|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 15, 2026, 6 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 227641 | 7.5 | 危険 | yigit aybuga | - | Yigit Aybuga Dizi Portali の diziler.asp における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-6803 | 2012-12-20 19:10 | 2009-05-11 | Show | GitHub Exploit DB Packet Storm |
| 227642 | 7.5 | 危険 | phpexplorer | - | phPhotoGallery の index.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-6802 | 2012-12-20 19:10 | 2009-05-7 | Show | GitHub Exploit DB Packet Storm |
| 227643 | 4.4 | 警告 | vivvo | - | Vivvo CMS におけるクロスサイトリクエストフォージェリの脆弱性 |
CWE-352
同一生成元ポリシー違反 |
CVE-2008-6801 | 2012-12-20 19:10 | 2009-05-7 | Show | GitHub Exploit DB Packet Storm |
| 227644 | 7.5 | 危険 | tufat | - | FlashChat の connection.php におけるロールフィルタメカニズムを回避される脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2008-6799 | 2012-12-20 19:10 | 2009-05-7 | Show | GitHub Exploit DB Packet Storm |
| 227645 | 7.5 | 危険 | PreProject.com | - | Pre Projects Pre Real Estate Listings の login.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-6798 | 2012-12-20 19:10 | 2009-05-7 | Show | GitHub Exploit DB Packet Storm |
| 227646 | 7.5 | 危険 | PreProject.com | - | Pre Projects Pre Real Estate Listings の manager/login.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-6796 | 2012-12-20 19:10 | 2009-05-7 | Show | GitHub Exploit DB Packet Storm |
| 227647 | 7.5 | 危険 | sfs ez pub | - | SFS EZ Pub Site の directory.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-6794 | 2012-12-20 19:10 | 2009-05-7 | Show | GitHub Exploit DB Packet Storm |
| 227648 | 7.5 | 危険 | scripts-for-sites | - | SFS EZ Adult Directory の directory.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-6784 | 2012-12-20 19:10 | 2009-05-1 | Show | GitHub Exploit DB Packet Storm |
| 227649 | 7.5 | 危険 | scripts-for-sites | - | SFS EZ Home Business Directory の directory.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-6783 | 2012-12-20 19:10 | 2009-05-1 | Show | GitHub Exploit DB Packet Storm |
| 227650 | 7.5 | 危険 | scripts-for-sites | - | SFS EZ Hosting Directory の directory.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2008-6782 | 2012-12-20 19:10 | 2009-05-1 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 16, 2026, 4 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 224691 | 8.8 |
HIGH
Network |
facebook_for_woocommerce | The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility. |
CWE-352
Origin Validation Error |
CVE-2019-15841 | 2024-11-21 13:29 | 2019-08-31 | Show | GitHub Exploit DB Packet Storm | |
| 224692 | 8.8 |
HIGH
Network |
facebook_for_woocommerce | The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF. |
CWE-352
Origin Validation Error |
CVE-2019-15840 | 2024-11-21 13:29 | 2019-08-31 | Show | GitHub Exploit DB Packet Storm | |
| 224693 | 7.5 |
HIGH
Network |
shaosina | sina_extension_for_elementor | The sina-extension-for-elementor plugin before 2.2.1 for WordPress has local file inclusion. |
CWE-22 CWE-829 Path Traversal Inclusion of Functionality from Untrusted Control Sphere |
CVE-2019-15839 | 2024-11-21 13:29 | 2019-08-31 | Show | GitHub Exploit DB Packet Storm |
| 224694 | 6.1 |
MEDIUM
Network |
kunalnagar | custom_404_pro | The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789. |
CWE-79
Cross-site Scripting |
CVE-2019-15838 | 2024-11-21 13:29 | 2019-08-31 | Show | GitHub Exploit DB Packet Storm |
| 224695 | 5.4 |
MEDIUM
Network |
bitwise-it | webp_express | The webp-express plugin before 0.14.8 for WordPress has stored XSS. |
CWE-79
Cross-site Scripting |
CVE-2019-15837 | 2024-11-21 13:29 | 2019-08-31 | Show | GitHub Exploit DB Packet Storm |
| 224696 | 5.4 |
MEDIUM
Network |
bootstrapped | wp_ultimate_recipe | The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS. |
CWE-79
Cross-site Scripting |
CVE-2019-15836 | 2024-11-21 13:29 | 2019-08-31 | Show | GitHub Exploit DB Packet Storm |
| 224697 | 8.8 |
HIGH
Network |
wp_better_permalinks_project | wp_better_permalinks | The wp-better-permalinks plugin before 3.0.5 for WordPress has CSRF. |
CWE-352
Origin Validation Error |
CVE-2019-15835 | 2024-11-21 13:29 | 2019-08-31 | Show | GitHub Exploit DB Packet Storm |
| 224698 | 8.8 |
HIGH
Network |
webp_converter_for_media_project | webp_converter_for_media | The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF. |
CWE-352
Origin Validation Error |
CVE-2019-15834 | 2024-11-21 13:29 | 2019-08-31 | Show | GitHub Exploit DB Packet Storm |
| 224699 | 7.5 |
HIGH
Network |
mulesoft |
mule_runtime api_gateway |
Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before August 1 2019, MuleSoft Mule Runtime 4.1.0 and higher released … |
CWE-22
Path Traversal |
CVE-2019-15630 | 2024-11-21 13:29 | 2019-08-31 | Show | GitHub Exploit DB Packet Storm |
| 224700 | 6.1 |
MEDIUM
Network |
simple_mail_address_encoder_project | simple_mail_address_encoder | The simple-mail-address-encoder plugin before 1.7 for WordPress has reflected XSS. |
CWE-79
Cross-site Scripting |
CVE-2019-15833 | 2024-11-21 13:29 | 2019-08-30 | Show | GitHub Exploit DB Packet Storm |