Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226501 7.5 危険 phpsmartcom - phpSmartCom の inc/pages/viewprofile.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4352 2012-12-20 18:52 2008-09-30 Show GitHub Exploit DB Packet Storm
226502 7.5 危険 phpsmartcom - phpSmartCom の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-4351 2012-12-20 18:52 2008-09-30 Show GitHub Exploit DB Packet Storm
226503 7.5 危険 vblogix - vbLOGIX Tutorial Script の main.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4350 2012-12-20 18:52 2008-09-30 Show GitHub Exploit DB Packet Storm
226504 4.3 警告 s0nic - s0nic Paranews の news.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-4349 2012-12-20 18:52 2008-09-30 Show GitHub Exploit DB Packet Storm
226505 7.5 危険 Powie - Powie pNews の newskom.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4347 2012-12-20 18:52 2008-09-30 Show GitHub Exploit DB Packet Storm
226506 7.5 危険 talkback - TalkBack におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-4346 2012-12-20 18:52 2008-09-30 Show GitHub Exploit DB Packet Storm
226507 7.5 危険 webportal - WebPortal CMS の download.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4345 2012-12-20 18:52 2008-09-30 Show GitHub Exploit DB Packet Storm
226508 6 警告 vacilanda - Drupal 用の Brilliant Gallery モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4338 2012-12-20 18:52 2008-09-30 Show GitHub Exploit DB Packet Storm
226509 7.5 危険 phpocs - phpOCS の library/pagefunctions.inc.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-4331 2012-12-20 18:52 2008-09-30 Show GitHub Exploit DB Packet Storm
226510 5.8 警告 ViewVC - ViewVC の lib/viewvc.py におけるブラウザにコンテンツを誤って解釈させる脆弱性 CWE-noinfo
情報不足
CVE-2008-4325 2012-12-20 18:52 2008-06-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
212491 8.8 HIGH
Network
strato
telekom
ionos
hidrive_desktop_client
magentacloud
1\&1_online_storage
STRATO HiDrive Desktop Client 5.0.1.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the HiDriveMaintenanceService service. This service establishes a NetNamedPipe endpo… CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2019-9486 2024-11-21 13:51 2019-05-1 Show GitHub Exploit DB Packet Storm
212492 7.5 HIGH
Network
zimbra collaboration_server Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component. CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2019-9621 2024-11-21 13:51 2019-05-1 Show GitHub Exploit DB Packet Storm
212493 7.8 HIGH
Local
datools daviewindy DaviewIndy 8.98.7 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed PDF file that is mishandled by Daview.exe. Attackers could exploit this and arb… CWE-190
 Integer Overflow or Wraparound
CVE-2019-9139 2024-11-21 13:51 2019-04-26 Show GitHub Exploit DB Packet Storm
212494 7.8 HIGH
Local
datools daviewindy DaviewIndy 8.98.7 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed PhotoShop file that is mishandled by Daview.exe. Attackers could exploit this a… CWE-190
 Integer Overflow or Wraparound
CVE-2019-9138 2024-11-21 13:51 2019-04-26 Show GitHub Exploit DB Packet Storm
212495 7.8 HIGH
Local
hmtalk daviewindy DaviewIndy 8.98.7 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed Image file that is mishandled by Daview.exe. Attackers could exploit this and a… CWE-190
 Integer Overflow or Wraparound
CVE-2019-9137 2024-11-21 13:51 2019-04-26 Show GitHub Exploit DB Packet Storm
212496 7.8 HIGH
Local
datools daviewindy DaviewIndy 8.98.7 and earlier versions have a Heap-based overflow vulnerability, triggered when the user opens a malformed JPEG2000 format file that is mishandled by Daview.exe. Attackers could explo… CWE-787
 Out-of-bounds Write
CVE-2019-9136 2024-11-21 13:51 2019-04-26 Show GitHub Exploit DB Packet Storm
212497 7.8 HIGH
Local
datools daviewindy DaviewIndy 8.98.7 and earlier versions have a Heap-based overflow vulnerability, triggered when the user opens a malformed DIB format file that is mishandled by Daview.exe. Attackers could exploit th… CWE-787
 Out-of-bounds Write
CVE-2019-9135 2024-11-21 13:51 2019-04-26 Show GitHub Exploit DB Packet Storm
212498 9.8 CRITICAL
Network
xinruidz sundray_wan_controller_firmware WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a Remote Code Execution issue allowing remote attackers to achieve full access to the system, because shell metacharacters i… CWE-78
OS Command 
CVE-2019-9161 2024-11-21 13:51 2019-04-19 Show GitHub Exploit DB Packet Storm
212499 9.8 CRITICAL
Network
xinruidz sundray_wan_controller_firmware WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a backdoor account allowing a remote attacker to login to the system via SSH (on TCP port 22345) and escalate to root (becau… CWE-798
 Use of Hard-coded Credentials
CVE-2019-9160 2024-11-21 13:51 2019-04-19 Show GitHub Exploit DB Packet Storm
212500 5.3 MEDIUM
Network
gitlab gitlab An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 5 of 5). CWE-200
Information Exposure
CVE-2019-9225 2024-11-21 13:51 2019-04-18 Show GitHub Exploit DB Packet Storm