|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 11, 2026, 6:01 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 226991 | 7.5 | 危険 | PHPNUKE | - | PHP-Nuke 用の Sarkilar モジュールにおける SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-6779 | 2012-12-20 19:10 | 2009-05-1 | Show | GitHub Exploit DB Packet Storm |
| 226992 | 7.5 | 危険 | scripts-for-sites | - | SFS EZ Auction の viewfaqs.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-6778 | 2012-12-20 19:10 | 2009-05-1 | Show | GitHub Exploit DB Packet Storm |
| 226993 | 7.5 | 危険 | scripts-for-sites | - | SFS EZ Hot or Not の viewcomments.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-6776 | 2012-12-20 19:10 | 2009-05-1 | Show | GitHub Exploit DB Packet Storm |
| 226994 | 6.8 | 警告 | shopsystem-forum | - | K&S Shopsoftware の admin/editor/images.php における任意の PHP コードを実行される脆弱性 |
CWE-Other
その他 |
CVE-2008-6768 | 2012-12-20 19:10 | 2009-04-29 | Show | GitHub Exploit DB Packet Storm |
| 226995 | 10 | 危険 | WordPress.org | - | WordPress の wp-admin/upgrade.php におけるアプリケーションをアップグレードされる脆弱性 |
CWE-noinfo
情報不足 |
CVE-2008-6767 | 2012-12-20 19:10 | 2009-04-28 | Show | GitHub Exploit DB Packet Storm |
| 226996 | 5 | 警告 | viart | - | ViArt Shop の cart_save.php におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-noinfo
情報不足 |
CVE-2008-6766 | 2012-12-20 19:10 | 2009-04-28 | Show | GitHub Exploit DB Packet Storm |
| 226997 | 5 | 警告 | viart | - | ViArt Shop における任意のショッピングカートの中身にアクセスされる脆弱性 |
CWE-noinfo
情報不足 |
CVE-2008-6765 | 2012-12-20 19:10 | 2009-04-28 | Show | GitHub Exploit DB Packet Storm |
| 226998 | 4.3 | 警告 | WordPress.org | - | WordPress の wp-admin/upgrade.php におけるオープンリダイレクトの脆弱性 |
CWE-59
リンク解釈の問題 |
CVE-2008-6762 | 2012-12-20 19:10 | 2009-04-28 | Show | GitHub Exploit DB Packet Storm |
| 226999 | 4.3 | 警告 | viart | - | ViArt Shop における重要な情報を取得される脆弱性 |
CWE-59
リンク解釈の問題 |
CVE-2008-6760 | 2012-12-20 19:10 | 2009-04-28 | Show | GitHub Exploit DB Packet Storm |
| 227000 | 4.3 | 警告 | viart | - | ViArt Shop における重要な情報を取得される脆弱性 |
CWE-59
リンク解釈の問題 |
CVE-2008-6759 | 2012-12-20 19:10 | 2009-04-28 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 12, 2026, 5:06 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 223841 | 5.3 |
MEDIUM
Network |
telegram | telegram | The Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that the access level is Nobody, because attackers can find these numbers via the Grou… |
NVD-CWE-noinfo
|
CVE-2019-15514 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223842 | 9.8 |
CRITICAL
Network |
it-novum | openitcockpit | openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21. |
CWE-918
Server-Side Request Forgery (SSRF) |
CVE-2019-15494 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223843 | 7.5 |
HIGH
Network |
it-novum | openitcockpit | openITCOCKPIT before 3.7.1 allows deletion of files, aka RVID 4-445b21. |
NVD-CWE-noinfo
|
CVE-2019-15493 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223844 | 6.1 |
MEDIUM
Network |
it-novum | openitcockpit | openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21. |
CWE-79
Cross-site Scripting |
CVE-2019-15492 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223845 | 8.8 |
HIGH
Network |
it-novum | openitcockpit | openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21. |
CWE-352
Origin Validation Error |
CVE-2019-15491 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223846 | 9.8 |
CRITICAL
Network |
it-novum | openitcockpit | openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21. |
CWE-78
OS Command |
CVE-2019-15490 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223847 | 6.1 |
MEDIUM
Network |
igniterealtime | openfire | Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test. |
CWE-79
Cross-site Scripting |
CVE-2019-15488 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223848 | 6.1 |
MEDIUM
Network |
schoolexperience | department_for_education_school_experience | DfE School Experience before v16333-GA has XSS via a teacher training URL. |
CWE-79
Cross-site Scripting |
CVE-2019-15487 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223849 | 6.1 |
MEDIUM
Network |
django_js_reverse_project | django_js_reserve | django-js-reverse (aka Django JS Reverse) before 0.9.1 has XSS via js_reverse_inline. |
CWE-79
Cross-site Scripting |
CVE-2019-15486 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223850 | 6.1 |
MEDIUM
Network |
boltcms | bolt | Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php. |
CWE-79
Cross-site Scripting |
CVE-2019-15485 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |