Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 17, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226481 7.5 危険 sweetphp - TotalCalendar の admin/manage_users.php における任意のパスワードを変更される脆弱性 CWE-287
不適切な認証
CVE-2009-4929 2012-12-20 19:28 2010-07-12 Show GitHub Exploit DB Packet Storm
226482 7.5 危険 sweetphp - TotalCalendar の config.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-4928 2012-12-20 19:28 2010-07-12 Show GitHub Exploit DB Packet Storm
226483 7.5 危険 webmobo - WB News における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2009-4927 2012-12-20 19:28 2010-07-12 Show GitHub Exploit DB Packet Storm
226484 6.8 警告 UnrealIRCd - UnrealIRCd におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-4893 2012-12-20 19:28 2010-06-15 Show GitHub Exploit DB Packet Storm
226485 7.5 危険 webjump - Content Management System WEBjump! における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4892 2012-12-20 19:28 2010-06-11 Show GitHub Exploit DB Packet Storm
226486 4.3 警告 retrieve - vBook のログインアプリケーションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4890 2012-12-20 19:28 2010-06-11 Show GitHub Exploit DB Packet Storm
226487 6.8 警告 sbuilder - CMS S.Builder の index.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-4887 2012-12-20 19:28 2010-06-11 Show GitHub Exploit DB Packet Storm
226488 7.5 危険 todd rogers - PHPRecipeBook の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4883 2012-12-20 19:28 2010-06-11 Show GitHub Exploit DB Packet Storm
226489 4.3 警告 zonecheck - ZoneCheck の zc/publisher/html.rb におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4882 2012-12-20 19:28 2010-05-26 Show GitHub Exploit DB Packet Storm
226490 6.8 警告 plain black - WebGUI におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2009-4877 2012-12-20 19:28 2010-05-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
222911 7.0 HIGH
Local
redhat openshift An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker with access to the container could use this flaw to modify /etc/passwd and esc… - CVE-2019-19351 2024-11-21 13:34 2020-03-19 Show GitHub Exploit DB Packet Storm
222912 4.4 MEDIUM
Local
redhat openshift During installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, with `kubeconfig` and `kubeadmin-password` files. Both files contain credentials … - CVE-2019-19335 2024-11-21 13:34 2020-03-19 Show GitHub Exploit DB Packet Storm
222913 7.2 HIGH
Network
sangoma freepbx In Sangoma FreePBX 13 through 15 and sysadmin (aka System Admin) 13.0.92 through 15.0.13.6 modules have a Remote Command Execution vulnerability that results in Privilege Escalation. NVD-CWE-noinfo
CVE-2019-19538 2024-11-21 13:34 2020-03-17 Show GitHub Exploit DB Packet Storm
222914 5.4 MEDIUM
Network
teampasswordmanager team_password_manager Post-authentication Stored XSS in Team Password Manager through 7.93.204 allows attackers to steal other users' credentials by creating a shared password with HTML code as the title. CWE-79
Cross-site Scripting
CVE-2019-19461 2024-11-21 13:34 2020-03-17 Show GitHub Exploit DB Packet Storm
222915 9.8 CRITICAL
Network
dolibarr dolibarr Dolibarr ERP/CRM 3.0 through 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen). CWE-79
Cross-site Scripting
CVE-2019-19212 2024-11-21 13:34 2020-03-17 Show GitHub Exploit DB Packet Storm
222916 7.4 HIGH
Network
opcfoundation ua-.netstandard
netstandard.opc.ua
In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Opc.Ua before 1.4.359.31, which allows man in the middle att… CWE-330
 Use of Insufficiently Random Values
CVE-2019-19135 2024-11-21 13:34 2020-03-17 Show GitHub Exploit DB Packet Storm
222917 6.1 MEDIUM
Network
dolibarr dolibarr Dolibarr ERP/CRM before 10.0.3 has an Insufficient Filtering issue that can lead to user/card.php XSS. CWE-79
Cross-site Scripting
CVE-2019-19211 2024-11-21 13:34 2020-03-17 Show GitHub Exploit DB Packet Storm
222918 5.4 MEDIUM
Network
dolibarr dolibarr Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files. CWE-79
Cross-site Scripting
CVE-2019-19210 2024-11-21 13:34 2020-03-17 Show GitHub Exploit DB Packet Storm
222919 7.5 HIGH
Network
dolibarr dolibarr Dolibarr ERP/CRM before 10.0.3 allows SQL Injection. CWE-89
SQL Injection
CVE-2019-19209 2024-11-21 13:34 2020-03-17 Show GitHub Exploit DB Packet Storm
222920 9.8 CRITICAL
Network
codiad codiad Codiad Web IDE through 2.8.4 allows PHP Code injection. CWE-94
Code Injection
CVE-2019-19208 2024-11-21 13:34 2020-03-17 Show GitHub Exploit DB Packet Storm