Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226961 7.5 危険 xigla - Xigla Software Absolute FAQ Manager.NET における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2008-6854 2012-12-20 19:10 2009-07-14 Show GitHub Exploit DB Packet Storm
226962 4.3 警告 PHP-Fusion - PHP-Fusion の messages.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6850 2012-12-20 19:10 2009-07-7 Show GitHub Exploit DB Packet Storm
226963 6.8 警告 w2b - phpGreetCards の index.php における任意の PHP コードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2008-6849 2012-12-20 19:10 2009-07-7 Show GitHub Exploit DB Packet Storm
226964 4.3 警告 w2b - phpGreetCards の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6848 2012-12-20 19:10 2009-07-7 Show GitHub Exploit DB Packet Storm
226965 4.3 警告 PreProject.com - Pre ASP Job Board の Employee/emp_login.asp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6847 2012-12-20 19:10 2009-07-2 Show GitHub Exploit DB Packet Storm
226966 6.8 警告 Pluck CMS - Pluck の data/modules/blog/module_pages_site.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-6842 2012-12-20 19:10 2009-07-2 Show GitHub Exploit DB Packet Storm
226967 4.3 警告 tgs-cms - TGS Content Management におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6839 2012-12-20 19:10 2009-06-27 Show GitHub Exploit DB Packet Storm
226968 4.3 警告 Zoph - Zoph の search.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6838 2012-12-20 19:10 2009-06-27 Show GitHub Exploit DB Packet Storm
226969 7.5 危険 Zoph - Zoph における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6837 2012-12-20 19:10 2009-06-27 Show GitHub Exploit DB Packet Storm
226970 5 警告 vicftps - VicFTPS におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2008-6829 2012-12-20 19:10 2009-06-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
223721 7.5 HIGH
Network
kbrw sweet_xml The SweetXml (aka sweet_xml) package through 0.6.6 for Erlang and Elixir allows attackers to cause a denial of service (resource consumption) via an XML entity expansion attack with an inline DTD. CWE-776
XML Entity Expansion
CVE-2019-15160 2024-11-21 13:28 2019-08-19 Show GitHub Exploit DB Packet Storm
223722 8.8 HIGH
Network
schine.games mw-oauth2client In the OAuth2 Client extension before 0.4 for MediaWiki, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function. CWE-352
 Origin Validation Error
CVE-2019-15150 2024-11-21 13:28 2019-08-19 Show GitHub Exploit DB Packet Storm
223723 9.8 CRITICAL
Network
adplug_project
fedoraproject
adplug
fedora
AdPlug 2.3.1 has a double free in the Cu6mPlayer class in u6m.h. CWE-415
 Double Free
CVE-2019-15151 2024-11-21 13:28 2019-08-19 Show GitHub Exploit DB Packet Storm
223724 6.5 MEDIUM
Network
gopro gpmf-parser GoPro GPMF-parser 1.2.2 has an out-of-bounds write in OpenMP4Source in demo/GPMF_mp4reader.c. CWE-787
 Out-of-bounds Write
CVE-2019-15148 2024-11-21 13:28 2019-08-19 Show GitHub Exploit DB Packet Storm
223725 6.5 MEDIUM
Network
gopro gpmf-parser GoPro GPMF-parser 1.2.2 has an out-of-bounds read and SEGV in GPMF_Next in GPMF_parser.c. CWE-125
Out-of-bounds Read
CVE-2019-15147 2024-11-21 13:28 2019-08-19 Show GitHub Exploit DB Packet Storm
223726 6.5 MEDIUM
Network
gopro gpmf-parser GoPro GPMF-parser 1.2.2 has a heap-based buffer over-read (4 bytes) in GPMF_Next in GPMF_parser.c. CWE-125
Out-of-bounds Read
CVE-2019-15146 2024-11-21 13:28 2019-08-19 Show GitHub Exploit DB Packet Storm
223727 5.5 MEDIUM
Local
djvulibre_project
debian
fedoraproject
canonical
opensuse
djvulibre
debian_linux
fedora
ubuntu_linux
leap
DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-of-bounds read) by crafting a corrupted JB2 image file that is mishandled in JB2Dict::JB2Codec::get… CWE-125
Out-of-bounds Read
CVE-2019-15145 2024-11-21 13:28 2019-08-19 Show GitHub Exploit DB Packet Storm
223728 9.8 CRITICAL
Network
networkgenomics mitogen core.py in Mitogen before 0.2.8 has a typo that drops the unidirectional-routing protection mechanism in the case of a child that is initiated by another child. The Ansible extension is unaffected. N… CWE-254
 7PK - Security Features
CVE-2019-15149 2024-11-21 13:28 2019-08-19 Show GitHub Exploit DB Packet Storm
223729 5.5 MEDIUM
Local
djvulibre_project
debian
fedoraproject
canonical
opensuse
djvulibre
debian_linux
fedora
ubuntu_linux
leap
In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) by crafting a PBM im… CWE-674
 Uncontrolled Recursion
CVE-2019-15144 2024-11-21 13:28 2019-08-19 Show GitHub Exploit DB Packet Storm
223730 5.5 MEDIUM
Local
djvulibre_project
debian
fedoraproject
canonical
opensuse
djvulibre
debian_linux
fedora
ubuntu_linux
leap
In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustion caused by a GBitmap::read_rle_raw infinite loop) by crafting a corrupted imag… CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2019-15143 2024-11-21 13:28 2019-08-19 Show GitHub Exploit DB Packet Storm