|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 14, 2026, 4 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 250531 | 7.5 | 危険 | - | Google Chrome の Safe Browsing 機能におけるサービス運用妨害 (ヒープメモリ破損) の脆弱性 |
CWE-399
リソース管理の問題 |
CVE-2011-3925 | 2012-01-25 16:07 | 2012-01-23 | Show | GitHub Exploit DB Packet Storm | |
| 250532 | 4.3 | 警告 | SimpleSAMLphp | - | SimpleSAMLphp の modules/core/www/no_cookie.php におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2012-0040 | 2012-01-25 14:16 | 2012-01-24 | Show | GitHub Exploit DB Packet Storm |
| 250533 | 7.5 | 危険 | Stoneware | - | Stoneware webNetwork における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2012-0912 | 2012-01-25 14:15 | 2012-01-23 | Show | GitHub Exploit DB Packet Storm |
| 250534 | 6.8 | 警告 | Stoneware | - | Stoneware webNetwork におけるクロスサイトリクエストフォージェリの脆弱性 |
CWE-352
同一生成元ポリシー違反 |
CVE-2012-0286 | 2012-01-25 14:14 | 2012-01-23 | Show | GitHub Exploit DB Packet Storm |
| 250535 | 4.3 | 警告 | Stoneware | - | Stoneware webNetwork におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2012-0285 | 2012-01-25 14:13 | 2012-01-23 | Show | GitHub Exploit DB Packet Storm |
| 250536 | 5.8 | 警告 | NeoAxis | - | NeoAxis web player におけるディレクトリトラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2012-0907 | 2012-01-25 11:24 | 2012-01-20 | Show | GitHub Exploit DB Packet Storm |
| 250537 | 7.5 | 危険 | deV!L'z Clanportal | - | deV!L'z Clanportal (DZCP) の Moviebase アドオンにおける SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2012-0906 | 2012-01-25 11:00 | 2012-01-20 | Show | GitHub Exploit DB Packet Storm |
| 250538 | 7.5 | 危険 | deV!L'z Clanportal | - | deV!L'z Clanportal (DZCP) の Gamebase アドオンにおける SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2012-0905 | 2012-01-25 10:57 | 2012-01-20 | Show | GitHub Exploit DB Packet Storm |
| 250539 | 4.3 | 警告 | VideoLAN | - | VLC media player におけるサービス運用妨害 (クラッシュ) の脆弱性 |
CWE-399
リソース管理の問題 |
CVE-2012-0904 | 2012-01-25 10:54 | 2012-01-20 | Show | GitHub Exploit DB Packet Storm |
| 250540 | 4.3 | 警告 | VMware | - | VMware Zimbra Desktop におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2012-0903 | 2012-01-25 10:51 | 2012-01-20 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 14, 2026, 4 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 196661 | 6.8 |
MEDIUM
Physics |
lenovo |
thinkpad_e14_firmware thinkpad_e15_firmware thinkpad_r14_firmware thinkpad_s3_gen_2_firmware thinkpad_e490s_firmware thinkpad_s3_firmware thinkpad_e490_firmware thinkpad_e590_fir… |
Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmware in flash. |
NVD-CWE-noinfo
|
CVE-2020-8336 | 2024-11-21 14:38 | 2020-06-10 | Show | GitHub Exploit DB Packet Storm |
| 196662 | 6.8 |
MEDIUM
Physics |
lenovo |
thinkpad_t495s_firmware thinkpad_x395_firmware thinkpad_t495_firmware thinkpad_a485_firmware thinkpad_a285_firmware thinkpad_a475_firmware thinkpad_a275_firmware |
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T495s, X395, T495, A485, A285, A475, A275 which may allow for unauthorized access. |
CWE-754
Improper Check for Unusual or Exceptional Conditions |
CVE-2020-8334 | 2024-11-21 14:38 | 2020-06-10 | Show | GitHub Exploit DB Packet Storm |
| 196663 | 6.7 |
MEDIUM
Local |
lenovo |
330-14ast_firmware 330-15ast_firmware 330-17ast_firmware 340c-15api_firmware 340c-15ast_firmware 720s_touch-15ikb_firmware 720s-15ikb_firmware 730s-13iwl_firmware c640-iml_fir… |
A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution. |
NVD-CWE-noinfo
|
CVE-2020-8323 | 2024-11-21 14:38 | 2020-06-10 | Show | GitHub Exploit DB Packet Storm |
| 196664 | 6.7 |
MEDIUM
Local |
lenovo |
330-14ast_firmware 330-15ast_firmware 330-17ast_firmware 340c-15api_firmware 340c-15ast_firmware 720s_touch-15ikb_firmware 720s-15ikb_firmware 730s-13iwl_firmware c640-iml_fir… |
A potential vulnerability in the SMI callback function used in the Legacy USB driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution. |
NVD-CWE-noinfo
|
CVE-2020-8322 | 2024-11-21 14:38 | 2020-06-10 | Show | GitHub Exploit DB Packet Storm |
| 196665 | 6.7 |
MEDIUM
Local |
lenovo |
130-14ast_firmware 130-14ikb_firmware 130-15ast_firmware 130-15ikb_firmware 320c-15ikb_firmware 330-14igm_firmware 330-14ikb_firmware 330-14ikbr_firmware 330-15arr_firmware | A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution. |
NVD-CWE-noinfo
|
CVE-2020-8321 | 2024-11-21 14:38 | 2020-06-10 | Show | GitHub Exploit DB Packet Storm |
| 196666 | 6.8 |
MEDIUM
Physics |
lenovo |
thinkpad_11e_yoga_gen_6_firmware thinkpad_11e_firmware thinkpad_yoga_11e_3rd_gen_firmware thinkpad_yoga_11e_4th_gen_firmware thinkpad_yoga_11e_5th_gen_firmware thinkpad_13_2nd_gen_firm… |
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege. |
CWE-269
Improper Privilege Management |
CVE-2020-8320 | 2024-11-21 14:38 | 2020-06-10 | Show | GitHub Exploit DB Packet Storm |
| 196667 | 9.9 |
CRITICAL
Network |
nextcloud | talk | A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an administrator. |
CWE-94
Code Injection |
CVE-2020-8180 | 2024-11-21 14:38 | 2020-06-8 | Show | GitHub Exploit DB Packet Storm |
| 196668 | 7.4 |
HIGH
Network |
nodejs oracle |
node.js graalvm banking_extensibility_workbench mysql_cluster blockchain_platform |
TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0. |
CWE-295
Improper Certificate Validation |
CVE-2020-8172 | 2024-11-21 14:38 | 2020-06-8 | Show | GitHub Exploit DB Packet Storm |
| 196669 | 7.1 |
HIGH
Local |
bitdefender | antivirus_2020 | A vulnerability in the improper handling of symbolic links in Bitdefender Antivirus Free can allow an unprivileged user to substitute a quarantined file, and restore it to a privileged location. This… |
CWE-59
Link Following |
CVE-2020-8103 | 2024-11-21 14:38 | 2020-06-6 | Show | GitHub Exploit DB Packet Storm |
| 196670 | 5.5 |
MEDIUM
Local |
abb | device_library_wizard | Insecure storage of sensitive information in ABB Device Library Wizard versions 6.0.X, 6.0.3.1 and 6.0.3.2 allows unauthenticated low privilege user to read file that contains confidential data |
CWE-922
Insecure Storage of Sensitive Information |
CVE-2020-8482 | 2024-11-21 14:38 | 2020-05-30 | Show | GitHub Exploit DB Packet Storm |