|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 14, 2026, 6 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 230901 | 5 | 警告 | zxid | - | ZXID における証明書チェーンの検証を回避される脆弱性 |
CWE-287
不適切な認証 |
CVE-2009-0051 | 2012-12-20 19:10 | 2009-01-7 | Show | GitHub Exploit DB Packet Storm |
| 230902 | 6.8 | 警告 | PunBB | - | PunBB におけるクロスサイトリクエストフォージェリの脆弱性 |
CWE-352
同一生成元ポリシー違反 |
CVE-2008-7241 | 2012-12-20 19:10 | 2009-09-17 | Show | GitHub Exploit DB Packet Storm |
| 230903 | 10 | 危険 | ourproject.org | - | White_Dune White_Dune におけるフォーマットストリングの脆弱性 |
CWE-134
書式文字列の問題 |
CVE-2008-7228 | 2012-12-20 19:10 | 2009-09-14 | Show | GitHub Exploit DB Packet Storm |
| 230904 | 7.5 | 危険 | PHPNUKE | - | PHP-Nuke 用の Recipes モジュールにおける SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-7226 | 2012-12-20 19:10 | 2009-09-14 | Show | GitHub Exploit DB Packet Storm |
| 230905 | 4.3 | 警告 | runcms | - | RunCMS の system/admin.php におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2008-7222 | 2012-12-20 19:10 | 2009-09-14 | Show | GitHub Exploit DB Packet Storm |
| 230906 | 6.8 | 警告 | runcms | - | RunCMS におけるクロスサイトリクエストフォージェリの脆弱性 |
CWE-352
同一生成元ポリシー違反 |
CVE-2008-7221 | 2012-12-20 19:10 | 2009-09-14 | Show | GitHub Exploit DB Packet Storm |
| 230907 | 7.5 | 危険 | prototypejs | - | Prototype JavaScript フレームワークにおける "クロスサイト ajax リクエスト" を実行される脆弱性 |
CWE-Other
その他 |
CVE-2008-7220 | 2012-12-20 19:10 | 2009-09-13 | Show | GitHub Exploit DB Packet Storm |
| 230908 | 4.3 | 警告 | WordPress.org | - | WordPress 用の Peter's Math Anti-Spam Spinoff プラグインにおける CAPTCHA 保護を回避される脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2008-7216 | 2012-12-20 19:10 | 2009-09-11 | Show | GitHub Exploit DB Packet Storm |
| 230909 | 6.9 | 警告 | soundblaster | - | Ensoniq PCI 1371 サウンドカードで使用されている CreativeLabs es1371mp.sys WDM 音声ドライバにおける SYSTEM 権限を取得される脆弱性 |
CWE-Other
その他 |
CVE-2008-7211 | 2012-12-20 19:10 | 2009-09-11 | Show | GitHub Exploit DB Packet Storm |
| 230910 | 2.1 | 注意 | RivetCode Software | - | RivetTracker におけるパスワードを特定される脆弱性 |
CWE-310
暗号の問題 |
CVE-2008-7207 | 2012-12-20 19:10 | 2009-09-11 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 14, 2026, 4:12 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 196221 | 7.5 |
HIGH
Network |
hitachienergy | esoms | Information Exposure vulnerability in Hitachi ABB Power Grids eSOMS allows unauthorized user to gain access to report data if the URL used to access the report is discovered. This issue affects: Hita… |
CWE-863
Incorrect Authorization |
CVE-2021-26845 | 2024-11-21 14:56 | 2021-06-15 | Show | GitHub Exploit DB Packet Storm |
| 196222 | 5.4 |
MEDIUM
Network |
openplcproject | scadabr | OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm. |
CWE-79
Cross-site Scripting |
CVE-2021-26829 | 2024-11-21 14:56 | 2021-06-11 | Show | GitHub Exploit DB Packet Storm |
| 196223 | 8.8 |
HIGH
Network |
openplcproject | scadabr | OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm. |
CWE-434
Unrestricted Upload of File with Dangerous Type |
CVE-2021-26828 | 2024-11-21 14:56 | 2021-06-11 | Show | GitHub Exploit DB Packet Storm |
| 196224 | 9.8 |
CRITICAL
Network |
apache debian fedoraproject oracle netapp |
http_server debian_linux fedora instantis_enterprisetrack enterprise_manager_ops_center zfs_storage_appliance_kit secure_backup cloud_backup |
In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow |
CWE-787
Out-of-bounds Write |
CVE-2021-26691 | 2024-11-21 14:56 | 2021-06-10 | Show | GitHub Exploit DB Packet Storm |
| 196225 | 7.5 |
HIGH
Network |
apache debian fedoraproject oracle |
http_server debian_linux fedora instantis_enterprisetrack enterprise_manager_ops_center zfs_storage_appliance_kit |
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service |
CWE-476
NULL Pointer Dereference |
CVE-2021-26690 | 2024-11-21 14:56 | 2021-06-10 | Show | GitHub Exploit DB Packet Storm |
| 196226 | 5.5 |
MEDIUM
Local |
xen arm broadcom intel fedoraproject |
xen cortex-a72 bcm2711 core_i7-7700k xeon_silver_4214 core_i9-9900k core_i7-10700k fedora |
Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause… |
CWE-203
Information Exposure Through Discrepancy |
CVE-2021-26314 | 2024-11-21 14:56 | 2021-06-9 | Show | GitHub Exploit DB Packet Storm |
| 196227 | 5.5 |
MEDIUM
Local |
xen arm broadcom intel debian |
xen cortex-a72 bcm2711 core_i7-7700k xeon_silver_4214 core_i9-9900k core_i7-10700k debian_linux |
Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorre… |
CWE-203
Information Exposure Through Discrepancy |
CVE-2021-26313 | 2024-11-21 14:56 | 2021-06-9 | Show | GitHub Exploit DB Packet Storm |
| 196228 | 7.1 |
HIGH
Network |
microsoft |
sharepoint_foundation sharepoint_enterprise_server sharepoint_server |
Microsoft SharePoint Server Remote Code Execution Vulnerability |
NVD-CWE-noinfo
|
CVE-2021-26420 | 2024-11-21 14:56 | 2021-06-9 | Show | GitHub Exploit DB Packet Storm |
| 196229 | 4.8 |
MEDIUM
Network |
microsoft |
windows_10 windows_server_2008 windows_7 windows_server_2012 windows_8.1 windows_server_2016 windows_rt_8.1 windows_server_2019 windows_server_2022 windows_server |
Windows DCOM Server Security Feature Bypass |
NVD-CWE-noinfo
|
CVE-2021-26414 | 2024-11-21 14:56 | 2021-06-9 | Show | GitHub Exploit DB Packet Storm |
| 196230 | 8.8 |
HIGH
Network |
vembu |
bdr_suite offsite_dr |
Various Vembu products allow an attacker to execute a (non-blind) http-only Cross Site Request Forgery (Other products or versions of products in this family may be affected too.) |
CWE-352
Origin Validation Error |
CVE-2021-26474 | 2024-11-21 14:56 | 2021-06-9 | Show | GitHub Exploit DB Packet Storm |