Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 10, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227181 7.5 危険 rgallery - WBB 用の rGallery プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4627 2012-12-20 18:52 2008-10-20 Show GitHub Exploit DB Packet Storm
227182 6.8 警告 zirkon box - Fritz Berger yappa-ng の yappa-ng におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-4626 2012-12-20 18:52 2008-10-20 Show GitHub Exploit DB Packet Storm
227183 7.5 危険 shiftthis - WordPress 用の ShiftThis Newsletter プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4625 2012-12-20 18:52 2008-10-20 Show GitHub Exploit DB Packet Storm
227184 5 警告 Wireshark - Wireshark の Bluetooth ACL 解析子におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2008-4683 2012-12-20 18:52 2007-04-4 Show GitHub Exploit DB Packet Storm
227185 7.5 危険 phpfastnews - phpFastNews の fastnews-code.php における認証を迂回される脆弱性 CWE-287
不適切な認証
CVE-2008-4622 2012-12-20 18:52 2008-10-20 Show GitHub Exploit DB Packet Storm
227186 7.5 危険 ZeeScripts.com - ZeeScripts Zeeproperty の bannerclick.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4621 2012-12-20 18:52 2008-10-20 Show GitHub Exploit DB Packet Storm
227187 10 危険 サン・マイクロシステムズ - Sun Solaris の RPC サブシステムにおけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2008-4619 2012-12-20 18:52 2008-10-20 Show GitHub Exploit DB Packet Storm
227188 7.5 危険 pyxicom - Joomla! 用の actualite モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4617 2012-12-20 18:52 2008-10-20 Show GitHub Exploit DB Packet Storm
227189 5 警告 the spanner
WordPress.org
- WordPress の SpamBam プラグインにおける制限を回避される脆弱性 CWE-20
不適切な入力確認
CVE-2008-4616 2012-12-20 18:52 2008-10-20 Show GitHub Exploit DB Packet Storm
227190 10 危険 portalapp - PortalApp の i_utils.asp における脆弱性 CWE-noinfo
情報不足
CVE-2008-4615 2012-12-20 18:52 2008-10-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 10, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
222711 7.5 HIGH
Network
tenda n301_firmware On Tenda N301 wireless routers, a long string in the wifiSSID parameter of a goform/setWifi POST request causes the device to crash. NVD-CWE-noinfo
CVE-2019-16288 2024-11-21 13:30 2019-09-14 Show GitHub Exploit DB Packet Storm
222712 7.8 HIGH
Local
picoc_project picoc PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called from ExpressionParseFunctionCall in expression.c. CWE-787
 Out-of-bounds Write
CVE-2019-16277 2024-11-21 13:30 2019-09-13 Show GitHub Exploit DB Packet Storm
222713 6.5 MEDIUM
Adjacent
w1.fi
debian
canonical
hostapd
wpa_supplicant
debian_linux
ubuntu_linux
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service th… CWE-346
 Origin Validation Error
CVE-2019-16275 2024-11-21 13:30 2019-09-13 Show GitHub Exploit DB Packet Storm
222714 6.1 MEDIUM
Network
afterlogic aurora Afterlogic Aurora through 8.3.9-build-a3 has XSS that can be leveraged for session hijacking by retrieving the session cookie from the administrator login. CWE-79
Cross-site Scripting
CVE-2019-16238 2024-11-21 13:30 2019-09-13 Show GitHub Exploit DB Packet Storm
222715 9.1 CRITICAL
Network
tripplite pdumh15at_firmware Tripp Lite PDUMH15AT 12.04.0053 devices allow unauthenticated POST requests to the /Forms/ directory, as demonstrated by changing the manager or admin password, or shutting off power to an outlet. NO… CWE-287
Improper Authentication
CVE-2019-16261 2024-11-21 13:30 2019-09-13 Show GitHub Exploit DB Packet Storm
222716 9.8 CRITICAL
Network
motorola motorola_firmware Some Motorola devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or ex… NVD-CWE-noinfo
CVE-2019-16257 2024-11-21 13:30 2019-09-12 Show GitHub Exploit DB Packet Storm
222717 9.8 CRITICAL
Network
samsung samsung_firmware Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or exe… NVD-CWE-noinfo
CVE-2019-16256 2024-11-21 13:30 2019-09-12 Show GitHub Exploit DB Packet Storm
222718 7.5 HIGH
Network
oceanwp ocean_extra includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequence. CWE-287
Improper Authentication
CVE-2019-16250 2024-11-21 13:30 2019-09-12 Show GitHub Exploit DB Packet Storm
222719 5.3 MEDIUM
Network
opencv opencv OpenCV 4.1.1 has an out-of-bounds read in hal_baseline::v_load in core/hal/intrin_sse.hpp when called from computeSSDMeanNorm in modules/video/src/dis_flow.cpp. CWE-125
Out-of-bounds Read
CVE-2019-16249 2024-11-21 13:30 2019-09-12 Show GitHub Exploit DB Packet Storm
222720 5.5 MEDIUM
Local
telegram telegram The "delete for" feature in Telegram before 5.11 on Android does not delete shared media files from the Telegram Images directory. In other words, there is a potentially misleading UI indication that… NVD-CWE-noinfo
CVE-2019-16248 2024-11-21 13:30 2019-09-12 Show GitHub Exploit DB Packet Storm