Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227151 4.3 警告 pro search - PRO-Search におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0207 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
227152 4.3 警告 WordPress.org - WordPress 用の Captcha! プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0206 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
227153 4.3 警告 WordPress.org - WordPress 用の Math Comment Spam Protection プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0205 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
227154 4.3 警告 WordPress.org - WordPress 用の Math Comment Spam Protection プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0204 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
227155 4.3 警告 WordPress.org - WordPress 用の Cryptographp プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0203 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
227156 5 警告 pro search - PRO-Search におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2008-0199 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
227157 4.3 警告 WordPress.org - WordPress 用の WP-ContactForm プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-0198 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
227158 4.3 警告 WordPress.org - WordPress 用の WP-ContactForm プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0197 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
227159 5 警告 WordPress.org - WordPress におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0196 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
227160 5 警告 WordPress.org - WordPress における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2008-0195 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 1, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211791 7.5 HIGH
Network
apowersoft apowermanager The ApowerManager application through 3.1.7 for Android allows remote attackers to cause a denial of service via many simultaneous /?Key=PhoneRequestAuthorization requests. NVD-CWE-noinfo
CVE-2019-9601 2024-11-21 13:51 2019-03-7 Show GitHub Exploit DB Packet Storm
211792 7.5 HIGH
Network
theolivetree ftp_server The Olive Tree FTP Server (aka com.theolivetree.ftpserver) application through 1.32 for Android allows remote attackers to cause a denial of service via a client that makes many connection attempts a… NVD-CWE-noinfo
CVE-2019-9600 2024-11-21 13:51 2019-03-7 Show GitHub Exploit DB Packet Storm
211793 7.5 HIGH
Network
airdroid airdroid The AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash) via many simultaneous sdctl/comm/lite_auth/ requests. NVD-CWE-noinfo
CVE-2019-9599 2024-11-21 13:51 2019-03-7 Show GitHub Exploit DB Packet Storm
211794 6.1 MEDIUM
Network
appcms appcms AppCMS 2.0.101 allows XSS via the upload/callback.php params parameter. CWE-79
Cross-site Scripting
CVE-2019-9595 2024-11-21 13:51 2019-03-7 Show GitHub Exploit DB Packet Storm
211795 9.8 CRITICAL
Network
bluecms_project bluecms BlueCMS 1.6 allows SQL Injection via the user_id parameter in an uploads/admin/user.php?act=edit request. CWE-89
SQL Injection
CVE-2019-9594 2024-11-21 13:51 2019-03-7 Show GitHub Exploit DB Packet Storm
211796 6.1 MEDIUM
Network
mitel connect_onsite A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter. CWE-79
Cross-site Scripting
CVE-2019-9593 2024-11-21 13:51 2019-03-7 Show GitHub Exploit DB Packet Storm
211797 6.1 MEDIUM
Network
mitel connect_onsite A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter. CWE-79
Cross-site Scripting
CVE-2019-9592 2024-11-21 13:51 2019-03-7 Show GitHub Exploit DB Packet Storm
211798 6.1 MEDIUM
Network
mitel connect_onsite A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web script or HTML via the brandUrl parameter. CWE-79
Cross-site Scripting
CVE-2019-9591 2024-11-21 13:51 2019-03-7 Show GitHub Exploit DB Packet Storm
211799 7.5 HIGH
Network
tengcon t-920_plc_firmware An issue was discovered on TENGCONTROL T-920 PLC v5.5 devices. It allows remote attackers to cause a denial of service (persistent failure mode) by sending a series of \x19\xb2\x00\x00\x00\x06\x43\x0… NVD-CWE-noinfo
CVE-2019-9590 2024-11-21 13:51 2019-03-7 Show GitHub Exploit DB Packet Storm
211800 7.8 HIGH
Local
glyphandcog xpdfreader There is a NULL pointer dereference vulnerability in PSOutputDev::setupResources() located in PSOutputDev.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfto… CWE-476
 NULL Pointer Dereference
CVE-2019-9589 2024-11-21 13:51 2019-03-6 Show GitHub Exploit DB Packet Storm