Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 4:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227001 5 警告 Canonical - Ubuntu の system-tools-backends におけるパスワードの総当たり攻撃を実行される脆弱性 CWE-310
暗号の問題
CVE-2008-6792 2012-12-20 19:10 2008-11-5 Show GitHub Exploit DB Packet Storm
227002 5 警告 ZoneMinder - Fedora 上で稼動する ZoneMinder における /etc/zm.conf を変更される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-6755 2012-12-20 19:10 2009-01-7 Show GitHub Exploit DB Packet Storm
227003 7.5 危険 revou - ReVou Micro Blogging 用の TClone プラグインにおける管理者のパスワードを変更される脆弱性 CWE-20
不適切な入力確認
CVE-2008-6752 2012-12-20 19:10 2009-04-24 Show GitHub Exploit DB Packet Storm
227004 6.8 警告 revou - ReVou Micro Blogging 用の TClone プラグインにおける任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2008-6751 2012-12-20 19:10 2009-04-24 Show GitHub Exploit DB Packet Storm
227005 7.5 危険 shock-therapy - RSMScript における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2008-6743 2012-12-20 19:10 2009-04-22 Show GitHub Exploit DB Packet Storm
227006 7.5 危険 Simple Machines - SMF の Load.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6741 2012-12-20 19:10 2009-04-21 Show GitHub Exploit DB Packet Storm
227007 7.5 危険 toddwoolums - Todd Woolums ASP Download 管理スクリプトにおける管理者権限を取得される脆弱性 CWE-287
不適切な認証
CVE-2008-6739 2012-12-20 19:10 2009-04-21 Show GitHub Exploit DB Packet Storm
227008 5.8 警告 thaiquickcart - ThaiQuickCart の qc/index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-6735 2012-12-20 19:10 2009-04-21 Show GitHub Exploit DB Packet Storm
227009 6.8 警告 phpmotion - PHPmotion の password.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-6729 2012-12-20 19:10 2009-04-20 Show GitHub Exploit DB Packet Storm
227010 7.5 危険 PHPNUKE - PHP-Nuke の Sections モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6728 2012-12-20 19:10 2009-04-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
222821 9.8 CRITICAL
Network
indexhibit indexhibit Indexhibit 2.1.5 allows a product reinstallation, with resultant remote code execution, via /ndxzstudio/install.php?p=2. NVD-CWE-noinfo
CVE-2019-16314 2024-11-21 13:30 2019-09-15 Show GitHub Exploit DB Packet Storm
222822 7.5 HIGH
Network
ifw8 fr6_firmware
fr8_firmware
fr5_firmware
fr5-e_firmware
fr6-s_firmware
ifw8 Router ROM v4.31 allows credential disclosure by reading the action/usermanager.htm HTML source code. CWE-798
 Use of Hard-coded Credentials
CVE-2019-16313 2024-11-21 13:30 2019-09-15 Show GitHub Exploit DB Packet Storm
222823 6.1 MEDIUM
Network
s-cms s-cms s-cms V3.0 has XSS in index.php?type=text via the S_id parameter. CWE-79
Cross-site Scripting
CVE-2019-16312 2024-11-21 13:30 2019-09-15 Show GitHub Exploit DB Packet Storm
222824 8.8 HIGH
Network
niushop niushop NIUSHOP V1.11 has CSRF via search_info to index.php. CWE-352
 Origin Validation Error
CVE-2019-16311 2024-11-21 13:30 2019-09-15 Show GitHub Exploit DB Packet Storm
222825 5.4 MEDIUM
Network
niushop niushop NIUSHOP V1.11 has XSS via the index.php?s=/admin URI. CWE-79
Cross-site Scripting
CVE-2019-16310 2024-11-21 13:30 2019-09-15 Show GitHub Exploit DB Packet Storm
222826 9.8 CRITICAL
Network
flamecms_project flamecms FlameCMS 3.3.5 has SQL injection in account/login.php via accountName. CWE-89
SQL Injection
CVE-2019-16309 2024-11-21 13:30 2019-09-15 Show GitHub Exploit DB Packet Storm
222827 7.8 HIGH
Local
notepad-plus-plus
scintilla
notepad\+\+
scintilla
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file. CWE-787
 Out-of-bounds Write
CVE-2019-16294 2024-11-21 13:30 2019-09-15 Show GitHub Exploit DB Packet Storm
222828 8.8 HIGH
Network
mobatek mobaxterm In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup asking whether the user wants to run MobaXterm to handle the link. If accepted,… CWE-77
Command Injection
CVE-2019-16305 2024-11-21 13:30 2019-09-15 Show GitHub Exploit DB Packet Storm
222829 9.8 CRITICAL
Network
jhipster jhipster
jhipster_kotlin
A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an insecure source of randomness (apache.commons.lang3 RandomStringUtils). This a… CWE-338
 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2019-16303 2024-11-21 13:30 2019-09-14 Show GitHub Exploit DB Packet Storm
222830 8.8 HIGH
Network
opmantek open-audit The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field. CWE-78
OS Command 
CVE-2019-16293 2024-11-21 13:30 2019-09-14 Show GitHub Exploit DB Packet Storm