Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227221 7.5 危険 scripts-for-sites - SFS Hotscripts-like Site の software-description.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6237 2012-12-20 19:10 2009-02-23 Show GitHub Exploit DB Packet Storm
227222 7.5 危険 PreProject.com - Pre Shopping Mall における認証を回避される脆弱性 CWE-255
証明書・パスワード管理
CVE-2008-6232 2012-12-20 19:10 2009-02-20 Show GitHub Exploit DB Packet Storm
227223 7.5 危険 PreProject.com - Pre Classified Listing PHP における認証を回避される脆弱性 CWE-255
証明書・パスワード管理
CVE-2008-6231 2012-12-20 19:10 2009-02-20 Show GitHub Exploit DB Packet Storm
227224 7.5 危険 PreProject.com - Pre Projects Pre Podcast Portal の Tour.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6230 2012-12-20 19:10 2009-02-20 Show GitHub Exploit DB Packet Storm
227225 7.5 危険 PreProject.com - Pre Multi-Vendor Shopping Malls における管理アクセス権を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2008-6228 2012-12-20 19:10 2009-02-20 Show GitHub Exploit DB Packet Storm
227226 7.5 危険 PreProject.com - Pre Multi-Vendor Shopping Malls の buyer_detail.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6227 2012-12-20 19:10 2009-02-20 Show GitHub Exploit DB Packet Storm
227227 6.8 警告 PreProject.com - Pre Projects PHP Auto Listings Script の moreinfo.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6226 2012-12-20 19:10 2009-02-20 Show GitHub Exploit DB Packet Storm
227228 7.5 危険 samelinux - WOTW の visualizza.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-6224 2012-12-20 19:10 2009-02-20 Show GitHub Exploit DB Packet Storm
227229 7.5 危険 wotw - WOTW の visualizza.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-6223 2012-12-20 19:10 2009-02-20 Show GitHub Exploit DB Packet Storm
227230 7.5 危険 Cafuego - SDMS の login.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6220 2012-12-20 19:10 2009-02-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
222341 5.4 MEDIUM
Network
solarwinds web_help_desk SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket. CWE-79
Cross-site Scripting
CVE-2019-16954 2024-11-21 13:31 2021-01-7 Show GitHub Exploit DB Packet Storm
222342 5.4 MEDIUM
Network
solarwinds web_help_desk SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field. CWE-79
Cross-site Scripting
CVE-2019-16960 2024-11-21 13:31 2021-01-4 Show GitHub Exploit DB Packet Storm
222343 5.4 MEDIUM
Network
solarwinds web_help_desk SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket. CWE-79
Cross-site Scripting
CVE-2019-16956 2024-11-21 13:31 2021-01-4 Show GitHub Exploit DB Packet Storm
222344 7.5 HIGH
Network
matrixssl matrixssl In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and a daemon crash) via a crafted incoming network message, a different vulnerabili… CWE-787
 Out-of-bounds Write
CVE-2019-16747 2024-11-21 13:31 2020-12-31 Show GitHub Exploit DB Packet Storm
222345 6.5 MEDIUM
Network
solarwinds webhelpdesk SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket. CWE-1236
 Improper Neutralization of Formula Elements in a CSV File
CVE-2019-16959 2024-11-21 13:31 2020-12-22 Show GitHub Exploit DB Packet Storm
222346 5.4 MEDIUM
Network
solarwinds webhelpdesk SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account. CWE-79
Cross-site Scripting
CVE-2019-16957 2024-11-21 13:31 2020-12-18 Show GitHub Exploit DB Packet Storm
222347 5.4 MEDIUM
Network
solarwinds webhelpdesk SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request. CWE-79
Cross-site Scripting
CVE-2019-16955 2024-11-21 13:31 2020-12-18 Show GitHub Exploit DB Packet Storm
222348 5.4 MEDIUM
Network
solarwinds help_desk Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name. CWE-79
Cross-site Scripting
CVE-2019-16958 2024-11-21 13:31 2020-12-2 Show GitHub Exploit DB Packet Storm
222349 7.5 HIGH
Network
mozilla
siemens
network_security_services
ruggedcom_rox_mx5000_firmware
ruggedcom_rox_rx1400_firmware
ruggedcom_rox_rx1500_firmware
ruggedcom_rox_rx1501_firmware
ruggedcom_rox_rx1510_firmware
rugge…
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service. CWE-295
Improper Certificate Validation 
CVE-2019-17007 2024-11-21 13:31 2020-10-23 Show GitHub Exploit DB Packet Storm
222350 9.8 CRITICAL
Network
siemens
mozilla
netapp
ruggedcom_rox_mx5000_firmware
ruggedcom_rox_rx1400_firmware
ruggedcom_rox_rx1500_firmware
ruggedcom_rox_rx1501_firmware
ruggedcom_rox_rx1510_firmware
ruggedcom_rox_rx1511_firmware
r…
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the in… CWE-119
CWE-20
Incorrect Access of Indexable Resource ('Range Error') 
 Improper Input Validation 
CVE-2019-17006 2024-11-21 13:31 2020-10-23 Show GitHub Exploit DB Packet Storm