|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 1, 2026, noon
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 228041 | 6.5 | 警告 | tufat | - | MyBackup の index.php における PHP リモートファイルインクルージョンの脆弱性 |
CWE-94
コード・インジェクション |
CVE-2009-4977 | 2012-12-20 19:28 | 2010-08-25 | Show | GitHub Exploit DB Packet Storm |
| 228042 | 7.5 | 危険 | sweetphp | - | TotalCalendar の box_display.php におけるディレクトリトラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2009-4974 | 2012-12-20 19:28 | 2010-07-28 | Show | GitHub Exploit DB Packet Storm |
| 228043 | 7.5 | 危険 | sweetphp | - | TotalCalendar の rss.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4973 | 2012-12-20 19:28 | 2010-07-28 | Show | GitHub Exploit DB Packet Storm |
| 228044 | 7.5 | 危険 | vincent tietz | - | TYPO3 用の AJAX Chat エクステンションにおける SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4971 | 2012-12-20 19:28 | 2010-07-28 | Show | GitHub Exploit DB Packet Storm |
| 228045 | 7.5 | 危険 | typo3-macher | - | TYPO3 用の t3m_affiliate エクステンションにおける SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4970 | 2012-12-20 19:28 | 2010-07-28 | Show | GitHub Exploit DB Packet Storm |
| 228046 | 7.5 | 危険 | TYPO3 Association | - | TYPO3 用の SBbanner エクステンションにおける SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4969 | 2012-12-20 19:28 | 2010-07-28 | Show | GitHub Exploit DB Packet Storm |
| 228047 | 7.5 | 危険 | thomas waggershauser | - | TYPO3 用の AIRware Lexicon エクステンションにおける SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4965 | 2012-12-20 19:28 | 2010-07-28 | Show | GitHub Exploit DB Packet Storm |
| 228048 | 5 | 警告 | ViewVC | - | ViewVC における非公開 root 名を発見される脆弱性 |
CWE-200
情報漏えい |
CVE-2010-0004 | 2012-12-20 19:28 | 2009-12-2 | Show | GitHub Exploit DB Packet Storm |
| 228049 | 4.3 | 警告 | Urs Wolfer | - | kwebkitpart の webkitpart.cpp におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-4976 | 2012-12-20 19:28 | 2009-12-5 | Show | GitHub Exploit DB Packet Storm |
| 228050 | 3.5 | 注意 | TYPO3 Association | - | TYPO3 用の Commerce エクステンションにおけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-4963 | 2012-12-20 19:28 | 2010-07-28 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 1, 2026, 4:12 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 220631 | 7.5 |
HIGH
Network |
z.cash | zcash | Zcash, before the Sapling network upgrade (2018-10-28), had a counterfeiting vulnerability. A key-generation process, during evaluation of polynomials related to a to-be-proven statement, produced ce… |
CWE-754
Improper Check for Unusual or Exceptional Conditions |
CVE-2019-7167 | 2024-11-21 13:47 | 2019-03-27 | Show | GitHub Exploit DB Packet Storm |
| 220632 | 6.1 |
MEDIUM
Network |
wpsupportplus | wp_support_plus_responsive_ticket_system | A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1.1 for WordPress allows remote attackers to inject arbitrar… |
CWE-79
Cross-site Scripting |
CVE-2019-7299 | 2024-11-21 13:47 | 2019-03-22 | Show | GitHub Exploit DB Packet Storm |
| 220633 | 5.4 |
MEDIUM
Network |
invoiceplane | invoiceplane | InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the "PDF password" field to the "Create Invoice" option. The XSS payload is rendered at an index.p… |
CWE-79
Cross-site Scripting |
CVE-2019-7223 | 2024-11-21 13:47 | 2019-03-22 | Show | GitHub Exploit DB Packet Storm |
| 220634 | 5.5 |
MEDIUM
Local |
linux fedoraproject opensuse debian canonical netapp redhat |
linux_kernel fedora leap debian_linux ubuntu_linux element_software_management_node active_iq_performance_analytics_services enterprise_linux_desktop enterprise_linux_workstat… |
The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak. |
NVD-CWE-noinfo
|
CVE-2019-7222 | 2024-11-21 13:47 | 2019-03-22 | Show | GitHub Exploit DB Packet Storm |
| 220635 | 7.8 |
HIGH
Local |
linux opensuse fedoraproject debian canonical netapp redhat |
linux_kernel leap fedora debian_linux ubuntu_linux element_software_management_node active_iq_performance_analytics_services enterprise_linux_desktop enterprise_linux_workstat… |
The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free. |
CWE-416
Use After Free |
CVE-2019-7221 | 2024-11-21 13:47 | 2019-03-22 | Show | GitHub Exploit DB Packet Storm |
| 220636 | 7.5 |
HIGH
Network |
zohocorp | manageengine_adselfservice_plus | An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving the capacity for an attacker to decipher any protec… |
CWE-798
Use of Hard-coded Credentials |
CVE-2019-7161 | 2024-11-21 13:47 | 2019-03-22 | Show | GitHub Exploit DB Packet Storm |
| 220637 | 7.5 |
HIGH
Network |
genivia | gsoap | Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server (based on gSOAP 2.8.x) is configured for an iterative queueing approach (aka no… |
NVD-CWE-noinfo
|
CVE-2019-6973 | 2024-11-21 13:47 | 2019-03-22 | Show | GitHub Exploit DB Packet Storm |
| 220638 | 7.5 |
HIGH
Network |
moodle | moodle | Moodle 3.5.x before 3.5.4 allows SSRF. |
CWE-918
Server-Side Request Forgery (SSRF) |
CVE-2019-6970 | 2024-11-21 13:47 | 2019-03-22 | Show | GitHub Exploit DB Packet Storm |
| 220639 | 8.8 |
HIGH
Network |
airties | air_5341_firmware | AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF. |
CWE-352
Origin Validation Error |
CVE-2019-6967 | 2024-11-21 13:47 | 2019-03-22 | Show | GitHub Exploit DB Packet Storm |
| 220640 | 7.8 |
HIGH
Local |
qemu opensuse fedoraproject canonical |
qemu leap fedora ubuntu_linux |
In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow. |
CWE-787
Out-of-bounds Write |
CVE-2019-6778 | 2024-11-21 13:47 | 2019-03-22 | Show | GitHub Exploit DB Packet Storm |