|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":Feb. 9, 2026, 12:59 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 223781 | 7.5 | 危険 | yarck | - | SH-News の action.php における認証を回避される脆弱性 |
CWE-287
不適切な認証 |
CVE-2008-6664 | 2012-12-20 19:10 | 2009-04-8 | Show | GitHub Exploit DB Packet Storm |
| 223782 | 7.5 | 危険 | phpauctions | - | PHPAuctions.info PHPAuctions の profile.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-6663 | 2012-12-20 19:10 | 2009-04-8 | Show | GitHub Exploit DB Packet Storm |
| 223783 | 4.3 | 警告 | structum | - | InfoBiz Server の search_results.php におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2008-6654 | 2012-12-20 19:10 | 2009-04-7 | Show | GitHub Exploit DB Packet Storm |
| 223784 | 7.5 | 危険 | wh-com | - | Joomla! および Mambo 用の webhosting.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-6653 | 2012-12-20 19:10 | 2009-04-7 | Show | GitHub Exploit DB Packet Storm |
| 223785 | 8.8 | 危険 | versalsoft | - | Versalsoft HTTP Image Uploader ActiveX コントロールにおける任意のファイルを削除される脆弱性 |
CWE-16
環境設定 |
CVE-2008-6638 | 2012-12-20 19:10 | 2009-04-7 | Show | GitHub Exploit DB Packet Storm |
| 223786 | 7.8 | 危険 | TYPO3 Association | - | TYPO3 用の wt_gallery エクステンションにおけるディレクトリトラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2008-6630 | 2012-12-20 19:10 | 2009-04-7 | Show | GitHub Exploit DB Packet Storm |
| 223787 | 4.3 | 警告 | webbdomain | - | WEBBDOMAIN Multi Languages WebShop Online の detail.php におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2008-6629 | 2012-12-20 19:10 | 2009-04-6 | Show | GitHub Exploit DB Packet Storm |
| 223788 | 7.5 | 危険 | webbdomain | - | WEBBDOMAIN WebShop の getin.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-6627 | 2012-12-20 19:10 | 2009-04-6 | Show | GitHub Exploit DB Packet Storm |
| 223789 | 7.5 | 危険 | webbdomain | - | WEBBDOMAIN Quiz の getin.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-6626 | 2012-12-20 19:10 | 2009-04-6 | Show | GitHub Exploit DB Packet Storm |
| 223790 | 7.5 | 危険 | webbdomain | - | WEBBDOMAIN Polls の getin.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-6625 | 2012-12-20 19:10 | 2009-04-6 | Show | GitHub Exploit DB Packet Storm |
Update Date:April 18, 2026, 4:11 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 1491 | 9.1 |
CRITICAL
Network |
siemens |
6gk5205-3bb00-2ab2_firmware 6gk5205-3bb00-2tb2_firmware 6gk5205-3bd00-2tb2_firmware 6gk5205-3bd00-2ab2_firmware 6gk5205-3bf00-2tb2_firmware 6gk5205-3bf00-2ab2_firmware 6gk5208-0ba00… |
Se ha identificado una vulnerabilidad en: SCALANCE XB205-3 (SC, PN) (V < 4.5), SCALANCE XB205-3 (ST, E/IP) (V < 4.5), SCALANCE XB205-3 (ST , E/IP) (V < 4.5), SCALANCE XB205-3 (ST, PN) (V… |
CWE-74
Injection |
CVE-2023-44373 | 2026-04-14 18:16 | 2023-11-14 | Show | GitHub Exploit DB Packet Storm |
| 1492 | 4.8 |
MEDIUM
Network |
siemens |
scalance_m-800_firmware scalance_s615_firmware scalance_sc-600_firmware scalance_sc622-2c_firmware scalance_sc632-2c_firmware scalance_sc636-2c_firmware scalance_sc642-2c_firmware | Affected devices do not properly sanitize data introduced by an user when rendering the web interface. This could allow an authenticated remote attacker with administrative privileges to inject code … |
CWE-80 NVD-CWE-Other Basic XSS |
CVE-2022-36325 | 2026-04-14 18:16 | 2022-08-10 | Show | GitHub Exploit DB Packet Storm |
| 1493 | 4.8 |
MEDIUM
Network |
siemens |
scalance_m-800_firmware scalance_s615_firmware scalance_sc-600_firmware scalance_sc622-2c_firmware scalance_sc632-2c_firmware scalance_sc636-2c_firmware scalance_sc642-2c_firmware | Los dispositivos afectados no sanean correctamente los datos introducidos por un usuario al renderizar la interfaz web. Esto podría permitir a un atacante remoto autenticado con privilegios administr… |
CWE-80 NVD-CWE-Other Basic XSS |
CVE-2022-36325 | 2026-04-14 18:16 | 2022-08-10 | Show | GitHub Exploit DB Packet Storm |
| 1494 | 7.5 |
HIGH
Network |
siemens |
scalance_m-800_firmware scalance_s615_firmware scalance_w700_ieee_802.11ax_firmware scalance_w700_ieee_802.11n_firmware scalance_w700_ieee_802.11ac_firmware scalance_xb-200_firmware | Affected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated remote attacker to bypass the TCP brute force prevention and lead to a denial of s… |
CWE-770
Allocation of Resources Without Limits or Throttling |
CVE-2022-36324 | 2026-04-14 18:16 | 2022-08-10 | Show | GitHub Exploit DB Packet Storm |
| 1495 | 7.5 |
HIGH
Network |
siemens |
scalance_m-800_firmware scalance_s615_firmware scalance_w700_ieee_802.11ax_firmware scalance_w700_ieee_802.11n_firmware scalance_w700_ieee_802.11ac_firmware scalance_xb-200_firmware | Los dispositivos afectados no manejan adecuadamente la renegociación de los parámetros SSL/TLS. Esto podría permitir a un atacante remoto no autenticado eludir la prevención de fuerza bruta de TCP y … |
CWE-770
Allocation of Resources Without Limits or Throttling |
CVE-2022-36324 | 2026-04-14 18:16 | 2022-08-10 | Show | GitHub Exploit DB Packet Storm |
| 1496 | 7.2 |
HIGH
Network |
siemens |
scalance_m-800_firmware scalance_s615_firmware scalance_sc-600_firmware scalance_sc622-2c_firmware scalance_sc632-2c_firmware scalance_sc636-2c_firmware scalance_sc642-2c_firmware | Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell. |
CWE-74 NVD-CWE-Other Injection |
CVE-2022-36323 | 2026-04-14 18:16 | 2022-08-10 | Show | GitHub Exploit DB Packet Storm |
| 1497 | 7.2 |
HIGH
Network |
siemens |
scalance_m-800_firmware scalance_s615_firmware scalance_sc-600_firmware scalance_sc622-2c_firmware scalance_sc632-2c_firmware scalance_sc636-2c_firmware scalance_sc642-2c_firmware | Los dispositivos afectados no sanean correctamente un campo de entrada. Esto podría permitir a un atacante remoto autenticado con privilegios administrativos inyectar código o generar un shell de raí… |
CWE-74 NVD-CWE-Other Injection |
CVE-2022-36323 | 2026-04-14 18:16 | 2022-08-10 | Show | GitHub Exploit DB Packet Storm |
| 1498 | 8.8 |
HIGH
Network |
siemens |
6gk6108-4am00-2ba2_firmware 6gk6108-4am00-2da2_firmware 6gk5804-0ap00-2aa2_firmware 6gk5812-1aa00-2aa2_firmware 6gk5812-1ba00-2aa2_firmware 6gk5816-1aa00-2aa2_firmware 6gk5816-1ba00… |
Affected devices do not properly authorize the change password function of the web interface. This could allow low privileged users to escalate their privileges. |
CWE-862
Missing Authorization |
CVE-2022-31765 | 2026-04-14 18:16 | 2022-10-11 | Show | GitHub Exploit DB Packet Storm |
| 1499 | 8.8 |
HIGH
Network |
siemens |
6gk6108-4am00-2ba2_firmware 6gk6108-4am00-2da2_firmware 6gk5804-0ap00-2aa2_firmware 6gk5812-1aa00-2aa2_firmware 6gk5812-1ba00-2aa2_firmware 6gk5816-1aa00-2aa2_firmware 6gk5816-1ba00… |
Los dispositivos afectados no autorizan apropiadamente la función change password de la interfaz web. Esto podría permitir a usuarios poco privilegiado escalar sus privilegios |
CWE-862
Missing Authorization |
CVE-2022-31765 | 2026-04-14 18:16 | 2022-10-11 | Show | GitHub Exploit DB Packet Storm |
| 1500 | 5.3 |
MEDIUM
Adjacent |
samsung arista siemens |
galaxy_i9305_firmware c-250_firmware c-260_firmware c-230_firmware c-235_firmware c-200_firmware c-120_firmware c-130_firmware c-100_firmware c-110_firmware o-105_firmwa… |
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfi… |
CWE-20
Improper Input Validation |
CVE-2020-26146 | 2026-04-14 18:16 | 2021-05-12 | Show | GitHub Exploit DB Packet Storm |