|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 4, 2026, 4 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 249331 | 5 | 警告 | Bradford Networks | - | Bradford Network Sentry のエージェントにおけるワークステーション上で任意のテキストを表示される脆弱性 |
CWE-287
不適切な認証 |
CVE-2012-2606 | 2012-06-14 16:28 | 2012-06-13 | Show | GitHub Exploit DB Packet Storm |
| 249332 | 6.8 | 警告 | Bradford Networks | - | Bradford Network Sentry の管理インタフェースにおけるクロスサイトリクエストフォージェリの脆弱性 |
CWE-352
同一生成元ポリシー違反 |
CVE-2012-2605 | 2012-06-14 16:26 | 2012-06-13 | Show | GitHub Exploit DB Packet Storm |
| 249333 | 3.5 | 注意 | Bradford Networks | - | Bradford Network Sentry の GuestAccess.jsp におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2012-2604 | 2012-06-14 16:24 | 2012-06-13 | Show | GitHub Exploit DB Packet Storm |
| 249334 | 4.3 | 警告 | アドビシステムズ | - | Adobe ColdFusion のコンポーネントブラウザにおける CRLF インジェクションの脆弱性 |
CWE-94
コード・インジェクション |
CVE-2012-2041 | 2012-06-14 15:21 | 2012-06-12 | Show | GitHub Exploit DB Packet Storm |
| 249335 | 2.6 | 注意 | MoboTap | - | Dolphin Browser における WebView クラスに関する脆弱性 |
CWE-Other
その他 |
CVE-2012-2635 | 2012-06-14 12:01 | 2012-06-14 | Show | GitHub Exploit DB Packet Storm |
| 249336 | 9.3 | 危険 | アップル | - | Apple iTunes におけるヒープベースのバッファオーバーフローの脆弱性 |
CWE-119
バッファエラー |
CVE-2012-0677 | 2012-06-14 11:51 | 2012-06-12 | Show | GitHub Exploit DB Packet Storm |
| 249337 | 7.2 | 危険 | アドビシステムズ | - | Adobe Flash Player および Adobe AIR のインストーラにおける権限を取得される脆弱性 |
CWE-Other
その他 |
CVE-2012-2040 | 2012-06-13 16:43 | 2012-06-8 | Show | GitHub Exploit DB Packet Storm |
| 249338 | 10 | 危険 | アドビシステムズ | - | Adobe Flash Player および Adobe AIR における任意のコードを実行される脆弱性 |
CWE-119
バッファエラー |
CVE-2012-2039 | 2012-06-13 16:42 | 2012-06-8 | Show | GitHub Exploit DB Packet Storm |
| 249339 | 2.6 | 注意 | アドビシステムズ | - | Flash Player における同一生成元ポリシー実装不備の脆弱性 |
CWE-Other
その他 |
CVE-2012-2038 | 2012-06-13 16:32 | 2012-06-11 | Show | GitHub Exploit DB Packet Storm |
| 249340 | 10 | 危険 | アドビシステムズ | - | Adobe Flash Player および Adobe AIR における任意のコードを実行される脆弱性 |
CWE-119
バッファエラー |
CVE-2012-2037 | 2012-06-13 16:30 | 2012-06-8 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 5, 2026, 4:11 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 209761 | 8.1 |
HIGH
Network |
bbraun |
datamodule_compactplus spacecom |
A session fixation vulnerability in the B. Braun Melsungen AG SpaceCom administrative interface Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attacke… | - | CVE-2020-25152 | 2024-11-21 14:17 | 2022-04-15 | Show | GitHub Exploit DB Packet Storm |
| 209762 | 8.8 |
HIGH
Network |
bbraun |
datamodule_compactplus spacecom |
A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with service user privileges … |
CWE-22
Path Traversal |
CVE-2020-25150 | 2024-11-21 14:17 | 2022-04-15 | Show | GitHub Exploit DB Packet Storm |
| 209763 | 8.8 |
HIGH
Network |
ge |
rt430_firmware rt431_firmware rt434_firmware |
A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06 that could allow an authenticated remote attacke… |
CWE-94
Code Injection |
CVE-2020-25197 | 2024-11-21 14:17 | 2022-03-19 | Show | GitHub Exploit DB Packet Storm |
| 209764 | 5.3 |
MEDIUM
Network |
ge |
rt430_firmware rt431_firmware rt434_firmware |
By having access to the hard-coded cryptographic key for GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06, attackers would be able to intercept and decrypt encry… |
CWE-798
Use of Hard-coded Credentials |
CVE-2020-25193 | 2024-11-21 14:17 | 2022-03-19 | Show | GitHub Exploit DB Packet Storm |
| 209765 | 5.5 |
MEDIUM
Local |
schneider-electric rockwellautomation xylem |
easergy_t300_firmware easergy_c5_firmware micom_c264_firmware pacis_gtw_firmware saitel_dp_firmware epas_gtw_firmware saitel_dr_firmware scd2200_firmware isagraf_free_runtime<… |
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the … |
CWE-522
Insufficiently Protected Credentials |
CVE-2020-25184 | 2024-11-21 14:17 | 2022-03-19 | Show | GitHub Exploit DB Packet Storm |
| 209766 | 6.7 |
MEDIUM
Local |
schneider-electric rockwellautomation xylem |
easergy_t300_firmware easergy_c5_firmware micom_c264_firmware pacis_gtw_firmware saitel_dp_firmware epas_gtw_firmware saitel_dr_firmware scd2200_firmware isagraf_free_runtime<… |
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled loading of dynamic libraries could allow a local, unauthenticated attacker to e… |
CWE-427
Uncontrolled Search Path Element |
CVE-2020-25182 | 2024-11-21 14:17 | 2022-03-19 | Show | GitHub Exploit DB Packet Storm |
| 209767 | 6.5 |
MEDIUM
Network |
schneider-electric rockwellautomation xylem |
easergy_t300_firmware easergy_c5_firmware micom_c264_firmware pacis_gtw_firmware saitel_dp_firmware epas_gtw_firmware saitel_dr_firmware scd2200_firmware isagraf_free_runtime<… |
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime… |
CWE-798
Use of Hard-coded Credentials |
CVE-2020-25180 | 2024-11-21 14:17 | 2022-03-19 | Show | GitHub Exploit DB Packet Storm |
| 209768 | 8.8 |
HIGH
Network |
schneider-electric rockwellautomation xylem |
easergy_t300_firmware easergy_c5_firmware micom_c264_firmware pacis_gtw_firmware saitel_dp_firmware epas_gtw_firmware saitel_dr_firmware scd2200_firmware isagraf_free_runtime<… |
ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as well as the uploadin… |
CWE-319
Cleartext Transmission of Sensitive Information |
CVE-2020-25178 | 2024-11-21 14:17 | 2022-03-19 | Show | GitHub Exploit DB Packet Storm |
| 209769 | 9.8 |
CRITICAL
Network |
schneider-electric rockwellautomation xylem |
easergy_t300_firmware easergy_c5_firmware micom_c264_firmware pacis_gtw_firmware saitel_dp_firmware epas_gtw_firmware saitel_dr_firmware scd2200_firmware isagraf_free_runtime<… |
Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to th… |
CWE-22
Path Traversal |
CVE-2020-25176 | 2024-11-21 14:17 | 2022-03-19 | Show | GitHub Exploit DB Packet Storm |
| 209770 | 5.5 |
MEDIUM
Local |
gpac | gpac | A Null pointer dereference vulnerability exits in MP4Box - GPAC version 0.8.0-rev177-g51a8ef874-master via the gf_isom_get_track_id function, which causes a denial of service. |
CWE-476
NULL Pointer Dereference |
CVE-2020-25427 | 2024-11-21 14:17 | 2022-01-11 | Show | GitHub Exploit DB Packet Storm |