|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 27, 2026, 6 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 251891 | 7.1 | 危険 | シーメンス | - | 複数の Siemens 製品の HmiLoad におけるサービス運用妨害 (アプリケーションクラッシュ) の脆弱性 |
CWE-20
不適切な入力確認 |
CVE-2011-4877 | 2012-02-8 11:09 | 2012-01-24 | Show | GitHub Exploit DB Packet Storm |
| 251892 | 9.3 | 危険 | シーメンス | - | 複数の Siemens 製品の HmiLoad におけるディレクトリトラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2011-4876 | 2012-02-8 11:07 | 2012-01-24 | Show | GitHub Exploit DB Packet Storm |
| 251893 | 9.3 | 危険 | シーメンス | - | 複数の Siemens 製品の HmiLoad におけるスタックベースのバッファオーバーフローの脆弱性 |
CWE-119
バッファエラー |
CVE-2011-4875 | 2012-02-8 11:06 | 2012-01-24 | Show | GitHub Exploit DB Packet Storm |
| 251894 | 10 | 危険 | シーメンス | - | 複数の Siemens 製品の TELNET デーモンにおけるアクセス権を取得される脆弱性 |
CWE-287
不適切な認証 |
CVE-2011-4514 | 2012-02-8 11:00 | 2012-01-24 | Show | GitHub Exploit DB Packet Storm |
| 251895 | 10 | 危険 | シーメンス | - | 複数の Siemens 製品における任意のコードを実行される脆弱性 |
CWE-noinfo
情報不足 |
CVE-2011-4513 | 2012-02-8 10:56 | 2012-01-24 | Show | GitHub Exploit DB Packet Storm |
| 251896 | 5 | 警告 | シーメンス | - | 複数の Siemens 製品の HMI Web サーバにおける CRLF インジェクションの脆弱性 |
CWE-94
コード・インジェクション |
CVE-2011-4512 | 2012-02-8 10:54 | 2012-01-24 | Show | GitHub Exploit DB Packet Storm |
| 251897 | 4.3 | 警告 | シーメンス | - | 複数の Siemens 製品の HMI Web サーバにおけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2011-4511 | 2012-02-8 10:53 | 2012-01-24 | Show | GitHub Exploit DB Packet Storm |
| 251898 | 4.3 | 警告 | シーメンス | - | 複数の Siemens 製品の HMI Web サーバにおけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2011-4510 | 2012-02-8 10:51 | 2012-01-24 | Show | GitHub Exploit DB Packet Storm |
| 251899 | 10 | 危険 | シーメンス | - | 複数の Siemens 製品の HMI Web サーバにおけるアクセス権を取得される脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2011-4509 | 2012-02-8 10:50 | 2012-01-24 | Show | GitHub Exploit DB Packet Storm |
| 251900 | 10 | 危険 | シーメンス | - | 複数の Siemens 製品の HMI Web サーバにおける認証を回避される脆弱性 |
CWE-287
不適切な認証 |
CVE-2011-4508 | 2012-02-8 10:49 | 2012-01-24 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 28, 2026, 4:16 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 195591 | 8.6 |
HIGH
Network |
xstream_project debian fedoraproject oracle |
xstream debian_linux fedora banking_platform webcenter_portal communications_unified_inventory_management communications_policy_management banking_virtual_account_management c… |
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resour… | - | CVE-2021-21349 | 2024-11-21 14:48 | 2021-03-23 | Show | GitHub Exploit DB Packet Storm |
| 195592 | 7.5 |
HIGH
Network |
xstream_project debian fedoraproject oracle |
xstream debian_linux fedora banking_platform webcenter_portal communications_unified_inventory_management communications_policy_management banking_virtual_account_management c… |
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes max… |
CWE-400
Uncontrolled Resource Consumption |
CVE-2021-21348 | 2024-11-21 14:48 | 2021-03-23 | Show | GitHub Exploit DB Packet Storm |
| 195593 | 9.8 |
CRITICAL
Network |
xstream_project debian fedoraproject oracle |
xstream debian_linux fedora banking_platform weblogic_server webcenter_portal communications_unified_inventory_management communications_policy_management banking_virtual_acco… |
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code f… | - | CVE-2021-21347 | 2024-11-21 14:48 | 2021-03-23 | Show | GitHub Exploit DB Packet Storm |
| 195594 | 9.8 |
CRITICAL
Network |
xstream_project debian fedoraproject oracle |
xstream debian_linux fedora banking_platform webcenter_portal bi_publisher communications_unified_inventory_management communications_policy_management banking_virtual_account… |
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code f… | - | CVE-2021-21346 | 2024-11-21 14:48 | 2021-03-23 | Show | GitHub Exploit DB Packet Storm |
| 195595 | 9.9 |
CRITICAL
Network |
xstream_project debian fedoraproject oracle |
xstream debian_linux fedora banking_platform webcenter_portal communications_unified_inventory_management communications_policy_management peoplesoft_enterprise_peopletools ba… |
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute… |
CWE-78
OS Command |
CVE-2021-21345 | 2024-11-21 14:48 | 2021-03-23 | Show | GitHub Exploit DB Packet Storm |
| 195596 | 9.8 |
CRITICAL
Network |
xstream_project debian fedoraproject oracle |
xstream debian_linux fedora banking_platform webcenter_portal communications_unified_inventory_management communications_policy_management banking_virtual_account_management c… |
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code f… | - | CVE-2021-21344 | 2024-11-21 14:48 | 2021-03-23 | Show | GitHub Exploit DB Packet Storm |
| 195597 | 7.5 |
HIGH
Network |
xstream_project debian fedoraproject oracle |
xstream debian_linux fedora banking_platform webcenter_portal communications_unified_inventory_management communications_policy_management banking_virtual_account_management c… |
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type informa… | - | CVE-2021-21343 | 2024-11-21 14:48 | 2021-03-23 | Show | GitHub Exploit DB Packet Storm |
| 195598 | 9.1 |
CRITICAL
Network |
xstream_project debian fedoraproject oracle |
xstream debian_linux fedora banking_platform webcenter_portal communications_unified_inventory_management communications_policy_management banking_virtual_account_management b… |
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type informa… | - | CVE-2021-21342 | 2024-11-21 14:48 | 2021-03-23 | Show | GitHub Exploit DB Packet Storm |
| 195599 | 7.5 |
HIGH
Network |
xstream_project debian fedoraproject oracle |
xstream debian_linux fedora banking_platform webcenter_portal communications_unified_inventory_management communications_billing_and_revenue_management_elastic_charging_engine bu… |
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the targe… | - | CVE-2021-21341 | 2024-11-21 14:48 | 2021-03-23 | Show | GitHub Exploit DB Packet Storm |
| 195600 | 4.3 |
MEDIUM
Network |
otrs |
faq otrs |
Agents are able to see linked FAQ articles without permissions (defined in FAQ Category). This issue affects: FAQ version 6.0.29 and prior versions, OTRS version 7.0.24 and prior versions. |
CWE-276
Incorrect Default Permissions |
CVE-2021-21438 | 2024-11-21 14:48 | 2021-03-22 | Show | GitHub Exploit DB Packet Storm |