Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226811 5 警告 Apache Software Foundation - Apache Commons Compress および Apache Ant におけるサービス運用妨害 (DoS) の脆弱性 CWE-310
暗号の問題
CVE-2012-2098 2013-01-25 16:52 2012-05-23 Show GitHub Exploit DB Packet Storm
226812 4.3 警告 Elefant CMS - Elefant CMS の apps/admin/handlers/versions.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6521 2013-01-25 14:34 2013-01-24 Show GitHub Exploit DB Packet Storm
226813 7.5 危険 Cenango Financial LLC - WikidForum の advanced search における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-6520 2013-01-25 14:33 2013-01-24 Show GitHub Exploit DB Packet Storm
226814 7.5 危険 diy-cms - DIY-CMS の modules/poll/index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-6519 2013-01-25 14:33 2013-01-24 Show GitHub Exploit DB Packet Storm
226815 6.8 警告 diy-cms - DiY-CMS の mod.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-6518 2013-01-25 14:32 2013-01-24 Show GitHub Exploit DB Packet Storm
226816 4.3 警告 diy-cms - DiY-CMS におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6517 2013-01-25 14:31 2013-01-24 Show GitHub Exploit DB Packet Storm
226817 7.5 危険 Shawn Bradley - PHP Ticket System における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-6516 2013-01-25 14:30 2013-01-24 Show GitHub Exploit DB Packet Storm
226818 5 警告 eFront Learning - eFront における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2012-6515 2013-01-25 14:30 2013-01-24 Show GitHub Exploit DB Packet Storm
226819 4.3 警告 Netshine Software - Joomla! 用 nBill コンポーネントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6514 2013-01-25 14:28 2013-01-24 Show GitHub Exploit DB Packet Storm
226820 4.3 警告 gpEasy - gpEasy CMS の index.php/Admin_Preferences におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6513 2013-01-25 14:28 2013-01-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
224761 9.8 CRITICAL
Network
minerstat msos minerstat msOS before 2019-10-23 does not have a unique SSH key for each instance of the product. NVD-CWE-noinfo
CVE-2019-19750 2024-11-21 13:35 2019-12-13 Show GitHub Exploit DB Packet Storm
224762 6.1 MEDIUM
Network
brizoit work_time_calendar The Work Time Calendar app before 4.7.1 for Jira allows XSS. CWE-79
Cross-site Scripting
CVE-2019-19748 2024-11-21 13:35 2019-12-12 Show GitHub Exploit DB Packet Storm
224763 5.5 MEDIUM
Local
fig2dev_project
fedoraproject
fig2dev
fedora
make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type. CWE-787
CWE-190
 Out-of-bounds Write
 Integer Overflow or Wraparound
CVE-2019-19746 2024-11-21 13:35 2019-12-12 Show GitHub Exploit DB Packet Storm
224764 9.8 CRITICAL
Network
octeth oempro Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable. CWE-89
SQL Injection
CVE-2019-19740 2024-11-21 13:35 2019-12-12 Show GitHub Exploit DB Packet Storm
224765 7.8 HIGH
Local
openbsd openbsd OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be defeated by setting a very small RLIMIT_DATA resource limit. When executing ch… CWE-269
 Improper Privilege Management
CVE-2019-19726 2024-11-21 13:35 2019-12-12 Show GitHub Exploit DB Packet Storm
224766 7.5 HIGH
Network
bson-objectid_project bson-objectid An issue was discovered in the BSON ObjectID (aka bson-objectid) package 1.3.0 for Node.js. ObjectID() allows an attacker to generate a malformed objectid by inserting an additional property to the u… CWE-670
 Always-Incorrect Control Flow Implementation
CVE-2019-19729 2024-11-21 13:35 2019-12-12 Show GitHub Exploit DB Packet Storm
224767 9.8 CRITICAL
Network
sysstat_project
debian
canonical
sysstat
debian_linux
ubuntu_linux
sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c. CWE-415
 Double Free
CVE-2019-19725 2024-11-21 13:35 2019-12-12 Show GitHub Exploit DB Packet Storm
224768 8.8 HIGH
Network
zohocorp manageengine_applications_manager Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet agentid parameter to the Agent.java process function. CWE-89
SQL Injection
CVE-2019-19650 2024-11-21 13:35 2019-12-12 Show GitHub Exploit DB Packet Storm
224769 9.8 CRITICAL
Network
zohocorp manageengine_applications_manager Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function. CWE-89
SQL Injection
CVE-2019-19649 2024-11-21 13:35 2019-12-12 Show GitHub Exploit DB Packet Storm
224770 8.8 HIGH
Network
yabasic yabasic Yabasic 2.86.1 has a heap-based buffer overflow in the yylex() function in flex.c via a crafted BASIC source file. CWE-787
 Out-of-bounds Write
CVE-2019-19720 2024-11-21 13:35 2019-12-11 Show GitHub Exploit DB Packet Storm