|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":Feb. 9, 2026, 12:59 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | 9.8 |
緊急
Network |
scshr | hr portal | scshrのhr portalにおける信頼できないデータのデシリアライゼーションに関する脆弱性 |
CWE-502
信頼性のないデータのデシリアライゼーション |
CVE-2025-48780 | 2026-02-6 10:41 | 2025-06-6 | Show | GitHub Exploit DB Packet Storm |
| 2 | 7.5 |
重要
Network |
scshr | hr portal | scshrのhr portalにおけるファイル名やパス名の外部制御に関する脆弱性 |
CWE-73
ファイル名やパス名の外部制御 |
CVE-2025-48781 | 2026-02-6 10:41 | 2025-06-6 | Show | GitHub Exploit DB Packet Storm |
| 3 | 9.8 |
緊急
Network |
scshr | hr portal | scshrのhr portalにおける危険なタイプのファイルの無制限アップロードに関する脆弱性 |
CWE-434
危険なタイプのファイルの無制限アップロード |
CVE-2025-48782 | 2026-02-6 10:41 | 2025-06-6 | Show | GitHub Exploit DB Packet Storm |
| 4 | 7.5 |
重要
Network |
scshr | hr portal | scshrのhr portalにおけるファイル名やパス名の外部制御に関する脆弱性 |
CWE-73
ファイル名やパス名の外部制御 |
CVE-2025-48783 | 2026-02-6 10:41 | 2025-06-6 | Show | GitHub Exploit DB Packet Storm |
| 5 | 7.5 |
重要
Network |
scshr | hr portal | scshrのhr portalにおける認証の欠如に関する脆弱性 |
CWE-862
認証の欠如 |
CVE-2025-48784 | 2026-02-6 10:41 | 2025-06-6 | Show | GitHub Exploit DB Packet Storm |
| 6 | 7.5 |
重要
Network |
scshr | hr portal | scshrのhr portalにおける重要な機能に対する認証の欠如に関する脆弱性 |
CWE-306
重要な機能に対する認証の欠如 解説 |
CVE-2025-5192 | 2026-02-6 10:41 | 2025-06-6 | Show | GitHub Exploit DB Packet Storm |
| 7 | 6.8 |
警告
Physics |
Elspec LTD | G5DFR ファームウェア | Elspec LTDのG5DFR ファームウェアにおける代替パスまたはチャネルを使用した認証回避に関する脆弱性 |
CWE-288
代替パスまたはチャネルを使用した認証回避 |
CVE-2025-59392 | 2026-02-6 10:41 | 2025-11-6 | Show | GitHub Exploit DB Packet Storm |
| 8 | 7.2 |
重要
Network |
Sangoma | freepbx | SangomaのfreepbxにおけるOS コマンドインジェクションの脆弱性 |
CWE-78
OSコマンド・インジェクション |
CVE-2025-64328 | 2026-02-6 10:41 | 2025-11-7 | Show | GitHub Exploit DB Packet Storm |
| 9 | 6.5 |
警告
Network |
Salesforce.com, inc. | MuleSoft Anypoint Extension Pack | Salesforce.com, inc.のMuleSoft Anypoint Extension Packにおけるコードインジェクションの脆弱性 |
CWE-94
コード・インジェクション |
CVE-2025-10875 | 2026-02-6 10:41 | 2025-11-4 | Show | GitHub Exploit DB Packet Storm |
| 10 | 7.5 |
重要
Network |
Intelbras | ICIP 30 Firmware | IntelbrasのICIP 30 Firmwareにおける複数の脆弱性 |
CWE-255 CWE-256 CWE-522 |
CVE-2025-13187 | 2026-02-6 10:41 | 2025-11-14 | Show | GitHub Exploit DB Packet Storm |
Update Date:April 15, 2026, 12:17 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 51 | 7.5 |
HIGH
Network |
xmlsoft redhat |
libxslt openshift_container_platform enterprise_linux |
Se encontró una falla en la librería libxslt. El mismo campo de memoria, psvi, se utiliza tanto para la hoja de estilo como para los datos de entrada, lo que puede provocar confusión de tipos durante… Update |
CWE-843
Type Confusion |
CVE-2025-7424 | 2026-04-15 07:16 | 2025-07-10 | Show | GitHub Exploit DB Packet Storm |
| 52 | 5.3 |
MEDIUM
Network |
- | - | The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on the redirect function in all versions up to, and including, 8.3.0. This ma… New |
CWE-862
Missing Authorization |
CVE-2025-15565 | 2026-04-15 07:16 | 2026-04-15 | Show | GitHub Exploit DB Packet Storm |
| 53 | 5.6 |
MEDIUM
Local |
- | - | A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an … Update |
CWE-362
Race Condition |
CVE-2024-12747 | 2026-04-15 07:16 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm |
| 54 | 5.6 |
MEDIUM
Local |
- | - | Se encontró un fallo en rsync. Esta vulnerabilidad surge de una condición de ejecución durante la gestión de enlaces simbólicos por parte de rsync. El comportamiento predeterminado de rsync cuando en… Update |
CWE-362
Race Condition |
CVE-2024-12747 | 2026-04-15 07:16 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm |
| 55 | 7.5 |
HIGH
Network |
samba redhat archlinux gentoo nixos novell tritondatacenter almalinux |
rsync discovery openshift_container_platform enterprise_linux enterprise_linux_eus enterprise_linux_for_arm_64 enterprise_linux_for_arm_64_eus enterprise_linux_for_ibm_z_systems<… |
A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it… Update |
CWE-22
Path Traversal |
CVE-2024-12088 | 2026-04-15 07:16 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm |
| 56 | 7.5 |
HIGH
Network |
samba redhat archlinux gentoo nixos novell tritondatacenter almalinux |
rsync discovery openshift_container_platform enterprise_linux enterprise_linux_eus enterprise_linux_for_arm_64 enterprise_linux_for_arm_64_eus enterprise_linux_for_ibm_z_systems<… |
Se encontró un fallo en rsync. Al usar la opción `--safe-links`, rsync no verifica correctamente si un destino de enlace simbólico contiene otro enlace simbólico dentro de él. Esto genera una vulnera… Update |
CWE-22
Path Traversal |
CVE-2024-12088 | 2026-04-15 07:16 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm |
| 57 | 7.5 |
HIGH
Network |
samba almalinux archlinux gentoo nixos suse tritondatacenter redhat |
rsync almalinux arch_linux linux nixos suse_linux smartos enterprise_linux enterprise_linux_eus enterprise_linux_for_arm_64 enterprise_linux_for_arm_64_eus enterprise… |
A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even … Update |
CWE-22
Path Traversal |
CVE-2024-12087 | 2026-04-15 07:16 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm |
| 58 | 7.5 |
HIGH
Network |
samba almalinux archlinux gentoo nixos suse tritondatacenter redhat |
rsync almalinux arch_linux linux nixos suse_linux smartos enterprise_linux enterprise_linux_eus enterprise_linux_for_arm_64 enterprise_linux_for_arm_64_eus enterprise… |
Existe una vulnerabilidad Path Traversal en rsync. Se origina en un comportamiento habilitado por la opción `--inc-recursive`, una opción habilitada de manera predeterminada para muchas opciones de c… Update |
CWE-22
Path Traversal |
CVE-2024-12087 | 2026-04-15 07:16 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm |
| 59 | 6.8 |
MEDIUM
Network |
samba redhat almalinux archlinux gentoo nixos suse tritondatacenter |
rsync openshift_container_platform enterprise_linux almalinux arch_linux linux nixos suse_linux smartos |
A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. D… Update |
CWE-390
Detection of Error Condition Without Action |
CVE-2024-12086 | 2026-04-15 07:16 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm |
| 60 | 6.8 |
MEDIUM
Network |
samba redhat almalinux archlinux gentoo nixos suse tritondatacenter |
rsync openshift_container_platform enterprise_linux almalinux arch_linux linux nixos suse_linux smartos |
Se encontró un fallo en rsync que podría permitir que un servidor enumere el contenido de un archivo arbitrario de la máquina del cliente. Este problema ocurre cuando se copian archivos de un cliente… Update |
CWE-390
Detection of Error Condition Without Action |
CVE-2024-12086 | 2026-04-15 07:16 | 2025-01-15 | Show | GitHub Exploit DB Packet Storm |