|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 9, 2026, 4 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 250141 | 4.6 | 警告 | ヒューレット・パッカード IBM オラクル |
- | HP ALM 内の getInstalledPackages 関数における権限を取得される脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2011-4834 | 2011-12-19 15:08 | 2011-12-15 | Show | GitHub Exploit DB Packet Storm |
| 250142 | 7.5 | 危険 | SugarCRM | - | SugarCRM の Leads モジュールにおける SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2011-4833 | 2011-12-19 15:08 | 2011-12-15 | Show | GitHub Exploit DB Packet Storm |
| 250143 | 7.5 | 危険 | Moxiecode Systems AB phpMyFAQ PHPletter |
- | 複数の製品で使用される inc/function.base.php における PHP コードを挿入される脆弱性 |
CWE-94
コード・インジェクション |
CVE-2011-4825 | 2011-12-19 15:07 | 2011-10-25 | Show | GitHub Exploit DB Packet Storm |
| 250144 | 7.5 | 危険 | The Cacti Group | - | Cacti の auth_login.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2011-4824 | 2011-12-19 15:06 | 2011-09-26 | Show | GitHub Exploit DB Packet Storm |
| 250145 | 4.3 | 警告 | Atlassian | - | Atlassian FishEye のユーザプロファイル機能におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2011-4822 | 2011-12-19 15:05 | 2011-10-24 | Show | GitHub Exploit DB Packet Storm |
| 250146 | 3.6 | 注意 | Artsoft Entertainment | - | Artsoft Entertainment の Rocks'n'Diamonds における任意のファイルを上書きされる脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2011-4606 | 2011-12-19 15:05 | 2011-12-15 | Show | GitHub Exploit DB Packet Storm |
| 250147 | 4.3 | 警告 | Digium | - | Asterisk の channels/chan_sip.c におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-200
情報漏えい |
CVE-2011-4598 | 2011-12-19 15:03 | 2011-11-2 | Show | GitHub Exploit DB Packet Storm |
| 250148 | 5 | 警告 | Digium | - | Asterisk の UDP 実装での SIP におけるユーザ名を列挙される脆弱性 |
CWE-200
情報漏えい |
CVE-2011-4597 | 2011-12-19 15:01 | 2011-07-18 | Show | GitHub Exploit DB Packet Storm |
| 250149 | 7.5 | 危険 | Caupo.Net | - | CaupoShop Pro および CaupoShop Classic におけるディレクトリトラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2011-4832 | 2011-12-19 13:44 | 2011-12-15 | Show | GitHub Exploit DB Packet Storm |
| 250150 | 4 | 警告 | David Azoulay | - | Web File Browser の webFileBrowser.php におけるディレクトリトラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2011-4831 | 2011-12-19 13:43 | 2011-12-15 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 9, 2026, 5:07 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 211081 | 9.1 |
CRITICAL
Network |
qualcomm |
apq8096au_firmware aqt1000_firmware ar8031_firmware ar8035_firmware ar9380_firmware csr8811_firmware csra6620_firmware csra6640_firmware ipq4018_firmware ipq4028_firmware | Possible out of bound read while WLAN frame parsing due to lack of check for body and header length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Co… |
CWE-125
Out-of-bounds Read |
CVE-2020-11126 | 2024-11-21 13:56 | 2021-06-9 | Show | GitHub Exploit DB Packet Storm |
| 211082 | 7.1 |
HIGH
Network |
infinispan redhat netapp |
infinispan-server-rest data_grid oncommand_insight |
A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site reques… | - | CVE-2020-10771 | 2024-11-21 13:56 | 2021-06-2 | Show | GitHub Exploit DB Packet Storm |
| 211083 | 5.5 |
MEDIUM
Local |
linux | linux_kernel | A memory disclosure flaw was found in the Linux kernel's versions before 4.18.0-193.el8 in the sysctl subsystem when reading the /proc/sys/kernel/rh_features file. This flaw allows a local user to re… | - | CVE-2020-10774 | 2024-11-21 13:56 | 2021-05-28 | Show | GitHub Exploit DB Packet Storm |
| 211084 | 9.8 |
CRITICAL
Network |
qualcomm |
apq8017_firmware aqt1000_firmware ar8035_firmware csrb31024_firmware msm8917_firmware pm215_firmware pm3003a_firmware pm4125_firmware pm4250_firmware pm439_firmware pm45… |
Possible buffer overflow while updating ikev2 parameters due to lack of check of input validation for certain parameters received from the ePDG server in Snapdragon Auto, Snapdragon Compute, Snapdrag… |
CWE-129
Improper Validation of Array Index |
CVE-2020-11163 | 2024-11-21 13:56 | 2021-02-22 | Show | GitHub Exploit DB Packet Storm |
| 211085 | 6.7 |
MEDIUM
Local |
qualcomm |
aqt1000_firmware pm3003a_firmware pm456_firmware pm6125_firmware pm6150_firmware pm6150a_firmware pm6150l_firmware pm6250_firmware pm6350_firmware pm660_firmware pm660a_… |
Use after free issue in audio modules while removing and freeing objects during list iteration due to incorrect usage of macro in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile |
CWE-416
Use After Free |
CVE-2020-11147 | 2024-11-21 13:56 | 2021-02-22 | Show | GitHub Exploit DB Packet Storm |
| 211086 | 5.3 |
MEDIUM
Network |
zulip | zulip_desktop | Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permission request handler. |
CWE-862
Missing Authorization |
CVE-2020-10858 | 2024-11-21 13:56 | 2021-02-6 | Show | GitHub Exploit DB Packet Storm |
| 211087 | 9.8 |
CRITICAL
Network |
zulip | zulip_desktop | Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remote code execution. |
NVD-CWE-noinfo
|
CVE-2020-10857 | 2024-11-21 13:56 | 2021-02-6 | Show | GitHub Exploit DB Packet Storm |
| 211088 | 7.5 |
HIGH
Network |
qualcomm |
apq8009_firmware apq8017_firmware apq8053_firmware apq8076_firmware apq8096au_firmware aqt1000_firmware ar8031_firmware ar8035_firmware ar8151_firmware ar9380_firmware c… |
Buffer over-read can happen when the buffer length received from response handlers is more than the size of the payload in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Con… |
CWE-20 CWE-125 Improper Input Validation Out-of-bounds Read |
CVE-2020-11119 | 2024-11-21 13:56 | 2021-01-21 | Show | GitHub Exploit DB Packet Storm |
| 211089 | 6.4 |
MEDIUM
Local |
qualcomm |
msm8909w sdm630 qca6174a qca6574au qca6584au qca9377 msm8976 msm8937 msm8952 apq8096au msm8996au msm8917 sd450 sd835 sdx24 qcs605 sd855 qcs405 ap… |
Race condition in HAL layer while processing callback objects received from HIDL due to lack of synchronization between accessing objects in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer I… |
CWE-362
Race Condition |
CVE-2020-11152 | 2024-11-21 13:56 | 2021-01-21 | Show | GitHub Exploit DB Packet Storm |
| 211090 | 6.4 |
MEDIUM
Local |
qualcomm |
qca6574au qca6584au sdx55 sa6155p qca6390 qcm4290 qcs4290 sa8150p sa8155 sa8195p sda429w sdx55m sm7250p sd675 pm3003a pm6125 pm6150 pm6150a pm615… |
Race condition occurs while calling user space ioctl from two different threads can results to use after free issue in video in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdrago… |
CWE-362 CWE-416 Race Condition Use After Free |
CVE-2020-11151 | 2024-11-21 13:56 | 2021-01-21 | Show | GitHub Exploit DB Packet Storm |