Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227421 7.5 危険 spacial audio solutions - SAM Broadcaster samPHPweb の songinfo.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0187 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
227422 4.3 警告 phprisk - NetRisk の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0186 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
227423 6.4 警告 prenotazioni on line - Line System 上で稼動している Sys-Hotel における絶対パストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0184 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
227424 4.3 警告 Plone Foundation - Plone CMS におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-0164 2012-12-20 18:34 2008-03-14 Show GitHub Exploit DB Packet Storm
227425 7.2 危険 sam lantinga - splitvt の misc.c における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-0162 2012-12-20 18:34 2008-02-21 Show GitHub Exploit DB Packet Storm
227426 5 警告 shop-script - Shop-Script の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0158 2012-12-20 18:34 2008-01-8 Show GitHub Exploit DB Packet Storm
227427 5 警告 pragma systems - Pragma TelnetServer の telnetd.exe におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2008-0153 2012-12-20 18:34 2008-01-8 Show GitHub Exploit DB Packet Storm
227428 4.3 警告 seattle lab software - SLnet.exe の SeattleLab SLNet RF Telnet Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2008-0152 2012-12-20 18:34 2008-01-8 Show GitHub Exploit DB Packet Storm
227429 5 警告 tutos - TUTOS におけるシステム情報を読み取られる脆弱性 CWE-DesignError
CVE-2008-0149 2012-12-20 18:34 2008-01-8 Show GitHub Exploit DB Packet Storm
227430 10 危険 tutos - TUTOS における任意のシェルコマンドを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-0148 2012-12-20 18:34 2008-01-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
223801 8.8 HIGH
Network
flarum flarum Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings. CWE-352
 Origin Validation Error
CVE-2019-13183 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
223802 9.8 CRITICAL
Network
dlink central_wifimanager A SQL Injection was discovered in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 in PayAction.class.php with the index.php/Pay/passcodeAuth parameter passcode. The vulnerability does no… CWE-89
SQL Injection
CVE-2019-13375 2024-11-21 13:24 2019-07-7 Show GitHub Exploit DB Packet Storm
223803 6.1 MEDIUM
Network
dlink central_wifimanager A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to inject arbitrary web scri… CWE-79
Cross-site Scripting
CVE-2019-13374 2024-11-21 13:24 2019-07-7 Show GitHub Exploit DB Packet Storm
223804 9.8 CRITICAL
Network
dlink central_wifimanager An issue was discovered in the D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6. Input does not get validated and arbitrary SQL statements can be executed in the database via the /web/Pub… CWE-89
SQL Injection
CVE-2019-13373 2024-11-21 13:24 2019-07-7 Show GitHub Exploit DB Packet Storm
223805 9.8 CRITICAL
Network
dlink central_wifimanager /web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via a cookie because a cookie's username fi… CWE-287
CWE-94
Improper Authentication
Code Injection
CVE-2019-13372 2024-11-21 13:24 2019-07-7 Show GitHub Exploit DB Packet Storm
223806 8.8 HIGH
Network
ignitedcms ignitedcms index.php/admin/permissions in Ignited CMS through 2017-02-19 allows CSRF to add an administrator. CWE-352
 Origin Validation Error
CVE-2019-13370 2024-11-21 13:24 2019-07-7 Show GitHub Exploit DB Packet Storm
223807 7.8 HIGH
Local
codedoc_project codedoc Codedoc v3.2 has a stack-based buffer overflow in add_variable in codedoc.c, related to codedoc_strlcpy. CWE-787
 Out-of-bounds Write
CVE-2019-13362 2024-11-21 13:24 2019-07-7 Show GitHub Exploit DB Packet Storm
223808 7.5 HIGH
Network
opencats opencats lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker must upload a file in the docx or odt format. CWE-611
XXE
CVE-2019-13358 2024-11-21 13:24 2019-07-6 Show GitHub Exploit DB Packet Storm
223809 9.8 CRITICAL
Network
wolfvision cynap WolfVision Cynap before 1.30j uses a static, hard-coded cryptographic secret for generating support PINs for the 'forgot password' feature. By knowing this static secret and the corresponding algorit… CWE-798
 Use of Hard-coded Credentials
CVE-2019-13352 2024-11-21 13:24 2019-07-6 Show GitHub Exploit DB Packet Storm
223810 8.1 HIGH
Network
jackaudio
alsa-project
jack2
alsa
posix/JackSocket.cpp in libjack in JACK2 1.9.1 through 1.9.12 (as distributed with alsa-plugins 1.1.7 and later) has a "double file descriptor close" issue during a failed connection attempt when jac… NVD-CWE-noinfo
CVE-2019-13351 2024-11-21 13:24 2019-07-6 Show GitHub Exploit DB Packet Storm