|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 11, 2026, 6:01 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 226861 | 6.8 | 警告 | Simon Rycroft | - | SID における PHP リモートファイルインクルージョンの脆弱性 |
CWE-94
コード・インジェクション |
CVE-2008-7152 | 2012-12-20 19:10 | 2009-09-1 | Show | GitHub Exploit DB Packet Storm |
| 226862 | 10 | 危険 | synfig | - | Synfig Animation Studio における任意のコードを実行される脆弱性 |
CWE-noinfo
情報不足 |
CVE-2008-7148 | 2012-12-20 19:10 | 2009-09-1 | Show | GitHub Exploit DB Packet Storm |
| 226863 | 10 | 危険 | RARLAB | - | RARLAB WinRAR における脆弱性 |
CWE-noinfo
情報不足 |
CVE-2008-7144 | 2012-12-20 19:10 | 2009-09-1 | Show | GitHub Exploit DB Packet Storm |
| 226864 | 6.8 | 警告 | phpBB | - | phpBB におけるセッションをハイジャックされる脆弱性 |
CWE-200
情報漏えい |
CVE-2008-7143 | 2012-12-20 19:10 | 2009-09-1 | Show | GitHub Exploit DB Packet Storm |
| 226865 | 4.3 | 警告 | redgalaxy | - | Chris LaPointe RedGalaxy Download Center のデフォルト URI におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2008-7134 | 2012-12-20 19:10 | 2009-09-1 | Show | GitHub Exploit DB Packet Storm |
| 226866 | 5 | 警告 | xyssl | - | XySSL におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-399
リソース管理の問題 |
CVE-2008-7129 | 2012-12-20 19:10 | 2009-08-31 | Show | GitHub Exploit DB Packet Storm |
| 226867 | 7.5 | 危険 | xyssl | - | XySSL の ssl_parse_client_key_exchange 関数における鍵を回復される脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2008-7128 | 2012-12-20 19:10 | 2009-08-31 | Show | GitHub Exploit DB Packet Storm |
| 226868 | 7.5 | 危険 | zkup | - | zKup CMS における管理者権限を取得される脆弱性 |
CWE-287
不適切な認証 |
CVE-2008-7124 | 2012-12-20 19:10 | 2009-08-31 | Show | GitHub Exploit DB Packet Storm |
| 226869 | 6.8 | 警告 | zkup | - | zKup CMS の admin/configuration/modifier.php における任意の PHP コード挿入される脆弱性 |
CWE-94
コード・インジェクション |
CVE-2008-7123 | 2012-12-20 19:10 | 2009-08-31 | Show | GitHub Exploit DB Packet Storm |
| 226870 | 7.5 | 危険 | WeBid Support | - | WeBid auction script の item.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-7119 | 2012-12-20 19:10 | 2009-08-28 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 11, 2026, 4:09 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 223641 | 5.3 |
MEDIUM
Network |
swoole | swoole | Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler. |
CWE-22
Path Traversal |
CVE-2019-15518 | 2024-11-21 13:28 | 2019-08-24 | Show | GitHub Exploit DB Packet Storm |
| 223642 | 5.5 |
MEDIUM
Local |
jc21 | nginx_proxy_manager | jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal. |
CWE-22
Path Traversal |
CVE-2019-15517 | 2024-11-21 13:28 | 2019-08-24 | Show | GitHub Exploit DB Packet Storm |
| 223643 | 7.5 |
HIGH
Network |
cuberite | cuberite | Cuberite before 2019-06-11 allows webadmin directory traversal via ....// because the protection mechanism simply removes one ../ substring. |
CWE-22
Path Traversal |
CVE-2019-15516 | 2024-11-21 13:28 | 2019-08-24 | Show | GitHub Exploit DB Packet Storm |
| 223644 | 5.3 |
MEDIUM
Network |
telegram | telegram | The Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that the access level is Nobody, because attackers can find these numbers via the Grou… |
NVD-CWE-noinfo
|
CVE-2019-15514 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223645 | 9.8 |
CRITICAL
Network |
it-novum | openitcockpit | openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21. |
CWE-918
Server-Side Request Forgery (SSRF) |
CVE-2019-15494 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223646 | 7.5 |
HIGH
Network |
it-novum | openitcockpit | openITCOCKPIT before 3.7.1 allows deletion of files, aka RVID 4-445b21. |
NVD-CWE-noinfo
|
CVE-2019-15493 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223647 | 6.1 |
MEDIUM
Network |
it-novum | openitcockpit | openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21. |
CWE-79
Cross-site Scripting |
CVE-2019-15492 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223648 | 8.8 |
HIGH
Network |
it-novum | openitcockpit | openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21. |
CWE-352
Origin Validation Error |
CVE-2019-15491 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223649 | 9.8 |
CRITICAL
Network |
it-novum | openitcockpit | openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21. |
CWE-78
OS Command |
CVE-2019-15490 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223650 | 6.1 |
MEDIUM
Network |
igniterealtime | openfire | Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test. |
CWE-79
Cross-site Scripting |
CVE-2019-15488 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |