|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 16, 2026, 6 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 258371 | 5 | 警告 | Opera Software ASA | - | Opera の X.509 証明書における SSLサーバになりすまされる脆弱性 |
CWE-310
暗号の問題 |
CVE-2009-3044 | 2010-09-27 16:13 | 2009-09-1 | Show | GitHub Exploit DB Packet Storm |
| 258372 | 4.3 | 警告 | Opera Software ASA | - | Opera における data: URI をブロックしない脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-3013 | 2010-09-27 16:13 | 2009-08-31 | Show | GitHub Exploit DB Packet Storm |
| 258373 | 5 | 警告 | Opera Software ASA | - | Opera におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-399
リソース管理の問題 |
CVE-2009-2577 | 2010-09-27 16:12 | 2009-07-22 | Show | GitHub Exploit DB Packet Storm |
| 258374 | 4.3 | 警告 | Opera Software ASA | - | Opera におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-399
リソース管理の問題 |
CVE-2009-2540 | 2010-09-27 16:11 | 2009-07-20 | Show | GitHub Exploit DB Packet Storm |
| 258375 | 4.3 | 警告 | Opera Software ASA | - | Opera における javascript: URI をブロックしない脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-2351 | 2010-09-27 16:11 | 2009-07-7 | Show | GitHub Exploit DB Packet Storm |
| 258376 | 6.8 | 警告 | Opera Software ASA | - | Opera における任意の https サイトになりすまされる脆弱性 |
CWE-287
不適切な認証 |
CVE-2009-2070 | 2010-09-27 16:11 | 2009-06-15 | Show | GitHub Exploit DB Packet Storm |
| 258377 | 6.8 | 警告 | Opera Software ASA | - | Opera における任意の Web スクリプトを実行される脆弱性 |
CWE-287
不適切な認証 |
CVE-2009-2067 | 2010-09-27 16:10 | 2009-06-15 | Show | GitHub Exploit DB Packet Storm |
| 258378 | 6.8 | 警告 | Opera Software ASA | - | Opera における任意の Web スクリプトを実行される脆弱性 |
CWE-287
不適切な認証 |
CVE-2009-2063 | 2010-09-27 16:10 | 2009-06-15 | Show | GitHub Exploit DB Packet Storm |
| 258379 | 6.8 | 警告 | Opera Software ASA | - | Opera における任意の Web スクリプトを実行される脆弱性 |
CWE-287
不適切な認証 |
CVE-2009-2059 | 2010-09-27 16:10 | 2009-06-15 | Show | GitHub Exploit DB Packet Storm |
| 258380 | 9.3 | 危険 | アドビシステムズ Opera Software ASA |
- | Opera における Adobe Acrobat の JavaScript の制限を回避される脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2009-1599 | 2010-09-27 16:09 | 2009-05-11 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 16, 2026, 4:13 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 197351 | 7.5 |
HIGH
Network |
android | Calling of non-existent provider in MobileWips application prior to SMR Feb-2021 Release 1 allows unauthorized actions including denial of service attack by hijacking the provider. |
NVD-CWE-noinfo
|
CVE-2021-25330 | 2024-11-21 14:54 | 2021-03-3 | Show | GitHub Exploit DB Packet Storm | |
| 197352 | 9.8 |
CRITICAL
Network |
gigaset | dx600a_firmware | The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout or throttling functionality. This situation (together with the weak password p… |
CWE-307 CWE-521 mproper Restriction of Excessive Authentication Attempts Weak Password Requirements |
CVE-2021-25309 | 2024-11-21 14:54 | 2021-03-2 | Show | GitHub Exploit DB Packet Storm |
| 197353 | 7.5 |
HIGH
Network |
gigaset | dx600a_firmware | A buffer overflow vulnerability in the AT command interface of Gigaset DX600A v41.00-175 devices allows remote attackers to force a device reboot by sending relatively long AT commands. |
CWE-120
Classic Buffer Overflow |
CVE-2021-25306 | 2024-11-21 14:54 | 2021-03-2 | Show | GitHub Exploit DB Packet Storm |
| 197354 | 7.0 |
HIGH
Local |
apache debian oracle |
tomcat debian_linux managed_file_transfer instantis_enterprisetrack agile_plm database siebel_ui_framework mysql_enterprise_monitor graph_server_and_client communications_c… |
The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikel… |
NVD-CWE-noinfo
|
CVE-2021-25329 | 2024-11-21 14:54 | 2021-03-1 | Show | GitHub Exploit DB Packet Storm |
| 197355 | 7.5 |
HIGH
Network |
apache debian oracle |
tomcat debian_linux managed_file_transfer instantis_enterprisetrack agile_plm database siebel_ui_framework mysql_enterprise_monitor graph_server_and_client communications_c… |
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body… |
CWE-200
Information Exposure |
CVE-2021-25122 | 2024-11-21 14:54 | 2021-03-1 | Show | GitHub Exploit DB Packet Storm |
| 197356 | 4.4 |
MEDIUM
Local |
saltstack fedoraproject debian |
salt fedora debian_linux |
An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level. |
CWE-532 CWE-522 Inclusion of Sensitive Information in Log Files Insufficiently Protected Credentials |
CVE-2021-25284 | 2024-11-21 14:54 | 2021-02-27 | Show | GitHub Exploit DB Packet Storm |
| 197357 | 9.8 |
CRITICAL
Network |
saltstack fedoraproject debian |
salt fedora debian_linux |
An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks. |
CWE-94
Code Injection |
CVE-2021-25283 | 2024-11-21 14:54 | 2021-02-27 | Show | GitHub Exploit DB Packet Storm |
| 197358 | 9.1 |
CRITICAL
Network |
saltstack fedoraproject debian |
salt fedora debian_linux |
An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal. |
CWE-22
Path Traversal |
CVE-2021-25282 | 2024-11-21 14:54 | 2021-02-27 | Show | GitHub Exploit DB Packet Storm |
| 197359 | 9.8 |
CRITICAL
Network |
saltstack fedoraproject debian |
salt fedora debian_linux |
An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the mast… |
CWE-287
Improper Authentication |
CVE-2021-25281 | 2024-11-21 14:54 | 2021-02-27 | Show | GitHub Exploit DB Packet Storm |
| 197360 | 7.8 |
HIGH
Local |
microsoft |
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_7 windows_rt_8.1 windows_server_2019 |
Windows PKU2U Elevation of Privilege Vulnerability |
NVD-CWE-noinfo
|
CVE-2021-25195 | 2024-11-21 14:54 | 2021-02-26 | Show | GitHub Exploit DB Packet Storm |