|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 26, 2026, 6 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 246801 | 7.5 | 危険 | graugon | - | Graugon PHP Article Publisher における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4807 | 2012-06-26 16:19 | 2010-04-23 | Show | GitHub Exploit DB Packet Storm |
| 246802 | 7.5 | 危険 | digitalinterchange | - | Digital Interchange Document Library の admin/save_user.asp における管理者の資格情報を変更される脆弱性 |
CWE-287
不適切な認証 |
CVE-2009-4806 | 2012-06-26 16:19 | 2010-04-23 | Show | GitHub Exploit DB Packet Storm |
| 246803 | 7.5 | 危険 | TYPO3 Association andreas schwarzkopf |
- | TYPO3 の a21glossary 拡張における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4803 | 2012-06-26 16:19 | 2010-03-5 | Show | GitHub Exploit DB Packet Storm |
| 246804 | 5 | 警告 | diskos | - | Diskos CMS におけるデータベースをダウンロードされる脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2009-4799 | 2012-06-26 16:19 | 2010-04-22 | Show | GitHub Exploit DB Packet Storm |
| 246805 | 7.5 | 危険 | diskos | - | Diskos CMS における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4798 | 2012-06-26 16:19 | 2010-04-22 | Show | GitHub Exploit DB Packet Storm |
| 246806 | 7.5 | 危険 | glFusion | - | glFusion の private/system/classes/listfactory.class.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4796 | 2012-06-26 16:19 | 2010-04-22 | Show | GitHub Exploit DB Packet Storm |
| 246807 | 7.5 | 危険 | community cms | - | Community CMS における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4794 | 2012-06-26 16:19 | 2010-04-22 | Show | GitHub Exploit DB Packet Storm |
| 246808 | 7.5 | 危険 | bhavesh chauhan Joomla! |
- | Joomla! 用の Quick News コンポーネントにおける SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4785 | 2012-06-26 16:19 | 2010-04-21 | Show | GitHub Exploit DB Packet Storm |
| 246809 | 9.3 | 危険 | Blizzard Entertainment, Inc. | - | Warcraft III: The Frozen Throne の JASS スクリプトインタプリタにおける任意のコードを実行される脆弱性 |
CWE-94
コード・インジェクション |
CVE-2009-4768 | 2012-06-26 16:19 | 2010-04-20 | Show | GitHub Exploit DB Packet Storm |
| 246810 | 5 | 警告 | cnr.somee | - | CNR Hikaye Portal におけるデータベースをダウンロードされる脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2009-4765 | 2012-06-26 16:19 | 2010-04-13 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 27, 2026, 4:35 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 218961 | 5.3 |
MEDIUM
Network |
zyxel | cloudcnm_secumanager | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /cnr requests. |
CWE-862
Missing Authorization |
CVE-2020-15338 | 2024-11-21 14:05 | 2022-09-29 | Show | GitHub Exploit DB Packet Storm |
| 218962 | 5.3 |
MEDIUM
Network |
zyxel | cloudcnm_secumanager | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /registerCpe requests. |
CWE-862
Missing Authorization |
CVE-2020-15337 | 2024-11-21 14:05 | 2022-09-29 | Show | GitHub Exploit DB Packet Storm |
| 218963 | 5.3 |
MEDIUM
Network |
zyxel | cloudcnm_secumanager | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows escape-sequence injection into the /var/log/axxmpp.log file. |
NVD-CWE-Other
|
CVE-2020-15334 | 2024-11-21 14:05 | 2022-09-29 | Show | GitHub Exploit DB Packet Storm |
| 218964 | 5.3 |
MEDIUM
Network |
zyxel | cloudcnm_secumanager | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows attackers to discover accounts via MySQL "select * from Administrator_users" and "select * from Users_users" requests. |
CWE-89
SQL Injection |
CVE-2020-15333 | 2024-11-21 14:05 | 2022-09-29 | Show | GitHub Exploit DB Packet Storm |
| 218965 | 9.8 |
CRITICAL
Network |
zyxel | cloudcnm_secumanager | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions. |
CWE-312
Cleartext Storage of Sensitive Information |
CVE-2020-15332 | 2024-11-21 14:05 | 2022-09-29 | Show | GitHub Exploit DB Packet Storm |
| 218966 | 9.8 |
CRITICAL
Network |
zyxel | cloudcnm_secumanager | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess. |
CWE-311
Missing Encryption of Sensitive Data |
CVE-2020-15331 | 2024-11-21 14:05 | 2022-09-29 | Show | GitHub Exploit DB Packet Storm |
| 218967 | 5.3 |
MEDIUM
Network |
zyxel | cloudcnm_secumanager | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded APP_KEY in /opt/axess/etc/default/axess. |
CWE-311
Missing Encryption of Sensitive Data |
CVE-2020-15330 | 2024-11-21 14:05 | 2022-09-29 | Show | GitHub Exploit DB Packet Storm |
| 218968 | 5.3 |
MEDIUM
Network |
zyxel | cloudcnm_secumanager | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak Data.fs permissions. |
CWE-732
Incorrect Permission Assignment for Critical Resource |
CVE-2020-15329 | 2024-11-21 14:05 | 2022-09-29 | Show | GitHub Exploit DB Packet Storm |
| 218969 | 5.3 |
MEDIUM
Network |
zyxel | cloudcnm_secumanager | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/var/blobstorage/ permissions. |
CWE-732
Incorrect Permission Assignment for Critical Resource |
CVE-2020-15328 | 2024-11-21 14:05 | 2022-09-29 | Show | GitHub Exploit DB Packet Storm |
| 218970 | 7.5 |
HIGH
Network |
zyxel | cloudcnm_secumanager | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication. |
CWE-798
Use of Hard-coded Credentials |
CVE-2020-15327 | 2024-11-21 14:05 | 2022-09-29 | Show | GitHub Exploit DB Packet Storm |