Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 15, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226961 4.3 警告 QtWeb.NET - QtWeb におけるクロスサイトスクリプティング (XSS) 攻撃を実行される脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3015 2012-12-20 19:28 2009-08-31 Show GitHub Exploit DB Packet Storm
226962 4.3 警告 RADVISION - Radvision Scopia の entry/index.jsp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2965 2012-12-20 19:28 2009-08-25 Show GitHub Exploit DB Packet Storm
226963 4.3 警告 xapian - Xapian Omega におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2947 2012-12-20 19:28 2009-09-14 Show GitHub Exploit DB Packet Storm
226964 4.3 警告 stanford - Stanford University WebAuth の weblogin/login.fcgi におけるパスワードを特定される脆弱性 CWE-255
証明書・パスワード管理
CVE-2009-2945 2012-12-20 19:28 2009-08-31 Show GitHub Exploit DB Packet Storm
226965 7.5 危険 pygresql - Python 用の pygresql モジュールにおけるマルチバイト文字のエンコーディングに関する問題を利用される脆弱性 CWE-Other
その他
CVE-2009-2940 2012-12-20 19:28 2009-10-14 Show GitHub Exploit DB Packet Storm
226966 6.9 警告 Postfix Project - Debian GNU/Linux などの製品で使用される postfix パッケージにおけるシンボリックリンク攻撃を実行される脆弱性 CWE-59
リンク解釈の問題
CVE-2009-2939 2012-12-20 19:28 2009-09-21 Show GitHub Exploit DB Packet Storm
226967 9.3 危険 programmedintegration - Programmed Integration PIPL の xaudio.dll におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-2934 2012-12-20 19:28 2009-08-21 Show GitHub Exploit DB Packet Storm
226968 7.5 危険 Piwigo - Piwigo の comments.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2933 2012-12-20 19:28 2009-08-21 Show GitHub Exploit DB Packet Storm
226969 4.3 警告 SAP - SAP NetWeaver Application Server の UDDI クライアントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2932 2012-12-20 19:28 2009-08-21 Show GitHub Exploit DB Packet Storm
226970 7.8 危険 slideshowpro - SlideShowPro Director の p.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-2931 2012-12-20 19:28 2009-08-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 16, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
224261 7.8 HIGH
Local
notepad-plus-plus
scintilla
notepad\+\+
scintilla
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file. CWE-787
 Out-of-bounds Write
CVE-2019-16294 2024-11-21 13:30 2019-09-15 Show GitHub Exploit DB Packet Storm
224262 8.8 HIGH
Network
mobatek mobaxterm In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup asking whether the user wants to run MobaXterm to handle the link. If accepted,… CWE-77
Command Injection
CVE-2019-16305 2024-11-21 13:30 2019-09-15 Show GitHub Exploit DB Packet Storm
224263 9.8 CRITICAL
Network
jhipster jhipster
jhipster_kotlin
A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an insecure source of randomness (apache.commons.lang3 RandomStringUtils). This a… CWE-338
 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2019-16303 2024-11-21 13:30 2019-09-14 Show GitHub Exploit DB Packet Storm
224264 8.8 HIGH
Network
opmantek open-audit The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field. CWE-78
OS Command 
CVE-2019-16293 2024-11-21 13:30 2019-09-14 Show GitHub Exploit DB Packet Storm
224265 5.4 MEDIUM
Network
webcraftic woody_ad_snippets The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter. CWE-79
Cross-site Scripting
CVE-2019-16289 2024-11-21 13:30 2019-09-14 Show GitHub Exploit DB Packet Storm
224266 7.5 HIGH
Network
tenda n301_firmware On Tenda N301 wireless routers, a long string in the wifiSSID parameter of a goform/setWifi POST request causes the device to crash. NVD-CWE-noinfo
CVE-2019-16288 2024-11-21 13:30 2019-09-14 Show GitHub Exploit DB Packet Storm
224267 7.8 HIGH
Local
picoc_project picoc PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called from ExpressionParseFunctionCall in expression.c. CWE-787
 Out-of-bounds Write
CVE-2019-16277 2024-11-21 13:30 2019-09-13 Show GitHub Exploit DB Packet Storm
224268 6.5 MEDIUM
Adjacent
w1.fi
debian
canonical
hostapd
wpa_supplicant
debian_linux
ubuntu_linux
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service th… CWE-346
 Origin Validation Error
CVE-2019-16275 2024-11-21 13:30 2019-09-13 Show GitHub Exploit DB Packet Storm
224269 6.1 MEDIUM
Network
afterlogic aurora Afterlogic Aurora through 8.3.9-build-a3 has XSS that can be leveraged for session hijacking by retrieving the session cookie from the administrator login. CWE-79
Cross-site Scripting
CVE-2019-16238 2024-11-21 13:30 2019-09-13 Show GitHub Exploit DB Packet Storm
224270 9.1 CRITICAL
Network
tripplite pdumh15at_firmware Tripp Lite PDUMH15AT 12.04.0053 devices allow unauthenticated POST requests to the /Forms/ directory, as demonstrated by changing the manager or admin password, or shutting off power to an outlet. NO… CWE-287
Improper Authentication
CVE-2019-16261 2024-11-21 13:30 2019-09-13 Show GitHub Exploit DB Packet Storm