|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 6, 2026, noon
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 249871 | 5 | 警告 | アップル サイバートラスト株式会社 PNG Development Group サン・マイクロシステムズ レッドハット |
- | libpng の複数のチャンクハンドラにおけるサービス運用妨害 (DoS) の脆弱性 |
CWE-20
不適切な入力確認 |
CVE-2007-5269 | 2012-04-18 17:57 | 2007-10-8 | Show | GitHub Exploit DB Packet Storm |
| 249872 | 6.8 | 警告 | ニュートン アップル サイバートラスト株式会社 Mozilla Foundation PNG Development Group サン・マイクロシステムズ フェンリル株式会社 レッドハット |
- | libpng が適切にエレメントポインタを初期化しない脆弱性 |
CWE-94
コード・インジェクション |
CVE-2009-0040 | 2012-04-18 17:54 | 2009-03-4 | Show | GitHub Exploit DB Packet Storm |
| 249873 | 4.3 | 警告 | サン・マイクロシステムズ PNG Development Group |
- | libpng におけるサービス運用妨害 (DoS) 状態の脆弱性 |
CWE-399
リソース管理の問題 |
CVE-2008-3964 | 2012-04-18 17:52 | 2008-09-11 | Show | GitHub Exploit DB Packet Storm |
| 249874 | 4.3 | 警告 | フォーティネット Panda Security Doctor Web アラジン |
- | 複数の製品の ELF ファイルパーサにおけるマルウェア検知を回避される脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2012-1447 | 2012-04-18 17:38 | 2012-03-21 | Show | GitHub Exploit DB Packet Storm |
| 249875 | 6.8 | 警告 | Squid-cache.org | - | Gopher の gopherToHTML 関数におけるバッファオーバーフローの脆弱性 |
CWE-DesignError
|
CVE-2011-3205 | 2012-04-18 17:28 | 2011-08-28 | Show | GitHub Exploit DB Packet Storm |
| 249876 | 7.8 | 危険 | マイクロソフト 日本電気 |
- | Microsoft .NET Framework におけるサービス運用妨害 (CPU 資源の消費) の脆弱性 |
CWE-399
リソース管理の問題 |
CVE-2011-3414 | 2012-04-18 17:07 | 2011-12-29 | Show | GitHub Exploit DB Packet Storm |
| 249877 | 5 | 警告 | リアルネットワークス | - | RealNetworks Helix Server および Helix Mobile Server におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-20
不適切な入力確認 |
CVE-2012-2268 | 2012-04-18 15:30 | 2012-04-17 | Show | GitHub Exploit DB Packet Storm |
| 249878 | 5 | 警告 | リアルネットワークス | - | RealNetworks Helix Server および Helix Mobile Server におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2012-2267 | 2012-04-18 15:22 | 2012-04-17 | Show | GitHub Exploit DB Packet Storm |
| 249879 | 6.8 | 警告 | リアルネットワークス | - | RealNetworks Helix Server および Helix Mobile Server におけるクロスサイトリクエストフォージェリの脆弱性 |
CWE-352
同一生成元ポリシー違反 |
CVE-2012-1985 | 2012-04-18 15:21 | 2012-04-2 | Show | GitHub Exploit DB Packet Storm |
| 249880 | 4.3 | 警告 | リアルネットワークス | - | RealNetworks Helix Server および Helix Mobile Server におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2012-1984 | 2012-04-18 15:20 | 2012-04-2 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 6, 2026, 4:18 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 201601 | 7.5 |
HIGH
Network |
commscope | arris_tg1692a_firmware | ARRIS TG1692A devices allow remote attackers to discover the administrator login name and password by reading the /login page and performing base64 decoding. |
CWE-326
Inadequate Encryption Strength |
CVE-2020-9476 | 2024-11-21 14:40 | 2020-03-5 | Show | GitHub Exploit DB Packet Storm |
| 201602 | 7.8 |
HIGH
Local |
codepeople | appointment_booking_calendar | The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via t… |
CWE-1236
Improper Neutralization of Formula Elements in a CSV File |
CVE-2020-9372 | 2024-11-21 14:40 | 2020-03-5 | Show | GitHub Exploit DB Packet Storm |
| 201603 | 4.8 |
MEDIUM
Network |
codepeople | appointment_booking_calendar | Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php file, the Calendar Name input could allow attackers to inject arbitrary JavaScr… |
CWE-79
Cross-site Scripting |
CVE-2020-9371 | 2024-11-21 14:40 | 2020-03-5 | Show | GitHub Exploit DB Packet Storm |
| 201604 | 5.3 |
MEDIUM
Network |
creative-solutions | creative_contact_form | An issue was discovered in helpers/mailer.php in the Creative Contact Form extension 4.6.2 before 2019-12-03 for Joomla!. A directory traversal vulnerability resides in the filename field for uploade… |
CWE-22
Path Traversal |
CVE-2020-9364 | 2024-11-21 14:40 | 2020-03-5 | Show | GitHub Exploit DB Packet Storm |
| 201605 | 7.8 |
HIGH
Local |
pdfresurrect_project debian |
pdfresurrect debian_linux |
In PDFResurrect 0.12 through 0.19, get_type in pdf.c has an out-of-bounds write via a crafted PDF document. |
CWE-787
Out-of-bounds Write |
CVE-2020-9549 | 2024-11-21 14:40 | 2020-03-2 | Show | GitHub Exploit DB Packet Storm |
| 201606 | 7.5 |
HIGH
Network |
palemoon | pale_moon | Pale Moon 28.x before 28.8.4 has a segmentation fault related to module scripting, as demonstrated by a Lacoste web site. |
CWE-476
NULL Pointer Dereference |
CVE-2020-9545 | 2024-11-21 14:40 | 2020-03-2 | Show | GitHub Exploit DB Packet Storm |
| 201607 | 9.8 |
CRITICAL
Network |
fasterxml netapp debian oracle |
jackson-databind active_iq_unified_manager debian_linux retail_xstore_point_of_service primavera_unifier weblogic_server retail_merchandising_system agile_plm banking_digital_… |
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core). |
CWE-502
Deserialization of Untrusted Data |
CVE-2020-9548 | 2024-11-21 14:40 | 2020-03-2 | Show | GitHub Exploit DB Packet Storm |
| 201608 | 9.8 |
CRITICAL
Network |
fasterxml netapp debian oracle |
jackson-databind active_iq_unified_manager debian_linux retail_xstore_point_of_service primavera_unifier weblogic_server enterprise_manager_base_platform communications_instant_m… |
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibati… |
CWE-502
Deserialization of Untrusted Data |
CVE-2020-9547 | 2024-11-21 14:40 | 2020-03-2 | Show | GitHub Exploit DB Packet Storm |
| 201609 | 9.8 |
CRITICAL
Network |
fasterxml netapp debian oracle |
jackson-databind active_iq_unified_manager debian_linux retail_xstore_point_of_service primavera_unifier retail_service_backbone weblogic_server retail_merchandising_system ag… |
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hika… |
CWE-502
Deserialization of Untrusted Data |
CVE-2020-9546 | 2024-11-21 14:40 | 2020-03-2 | Show | GitHub Exploit DB Packet Storm |
| 201610 | 7.8 |
HIGH
Local |
sophos | hitmanpro.alert | Sophos HitmanPro.Alert before build 861 allows local elevation of privilege. |
NVD-CWE-noinfo
|
CVE-2020-9540 | 2024-11-21 14:40 | 2020-03-2 | Show | GitHub Exploit DB Packet Storm |