Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 19, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226611 1.9 注意 vincent fourmond - pmount の policy.c における任意のファイルを上書きされる脆弱性 CWE-59
リンク解釈の問題
CVE-2010-2192 2012-12-20 19:29 2010-06-18 Show GitHub Exploit DB Packet Storm
226612 2.1 注意 speedtech - Drupal 用の Storm モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-2158 2012-12-20 19:29 2010-05-19 Show GitHub Exploit DB Packet Storm
226613 4.3 警告 zonecheck - ZoneCheck の zc/publisher/html.rb におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-2155 2012-12-20 19:29 2010-05-26 Show GitHub Exploit DB Packet Storm
226614 6.8 警告 Tecnick.com - TCExam の admin/code/tce_functions_tcecode_editor.php における任意のコードを実行される脆弱性 CWE-Other
その他
CVE-2010-2153 2012-12-20 19:29 2010-06-3 Show GitHub Exploit DB Packet Storm
226615 7.5 危険 unisoft - Joomla! 用の My Car コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-2148 2012-12-20 19:29 2010-06-3 Show GitHub Exploit DB Packet Storm
226616 4.3 警告 unisoft - Joomla! 用の My Car コンポーネントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-2147 2012-12-20 19:29 2010-06-3 Show GitHub Exploit DB Packet Storm
226617 7.5 危険 richrumble - ClearSite における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2010-2145 2012-12-20 19:29 2010-06-3 Show GitHub Exploit DB Packet Storm
226618 4.3 警告 zeeways - Zeeways eBay Clone Auction Script の signinform.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-2144 2012-12-20 19:29 2010-06-3 Show GitHub Exploit DB Packet Storm
226619 7.5 危険 Symphony CMS - Symphony CMS の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-2143 2012-12-20 19:29 2010-06-3 Show GitHub Exploit DB Packet Storm
226620 7.5 危険 snipegallery - Snipe Gallery における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2010-2126 2012-12-20 19:29 2010-06-1 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 19, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
222641 7.2 HIGH
Network
halo halo Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is not used in the FreeMarker configuration. CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2019-19999 2024-11-21 13:35 2019-12-26 Show GitHub Exploit DB Packet Storm
222642 7.5 HIGH
Network
xiuno xiunobbs Xiuno BBS 4.0 allows XXE via plugin/xn_wechat_public/route/token.php. CWE-611
XXE
CVE-2019-19998 2024-11-21 13:35 2019-12-26 Show GitHub Exploit DB Packet Storm
222643 5.3 MEDIUM
Network
icegram email_subscribers_\&_newsletters The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure. CWE-862
 Missing Authorization
CVE-2019-19985 2024-11-21 13:35 2019-12-26 Show GitHub Exploit DB Packet Storm
222644 6.3 MEDIUM
Network
icegram email_subscribers_\&_newsletters The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns. CWE-863
 Incorrect Authorization
CVE-2019-19984 2024-11-21 13:35 2019-12-26 Show GitHub Exploit DB Packet Storm
222645 4.3 MEDIUM
Network
fastvelocity minify In the WordPress plugin, Fast Velocity Minify before 2.7.7, the full web root path to the running WordPress application can be discovered. In order to exploit this vulnerability, FVM Debug Mode needs… CWE-200
Information Exposure
CVE-2019-19983 2024-11-21 13:35 2019-12-26 Show GitHub Exploit DB Packet Storm
222646 5.3 MEDIUM
Network
icegram email_subscribers_\&_newsletters The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send… CWE-287
Improper Authentication
CVE-2019-19982 2024-11-21 13:35 2019-12-26 Show GitHub Exploit DB Packet Storm
222647 5.4 MEDIUM
Network
icegram email_subscribers_\&_newsletters The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings. CWE-352
 Origin Validation Error
CVE-2019-19981 2024-11-21 13:35 2019-12-26 Show GitHub Exploit DB Packet Storm
222648 4.3 MEDIUM
Network
icegram email_subscribers_\&_newsletters The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administra… NVD-CWE-noinfo
CVE-2019-19980 2024-11-21 13:35 2019-12-26 Show GitHub Exploit DB Packet Storm
222649 8.8 HIGH
Network
wp_maintenance_project wp_maintenance A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance mode and inject malicious code affecting site visitors. There was CSRF with re… CWE-352
CWE-79
 Origin Validation Error
Cross-site Scripting
CVE-2019-19979 2024-11-21 13:35 2019-12-26 Show GitHub Exploit DB Packet Storm
222650 9.8 CRITICAL
Network
libesmtp_project libesmtp libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read. CWE-125
Out-of-bounds Read
CVE-2019-19977 2024-11-21 13:35 2019-12-26 Show GitHub Exploit DB Packet Storm