Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 15, 2026, 12:10 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226961 4.3 警告 RADVISION - Radvision Scopia の entry/index.jsp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2965 2012-12-20 19:28 2009-08-25 Show GitHub Exploit DB Packet Storm
226962 4.3 警告 xapian - Xapian Omega におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2947 2012-12-20 19:28 2009-09-14 Show GitHub Exploit DB Packet Storm
226963 4.3 警告 stanford - Stanford University WebAuth の weblogin/login.fcgi におけるパスワードを特定される脆弱性 CWE-255
証明書・パスワード管理
CVE-2009-2945 2012-12-20 19:28 2009-08-31 Show GitHub Exploit DB Packet Storm
226964 7.5 危険 pygresql - Python 用の pygresql モジュールにおけるマルチバイト文字のエンコーディングに関する問題を利用される脆弱性 CWE-Other
その他
CVE-2009-2940 2012-12-20 19:28 2009-10-14 Show GitHub Exploit DB Packet Storm
226965 6.9 警告 Postfix Project - Debian GNU/Linux などの製品で使用される postfix パッケージにおけるシンボリックリンク攻撃を実行される脆弱性 CWE-59
リンク解釈の問題
CVE-2009-2939 2012-12-20 19:28 2009-09-21 Show GitHub Exploit DB Packet Storm
226966 9.3 危険 programmedintegration - Programmed Integration PIPL の xaudio.dll におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-2934 2012-12-20 19:28 2009-08-21 Show GitHub Exploit DB Packet Storm
226967 7.5 危険 Piwigo - Piwigo の comments.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2933 2012-12-20 19:28 2009-08-21 Show GitHub Exploit DB Packet Storm
226968 4.3 警告 SAP - SAP NetWeaver Application Server の UDDI クライアントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2932 2012-12-20 19:28 2009-08-21 Show GitHub Exploit DB Packet Storm
226969 7.8 危険 slideshowpro - SlideShowPro Director の p.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-2931 2012-12-20 19:28 2009-08-21 Show GitHub Exploit DB Packet Storm
226970 4.3 警告 SpringSource - SpringSource tc Server などの製品におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2907 2012-12-20 19:28 2010-03-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 15, 2026, 4:28 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
224091 9.8 CRITICAL
Network
weidmueller ie-sw-pl09m-5gc-4gt_firmware
ie-sw-pl09mt-5gc-4gt_firmware
ie-sw-pl18m-2gc-16tx_firmware
ie-sw-pl18mt-2gc-16tx_firmware
ie-sw-pl18m-2gc14tx2sc_firmware
ie-sw-pl18mt-2gc14tx2sc_firmware…
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Sensitive Credentials data is transmitted in… CWE-319
CWE-522
Cleartext Transmission of Sensitive Information
 Insufficiently Protected Credentials
CVE-2019-16672 2024-11-21 13:30 2019-12-7 Show GitHub Exploit DB Packet Storm
224092 6.5 MEDIUM
Network
weidmueller ie-sw-pl09m-5gc-4gt_firmware
ie-sw-pl09mt-5gc-4gt_firmware
ie-sw-pl18m-2gc-16tx_firmware
ie-sw-pl18mt-2gc-16tx_firmware
ie-sw-pl18m-2gc14tx2sc_firmware
ie-sw-pl18mt-2gc14tx2sc_firmware…
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Remote authenticated users can crash a devic… CWE-400
 Uncontrolled Resource Consumption
CVE-2019-16671 2024-11-21 13:30 2019-12-7 Show GitHub Exploit DB Packet Storm
224093 9.8 CRITICAL
Network
weidmueller ie-sw-pl09m-5gc-4gt_firmware
ie-sw-pl09mt-5gc-4gt_firmware
ie-sw-pl18m-2gc-16tx_firmware
ie-sw-pl18mt-2gc-16tx_firmware
ie-sw-pl18m-2gc14tx2sc_firmware
ie-sw-pl18mt-2gc14tx2sc_firmware…
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. The Authentication mechanism has no brute-fo… CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2019-16670 2024-11-21 13:30 2019-12-7 Show GitHub Exploit DB Packet Storm
224094 4.3 MEDIUM
Network
pega pega_platform PEGA Platform 8.3.0 is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyStream=MyAlerts request to get Audit Log information while using a low-privilege account. N… CWE-425
 Direct Request ('Forced Browsing')
CVE-2019-16388 2024-11-21 13:30 2019-11-27 Show GitHub Exploit DB Packet Storm
224095 4.3 MEDIUM
Network
pega pega_platform PEGA Platform 7.x and 8.x is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyActivity=GetWebInfo&target=popup&pzHarnessID=random_harness_id request to get databas… CWE-425
 Direct Request ('Forced Browsing')
CVE-2019-16386 2024-11-21 13:30 2019-11-27 Show GitHub Exploit DB Packet Storm
224096 8.1 HIGH
Network
pega pega_platform PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_ListDatabases request while using a low-privilege account. (This can perform acti… CWE-668
 Exposure of Resource to Wrong Sphere
CVE-2019-16387 2024-11-21 13:30 2019-11-27 Show GitHub Exploit DB Packet Storm
224097 8.1 HIGH
Network
ruby-lang
debian
opensuse
oracle
ruby
debian_linux
leap
graalvm
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[] or Shell#test in lib/shell.rb is untrusted data. … CWE-94
Code Injection
CVE-2019-16255 2024-11-21 13:30 2019-11-27 Show GitHub Exploit DB Packet Storm
224098 5.3 MEDIUM
Network
ruby-lang
debian
ruby
debian_linux
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBrick inserts untrusted input into the response header, an attacker can exploit i… CWE-74
Injection
CVE-2019-16254 2024-11-21 13:30 2019-11-27 Show GitHub Exploit DB Packet Storm
224099 7.5 HIGH
Network
ruby-lang
debian
ruby
debian_linux
WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expression Denial of Service cause by looping/backtracking. A victim must expose a WEBr… CWE-287
Improper Authentication
CVE-2019-16201 2024-11-21 13:30 2019-11-27 Show GitHub Exploit DB Packet Storm
224100 6.1 MEDIUM
Network
centreon centreon Centreon before 2.8.30, 18.x before 18.10.8, and 19.x before 19.04.5 allows XSS via myAccount alias and name fields. CWE-79
Cross-site Scripting
CVE-2019-16195 2024-11-21 13:30 2019-11-27 Show GitHub Exploit DB Packet Storm