|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 24, 2026, 2 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 244921 | 7.5 | 危険 | ASP indir | - | W1L3D4 Philboard における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-2334 | 2012-06-26 16:02 | 2008-05-19 | Show | GitHub Exploit DB Packet Storm |
| 244922 | 4.3 | 警告 | Django Software Foundation | - | Django の管理アプリケーションのログインフォームにおけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2008-2302 | 2012-06-26 16:02 | 2008-05-23 | Show | GitHub Exploit DB Packet Storm |
| 244923 | 6.5 | 警告 | シトリックス・システムズ | - | Citrix Presentation Server などの製品における不正にデスクトップへアクセスされる脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2008-2300 | 2012-06-26 16:02 | 2008-05-13 | Show | GitHub Exploit DB Packet Storm |
| 244924 | 5 | 警告 | シトリックス・システムズ | - | Citrix Presentation Server などの製品で使用される SecureICA における制限を回避される脆弱性 |
CWE-310
暗号の問題 |
CVE-2008-2299 | 2012-06-26 16:02 | 2008-05-12 | Show | GitHub Exploit DB Packet Storm |
| 244925 | 7.5 | 危険 | Fusebox | - | Fusebox の fusebox5.php における PHP リモートファイルインクルージョンの脆弱性 |
CWE-94
コード・インジェクション |
CVE-2008-2284 | 2012-06-26 16:02 | 2008-05-18 | Show | GitHub Exploit DB Packet Storm |
| 244926 | 5 | 警告 | freelanceauction | - | Freelance Auction Script における権限を取得される脆弱性 |
CWE-255
証明書・パスワード管理 |
CVE-2008-2279 | 2012-06-26 16:02 | 2008-05-16 | Show | GitHub Exploit DB Packet Storm |
| 244927 | 7.5 | 危険 | freelanceauction | - | Freelance Auction Script の browseproject.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-2278 | 2012-06-26 16:02 | 2008-05-16 | Show | GitHub Exploit DB Packet Storm |
| 244928 | 7.5 | 危険 | cmsnx | - | Feedback および Rating Script の detail.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-2277 | 2012-06-26 16:02 | 2008-05-16 | Show | GitHub Exploit DB Packet Storm |
| 244929 | 9 | 危険 | アルバネットワークス株式会社 | - | Aruba Mobility Controller の TACACS 認証コンポーネントにおける権限を取得される脆弱性 |
CWE-noinfo
情報不足 |
CVE-2008-2273 | 2012-06-26 16:02 | 2008-05-14 | Show | GitHub Exploit DB Packet Storm |
| 244930 | 4.3 | 警告 | アルバネットワークス株式会社 | - | Aruba Mobility Controller の Web インターフェースにおけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2008-2272 | 2012-06-26 16:02 | 2008-05-14 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 24, 2026, 4:05 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 218701 | 9.8 |
CRITICAL
Network |
moxa |
iks-g6824a_firmware eds-405a_firmware eds-408a_firmware eds-510a_firmware |
Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administrator's password, which could lead to a full compromise of the device. |
CWE-916
Use of Password Hash With Insufficient Computational Effort |
CVE-2019-6563 | 2024-11-21 13:46 | 2019-03-6 | Show | GitHub Exploit DB Packet Storm |
| 218702 | 8.8 |
HIGH
Network |
moxa |
iks-g6824a_firmware eds-405a_firmware eds-408a_firmware eds-510a_firmware |
Cross-site request forgery has been identified in Moxa IKS and EDS, which may allow for the execution of unauthorized actions on the device. |
CWE-352
Origin Validation Error |
CVE-2019-6561 | 2024-11-21 13:46 | 2019-03-6 | Show | GitHub Exploit DB Packet Storm |
| 218703 | 6.5 |
MEDIUM
Network |
moxa |
iks-g6824a_firmware eds-405a_firmware eds-408a_firmware eds-510a_firmware |
Moxa IKS and EDS allow remote authenticated users to cause a denial of service via a specially crafted packet, which may cause the switch to crash. |
CWE-400
Uncontrolled Resource Consumption |
CVE-2019-6559 | 2024-11-21 13:46 | 2019-03-6 | Show | GitHub Exploit DB Packet Storm |
| 218704 | 9.8 |
CRITICAL
Network |
moxa |
iks-g6824a_firmware eds-405a_firmware eds-408a_firmware eds-510a_firmware |
Several buffer overflow vulnerabilities have been identified in Moxa IKS and EDS, which may allow remote code execution. |
CWE-120
Classic Buffer Overflow |
CVE-2019-6557 | 2024-11-21 13:46 | 2019-03-6 | Show | GitHub Exploit DB Packet Storm |
| 218705 | 9.8 |
CRITICAL
Network |
moxa |
iks-g6824a_firmware eds-405a_firmware eds-408a_firmware eds-510a_firmware |
Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to discover passwords via brute force attack. |
CWE-307
mproper Restriction of Excessive Authentication Attempts |
CVE-2019-6524 | 2024-11-21 13:46 | 2019-03-6 | Show | GitHub Exploit DB Packet Storm |
| 218706 | 9.1 |
CRITICAL
Network |
moxa |
iks-g6824a_firmware eds-405a_firmware eds-408a_firmware eds-510a_firmware |
Moxa IKS and EDS fails to properly check array bounds which may allow an attacker to read device memory on arbitrary addresses, and may allow an attacker to retrieve sensitive data or cause device re… |
CWE-125
Out-of-bounds Read |
CVE-2019-6522 | 2024-11-21 13:46 | 2019-03-6 | Show | GitHub Exploit DB Packet Storm |
| 218707 | 8.8 |
HIGH
Network |
psigridconnect |
telecontrol_gateway_xs-mu_firmware telecontrol_gateway_vm_firmware telecontrol_gateway_3g_firmware smart_telecontrol_unit_tcg_firmware iec104_security_proxy_firmware |
PSI GridConnect GmbH Telecontrol Gateway and Smart Telecontrol Unit family, IEC104 Security Proxy versions Telecontrol Gateway 3G Versions 4.2.21, 5.0.27, 5.1.19, 6.0.16 and prior, and Telecontrol Ga… |
CWE-79
Cross-site Scripting |
CVE-2019-6528 | 2024-11-21 13:46 | 2019-03-6 | Show | GitHub Exploit DB Packet Storm |
| 218708 | 7.5 |
HIGH
Network |
moxa |
iks-g6824a_firmware eds-405a_firmware eds-408a_firmware eds-510a_firmware |
Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user being able to perform arbitrary configuration changes. |
NVD-CWE-Other
|
CVE-2019-6520 | 2024-11-21 13:46 | 2019-03-6 | Show | GitHub Exploit DB Packet Storm |
| 218709 | 7.5 |
HIGH
Network |
moxa |
iks-g6824a_firmware eds-405a_firmware eds-408a_firmware eds-510a_firmware |
Moxa IKS and EDS store plaintext passwords, which may allow sensitive information to be read by someone with access to the device. |
CWE-311
Missing Encryption of Sensitive Data |
CVE-2019-6518 | 2024-11-21 13:46 | 2019-03-6 | Show | GitHub Exploit DB Packet Storm |
| 218710 | 8.8 |
HIGH
Network |
apple webkitgtk |
iphone_os safari tvos icloud itunes webkitgtk\+ |
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing ma… |
CWE-787
Out-of-bounds Write |
CVE-2019-6234 | 2024-11-21 13:46 | 2019-03-6 | Show | GitHub Exploit DB Packet Storm |