Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 1, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227341 7.8 危険 Phpcms - phpCMS の parser/include/class.cache_phpcms.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0513 2012-12-20 18:34 2008-01-31 Show GitHub Exploit DB Packet Storm
227342 6.8 警告 WordPress.org - WordPress 用の Dean's Permalinks Migration プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-0508 2012-12-20 18:34 2008-01-31 Show GitHub Exploit DB Packet Storm
227343 7.5 危険 WordPress.org - WordPress 用の AdServe プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0507 2012-12-20 18:34 2008-01-31 Show GitHub Exploit DB Packet Storm
227344 5.8 警告 加藤和良 - phpMyClub におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0501 2012-12-20 18:34 2008-01-30 Show GitHub Exploit DB Packet Storm
227345 7.5 危険 WordPress.org - WordPress 用の fGallery プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0491 2012-12-20 18:34 2008-01-30 Show GitHub Exploit DB Packet Storm
227346 7.5 危険 WordPress.org - WordPress 用の WP-Cal プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0490 2012-12-20 18:34 2008-01-30 Show GitHub Exploit DB Packet Storm
227347 7.5 危険 vb marketing - VB Marketing の tseekdir.cgi におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0488 2012-12-20 18:34 2008-01-30 Show GitHub Exploit DB Packet Storm
227348 7.5 危険 the net guys - ASPired2Protect の login.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0487 2012-12-20 18:34 2008-01-30 Show GitHub Exploit DB Packet Storm
227349 5 警告 webwiz - Web Wiz Rich Text Editor の RTE_file_browser.asp におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0481 2012-12-20 18:34 2008-01-29 Show GitHub Exploit DB Packet Storm
227350 5 警告 webwiz - Web Wiz Forums におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0480 2012-12-20 18:34 2008-01-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 2, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
213061 9.8 CRITICAL
Network
zoneminder zoneminder daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters. CWE-78
OS Command 
CVE-2019-8427 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
213062 6.1 MEDIUM
Network
zoneminder zoneminder skins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the newControl[MinTiltRange] parameter. CWE-79
Cross-site Scripting
CVE-2019-8426 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
213063 6.1 MEDIUM
Network
zoneminder zoneminder includes/database.php in ZoneMinder before 1.32.3 has XSS in the construction of SQL-ERR messages. CWE-79
Cross-site Scripting
CVE-2019-8425 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
213064 9.8 CRITICAL
Network
zoneminder zoneminder ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter. CWE-89
SQL Injection
CVE-2019-8424 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
213065 9.8 CRITICAL
Network
zoneminder zoneminder ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter. CWE-89
SQL Injection
CVE-2019-8423 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
213066 7.2 HIGH
Network
pbootcms pbootcms A SQL Injection vulnerability exists in PbootCMS v1.3.2 via the description parameter in apps\admin\controller\content\ContentController.php. CWE-89
SQL Injection
CVE-2019-8422 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
213067 7.2 HIGH
Network
bagesoft bagecms upload/protected/modules/admini/views/post/index.php in BageCMS through 3.1.4 allows SQL Injection via the title or titleAlias parameter. CWE-89
SQL Injection
CVE-2019-8421 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
213068 6.1 MEDIUM
Network
vnote_project vnote VNote 2.2 has XSS via a new text note. CWE-79
Cross-site Scripting
CVE-2019-8419 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
213069 8.8 HIGH
Network
seacms seacms SeaCMS 7.2 mishandles member.php?mod=repsw4 requests. NVD-CWE-noinfo
CVE-2019-8418 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
213070 5.5 MEDIUM
Local
mi mi_mix_2_firmware On Xiaomi MIX 2 devices with the 4.4.78 kernel, a NULL pointer dereference in the ioctl interface of the device file /dev/elliptic1 or /dev/elliptic0 causes a system crash via IOCTL 0x4008c575 (aka d… CWE-476
 NULL Pointer Dereference
CVE-2019-8413 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm