Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 1, 2026, 12:10 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227351 6.4 警告 webwiz - Web Wiz Rich Text Editor の RTE_popup_save_file.asp における .html ファイルなどをアップロードされる脆弱性 CWE-20
不適切な入力確認
CVE-2008-0473 2012-12-20 18:34 2008-01-29 Show GitHub Exploit DB Packet Storm
227352 4.3 警告 woltlab - wBB の modcp.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-0472 2012-12-20 18:34 2008-01-29 Show GitHub Exploit DB Packet Storm
227353 4.3 警告 phpBB - phpBB の privmsg.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-0471 2012-12-20 18:34 2008-01-29 Show GitHub Exploit DB Packet Storm
227354 7.5 危険 tiger php news system - TPNS の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0469 2012-12-20 18:34 2008-01-29 Show GitHub Exploit DB Packet Storm
227355 5 警告 webwiz - Web Wiz Rich Text Edito などで使用されている Web Wiz RTE_file_browser.asp におけるディレクトリトラバーサルの脆弱性 CWE-287
不適切な認証
CVE-2008-0466 2012-12-20 18:34 2008-01-28 Show GitHub Exploit DB Packet Storm
227356 5 警告 seagullproject.org - Seagull の optimizer.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0465 2012-12-20 18:34 2008-01-25 Show GitHub Exploit DB Packet Storm
227357 6.8 警告 slaed - SLAED CMS の function/sources.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0458 2012-12-20 18:34 2008-01-25 Show GitHub Exploit DB Packet Storm
227358 10 危険 シマンテック - Symantec Backup Exec System Recovery Manager で使用される Symantec LiveState Apache Tomcat サーバで稼動している FileUpload クラスにおける任意の JSP ファイルをアップロードされる脆弱性 CWE-20
不適切な入力確認
CVE-2008-0457 2012-12-20 18:34 2008-02-4 Show GitHub Exploit DB Packet Storm
227359 5 警告 siteman - Siteman の articles.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0452 2012-12-20 18:34 2008-01-24 Show GitHub Exploit DB Packet Storm
227360 7.5 危険 rocksalt international - VP-ASP Shopping Cart の paypalresult.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0449 2012-12-20 18:34 2008-01-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 1, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
212841 7.8 HIGH
Local
autodesk fbx_software_development_kit Buffer overflow vulnerability in Autodesk FBX Software Development Kit version 2019.5. A user may be tricked into opening a malicious FBX file which may exploit a buffer overflow vulnerability causin… CWE-120
Classic Buffer Overflow
CVE-2019-7366 2024-11-21 13:48 2019-12-4 Show GitHub Exploit DB Packet Storm
212842 7.8 HIGH
Local
autodesk autodesk_desktop DLL preloading vulnerability in Autodesk Desktop Application versions 7.0.16.29 and earlier. An attacker may trick a user into downloading a malicious DLL file into the working directory, which may t… CWE-427
 Uncontrolled Search Path Element
CVE-2019-7365 2024-11-21 13:48 2019-12-4 Show GitHub Exploit DB Packet Storm
212843 8.3 HIGH
Network
cloudera cdh An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBackend, SAML2Backend, … CWE-269
 Improper Privilege Management
CVE-2019-7319 2024-11-21 13:48 2019-11-27 Show GitHub Exploit DB Packet Storm
212844 7.5 HIGH
Network
elastic logstash Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthenticated user who is able to connect to the port the Logstash beats input could… NVD-CWE-noinfo
CVE-2019-7620 2024-11-21 13:48 2019-10-30 Show GitHub Exploit DB Packet Storm
212845 5.3 MEDIUM
Network
elastic elasticsearch Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determin… NVD-CWE-noinfo
CVE-2019-7619 2024-11-21 13:48 2019-10-30 Show GitHub Exploit DB Packet Storm
212846 6.5 MEDIUM
Network
elastic kibana A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local fil… CWE-22
Path Traversal
CVE-2019-7618 2024-11-21 13:48 2019-10-2 Show GitHub Exploit DB Packet Storm
212847 7.8 HIGH
Local
autodesk design_review Use-after-free vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a use-after-free vulnerabi… CWE-416
 Use After Free
CVE-2019-7363 2024-11-21 13:48 2019-08-24 Show GitHub Exploit DB Packet Storm
212848 7.8 HIGH
Local
autodesk design_review DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a DLL preloading vulnerabi… CWE-427
 Uncontrolled Search Path Element
CVE-2019-7362 2024-11-21 13:48 2019-08-24 Show GitHub Exploit DB Packet Storm
212849 7.8 HIGH
Local
autodesk advance_steel
autocad
autocad_architecture
autocad_electrical
autocad_lt
autocad_map_3d
autocad_mechanical
autocad_mep
autocad_plant_3d
civil_3d
autocad_p\&id
DLL preloading vulnerability in versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechan… CWE-427
 Uncontrolled Search Path Element
CVE-2019-7364 2024-11-21 13:48 2019-08-24 Show GitHub Exploit DB Packet Storm
212850 7.2 HIGH
Network
elastic apm_agent When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can control the proxy header. This could result in an atta… CWE-20
 Improper Input Validation 
CVE-2019-7617 2024-11-21 13:48 2019-08-23 Show GitHub Exploit DB Packet Storm