|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 14, 2026, noon
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 245121 | 6.8 | 警告 | element-it | - | Element-IT Ultimate Uploader における任意のコードを実行される脆弱性 |
CWE-Other
その他 |
CVE-2009-4817 | 2012-06-26 16:19 | 2010-04-27 | Show | GitHub Exploit DB Packet Storm |
| 245122 | 5 | 警告 | MegaLab.it | - | MegaLab The Uploader の api/download_checker.php におけるディレクトリトラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2009-4816 | 2012-06-26 16:19 | 2010-04-27 | Show | GitHub Exploit DB Packet Storm |
| 245123 | 7.5 | 危険 | graugon | - | Graugon PHP Article Publisher の admin.php における管理者用アクセス権を取得される脆弱性 |
CWE-287
不適切な認証 |
CVE-2009-4808 | 2012-06-26 16:19 | 2010-04-23 | Show | GitHub Exploit DB Packet Storm |
| 245124 | 7.5 | 危険 | graugon | - | Graugon PHP Article Publisher における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4807 | 2012-06-26 16:19 | 2010-04-23 | Show | GitHub Exploit DB Packet Storm |
| 245125 | 7.5 | 危険 | digitalinterchange | - | Digital Interchange Document Library の admin/save_user.asp における管理者の資格情報を変更される脆弱性 |
CWE-287
不適切な認証 |
CVE-2009-4806 | 2012-06-26 16:19 | 2010-04-23 | Show | GitHub Exploit DB Packet Storm |
| 245126 | 7.5 | 危険 | TYPO3 Association andreas schwarzkopf |
- | TYPO3 の a21glossary 拡張における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4803 | 2012-06-26 16:19 | 2010-03-5 | Show | GitHub Exploit DB Packet Storm |
| 245127 | 5 | 警告 | diskos | - | Diskos CMS におけるデータベースをダウンロードされる脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2009-4799 | 2012-06-26 16:19 | 2010-04-22 | Show | GitHub Exploit DB Packet Storm |
| 245128 | 7.5 | 危険 | diskos | - | Diskos CMS における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4798 | 2012-06-26 16:19 | 2010-04-22 | Show | GitHub Exploit DB Packet Storm |
| 245129 | 7.5 | 危険 | glFusion | - | glFusion の private/system/classes/listfactory.class.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4796 | 2012-06-26 16:19 | 2010-04-22 | Show | GitHub Exploit DB Packet Storm |
| 245130 | 7.5 | 危険 | community cms | - | Community CMS における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4794 | 2012-06-26 16:19 | 2010-04-22 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 14, 2026, 4:12 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 218081 | 7.5 |
HIGH
Network |
sylabs | singularity | Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not sign metadata found in the global header or data object descriptors of a SIF fil… |
CWE-354
Improper Validation of Integrity Check Value |
CVE-2020-13847 | 2024-11-21 14:01 | 2020-07-15 | Show | GitHub Exploit DB Packet Storm |
| 218082 | 7.5 |
HIGH
Network |
sylabs | singularity | Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code. |
NVD-CWE-Other
|
CVE-2020-13846 | 2024-11-21 14:01 | 2020-07-15 | Show | GitHub Exploit DB Packet Storm |
| 218083 | 7.5 |
HIGH
Network |
sylabs | singularity | Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compare… |
CWE-347 CWE-354 Improper Verification of Cryptographic Signature Improper Validation of Integrity Check Value |
CVE-2020-13845 | 2024-11-21 14:01 | 2020-07-15 | Show | GitHub Exploit DB Packet Storm |
| 218084 | 10.0 |
CRITICAL
Network |
wpewebkit webkitgtk fedoraproject debian canonical opensuse |
wpe_webkit webkitgtk fedora debian_linux ubuntu_linux leap |
The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-des… |
CWE-20
Improper Input Validation |
CVE-2020-13753 | 2024-11-21 14:01 | 2020-07-14 | Show | GitHub Exploit DB Packet Storm |
| 218085 | 6.1 |
MEDIUM
Network |
synacor | zimbra_collaboration_suite | An XSS vulnerability exists in the Webmail component of Zimbra Collaboration Suite before 8.8.15 Patch 11. It allows an attacker to inject executable JavaScript into the account name of a user's prof… |
CWE-79
Cross-site Scripting |
CVE-2020-13653 | 2024-11-21 14:01 | 2020-07-3 | Show | GitHub Exploit DB Packet Storm |
| 218086 | 9.8 |
CRITICAL
Network |
locutus | locutus_php | php/exec/escapeshellarg in Locutus PHP through 2.0.11 allows an attacker to achieve code execution. |
CWE-78
OS Command |
CVE-2020-13619 | 2024-11-21 14:01 | 2020-07-2 | Show | GitHub Exploit DB Packet Storm |
| 218087 | 7.5 |
HIGH
Network |
os4ed | opensis | openSIS through 7.4 allows Directory Traversal. |
CWE-22
Path Traversal |
CVE-2020-13383 | 2024-11-21 14:01 | 2020-07-2 | Show | GitHub Exploit DB Packet Storm |
| 218088 | 9.1 |
CRITICAL
Network |
os4ed | opensis | openSIS through 7.4 has Incorrect Access Control. |
CWE-306
Missing Authentication for Critical Function |
CVE-2020-13382 | 2024-11-21 14:01 | 2020-07-2 | Show | GitHub Exploit DB Packet Storm |
| 218089 | 9.8 |
CRITICAL
Network |
os4ed | opensis | openSIS through 7.4 allows SQL Injection. |
CWE-89
SQL Injection |
CVE-2020-13381 | 2024-11-21 14:01 | 2020-07-2 | Show | GitHub Exploit DB Packet Storm |
| 218090 | 9.8 |
CRITICAL
Network |
os4ed | opensis | openSIS before 7.4 allows SQL Injection. |
CWE-89
SQL Injection |
CVE-2020-13380 | 2024-11-21 14:01 | 2020-07-2 | Show | GitHub Exploit DB Packet Storm |