|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 12, 2026, 6 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 229271 | 4.3 | 警告 | vikingboard | - | Vikingboard におけるクロスサイトスクリプティングの脆弱性 | - | CVE-2007-4090 | 2012-12-20 18:33 | 2007-07-30 | Show | GitHub Exploit DB Packet Storm |
| 229272 | 4.3 | 警告 | wp-feedstats | - | WordPress 用の WP-FeedStats プラグインにおけるクロスサイトスクリプティングの脆弱性 | - | CVE-2007-4104 | 2012-12-20 18:33 | 2006-08-17 | Show | GitHub Exploit DB Packet Storm |
| 229273 | 7.5 | 危険 | wikiwebweaver | - | WikiWebWeaver の index.php における任意のコードを実行される脆弱性 | - | CVE-2007-4182 | 2012-12-20 18:33 | 2007-08-7 | Show | GitHub Exploit DB Packet Storm |
| 229274 | 5.8 | 警告 | The Tor Project | - | Tor における torrc 設定ファイルを変更される脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2007-4174 | 2012-12-20 18:33 | 2007-08-7 | Show | GitHub Exploit DB Packet Storm |
| 229275 | 5 | 警告 | WordPress.org | - | WordPress 用の Unnamed テーマなどの index.php におけるクロスサイトスクリプティングの脆弱性 | - | CVE-2007-4166 | 2012-12-20 18:33 | 2007-08-7 | Show | GitHub Exploit DB Packet Storm |
| 229276 | 4.3 | 警告 | WordPress.org xu yiyang |
- | WordPress 用の Blue Memories テーマの index.php におけるクロスサイトスクリプティングの脆弱性 | - | CVE-2007-4165 | 2012-12-20 18:33 | 2007-08-7 | Show | GitHub Exploit DB Packet Storm |
| 229277 | 7.8 | 危険 | TIBCO Software | - | TIBCO RV におけるトラフィックをキャプチャされる脆弱性 | - | CVE-2007-4162 | 2012-12-20 18:33 | 2007-08-3 | Show | GitHub Exploit DB Packet Storm |
| 229278 | 4.3 | 警告 | TIBCO Software | - | TIBCO RV の rvd におけるサービス運用妨害 (DoS) の脆弱性 | - | CVE-2007-4161 | 2012-12-20 18:33 | 2007-08-3 | Show | GitHub Exploit DB Packet Storm |
| 229279 | 4.3 | 警告 | vikingboard | - | Vikingboard における重要な情報を取得される脆弱性 | - | CVE-2007-4089 | 2012-12-20 18:33 | 2007-07-30 | Show | GitHub Exploit DB Packet Storm |
| 229280 | 4.3 | 警告 | vikingboard | - | Vikingboard におけるクロスサイトスクリプティングの脆弱性 | - | CVE-2007-4088 | 2012-12-20 18:33 | 2007-07-30 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 12, 2026, 5:06 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 223841 | 5.3 |
MEDIUM
Network |
telegram | telegram | The Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that the access level is Nobody, because attackers can find these numbers via the Grou… |
NVD-CWE-noinfo
|
CVE-2019-15514 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223842 | 9.8 |
CRITICAL
Network |
it-novum | openitcockpit | openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21. |
CWE-918
Server-Side Request Forgery (SSRF) |
CVE-2019-15494 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223843 | 7.5 |
HIGH
Network |
it-novum | openitcockpit | openITCOCKPIT before 3.7.1 allows deletion of files, aka RVID 4-445b21. |
NVD-CWE-noinfo
|
CVE-2019-15493 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223844 | 6.1 |
MEDIUM
Network |
it-novum | openitcockpit | openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21. |
CWE-79
Cross-site Scripting |
CVE-2019-15492 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223845 | 8.8 |
HIGH
Network |
it-novum | openitcockpit | openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21. |
CWE-352
Origin Validation Error |
CVE-2019-15491 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223846 | 9.8 |
CRITICAL
Network |
it-novum | openitcockpit | openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21. |
CWE-78
OS Command |
CVE-2019-15490 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223847 | 6.1 |
MEDIUM
Network |
igniterealtime | openfire | Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test. |
CWE-79
Cross-site Scripting |
CVE-2019-15488 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223848 | 6.1 |
MEDIUM
Network |
schoolexperience | department_for_education_school_experience | DfE School Experience before v16333-GA has XSS via a teacher training URL. |
CWE-79
Cross-site Scripting |
CVE-2019-15487 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223849 | 6.1 |
MEDIUM
Network |
django_js_reverse_project | django_js_reserve | django-js-reverse (aka Django JS Reverse) before 0.9.1 has XSS via js_reverse_inline. |
CWE-79
Cross-site Scripting |
CVE-2019-15486 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |
| 223850 | 6.1 |
MEDIUM
Network |
boltcms | bolt | Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php. |
CWE-79
Cross-site Scripting |
CVE-2019-15485 | 2024-11-21 13:28 | 2019-08-23 | Show | GitHub Exploit DB Packet Storm |