2019-9955 | 2024-11-21 13:52 | 2019-04-23 | Show | GitHub Exploit DB Packet Storm |