|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 11, 2026, 10 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 227141 | 7.5 | 危険 | tufat | - | MyCard の gallery.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-4738 | 2012-12-20 18:52 | 2008-10-24 | Show | GitHub Exploit DB Packet Storm |
| 227142 | 7.5 | 危険 | pressography | - | WordPress 用の WP Comment Remix プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 |
CWE-352
同一生成元ポリシー違反 |
CVE-2008-4734 | 2012-12-20 18:52 | 2008-10-24 | Show | GitHub Exploit DB Packet Storm |
| 227143 | 4.3 | 警告 | pressography | - | WordPress 用の WP Comment Remix プラグインにおけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2008-4733 | 2012-12-20 18:52 | 2008-10-24 | Show | GitHub Exploit DB Packet Storm |
| 227144 | 7.5 | 危険 | pressography | - | WordPress 用の WP Comment Remix プラグインにおける SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-4732 | 2012-12-20 18:52 | 2008-10-24 | Show | GitHub Exploit DB Packet Storm |
| 227145 | 4.3 | 警告 | CJ Niemira | - | phpMyID の MyID.php におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2008-4730 | 2012-12-20 18:52 | 2008-10-24 | Show | GitHub Exploit DB Packet Storm |
| 227146 | 4.3 | 警告 | sungard | - | SunGard Banner Student のコンタクトアップデートページにおけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2008-4727 | 2012-12-20 18:52 | 2008-10-23 | Show | GitHub Exploit DB Packet Storm |
| 227147 | 7.5 | 危険 | X7 Group | - | X7 Chat の help/mini.php におけるディレクトリトラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2008-4718 | 2012-12-20 18:52 | 2008-10-23 | Show | GitHub Exploit DB Packet Storm |
| 227148 | 7.5 | 危険 | zeeways | - | ZEELYRICS の bannerclick.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-4717 | 2012-12-20 18:52 | 2008-10-23 | Show | GitHub Exploit DB Packet Storm |
| 227149 | 7.5 | 危険 | scriptdemo | - | BitmixSoft PHP-Lance の show.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-4716 | 2012-12-20 18:52 | 2008-10-23 | Show | GitHub Exploit DB Packet Storm |
| 227150 | 7.5 | 危険 | pilotgroup | - | PG eTraining の news_read.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-4709 | 2012-12-20 18:52 | 2008-10-23 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 11, 2026, 4:09 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 196391 | 6.9 |
MEDIUM
Local |
mcafee | total_protection | Privilege Escalation vulnerability in the installer in McAfee McAfee Total Protection (MTP) trial prior to 4.0.161.1 allows local users to change files that are part of write protection rules via man… |
CWE-269
Improper Privilege Management |
CVE-2020-7310 | 2024-11-21 14:37 | 2020-08-21 | Show | GitHub Exploit DB Packet Storm |
| 196392 | 9.8 |
CRITICAL
Network |
irrelon |
\@irrelon\/path irrelon-path |
The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via the set, unSet, pushVal and pullVal functions. |
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
CVE-2020-7708 | 2024-11-21 14:37 | 2020-08-19 | Show | GitHub Exploit DB Packet Storm |
| 196393 | 9.8 |
CRITICAL
Network |
property-expr_project | property-expr | The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function. |
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
CVE-2020-7707 | 2024-11-21 14:37 | 2020-08-18 | Show | GitHub Exploit DB Packet Storm |
| 196394 | 9.8 |
CRITICAL
Network |
connie-lang_project | connie-lang | The package connie-lang before 0.1.1 are vulnerable to Prototype Pollution in the configuration language library used by connie. |
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
CVE-2020-7706 | 2024-11-21 14:37 | 2020-08-18 | Show | GitHub Exploit DB Packet Storm |
| 196395 | 9.8 |
CRITICAL
Network |
linux-cmdline_project | linux-cmdline | The package linux-cmdline before 1.0.1 are vulnerable to Prototype Pollution via the constructor. |
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
CVE-2020-7704 | 2024-11-21 14:37 | 2020-08-18 | Show | GitHub Exploit DB Packet Storm |
| 196396 | 9.8 |
CRITICAL
Network |
nis-utils_project | nis-utils | All versions of package nis-utils are vulnerable to Prototype Pollution via the setValue function. |
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
CVE-2020-7703 | 2024-11-21 14:37 | 2020-08-18 | Show | GitHub Exploit DB Packet Storm |
| 196397 | 9.8 |
CRITICAL
Network |
templ8_project | templ8 | All versions of package templ8 are vulnerable to Prototype Pollution via the parse function. |
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
CVE-2020-7702 | 2024-11-21 14:37 | 2020-08-17 | Show | GitHub Exploit DB Packet Storm |
| 196398 | 7.8 |
HIGH
Local |
siemens | automation_license_manager | A vulnerability has been identified in Automation License Manager 5 (All versions), Automation License Manager 6 (All versions < V6.0.8). The application does not properly validate the users' privile… |
CWE-863
Incorrect Authorization |
CVE-2020-7583 | 2024-11-21 14:37 | 2020-08-15 | Show | GitHub Exploit DB Packet Storm |
| 196399 | 9.8 |
CRITICAL
Network |
springtree | madlib-object-utils | madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue. |
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
CVE-2020-7701 | 2024-11-21 14:37 | 2020-08-15 | Show | GitHub Exploit DB Packet Storm |
| 196400 | 9.8 |
CRITICAL
Network |
php.js_project | php.js | All versions of phpjs are vulnerable to Prototype Pollution via parse_str. |
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
CVE-2020-7700 | 2024-11-21 14:37 | 2020-08-15 | Show | GitHub Exploit DB Packet Storm |