Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227491 7.5 危険 w1n78 - e107 用の Lyrics プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4906 2012-12-20 18:52 2008-11-3 Show GitHub Exploit DB Packet Storm
227492 5 警告 typosphere - Typo におけるパスワードを推測される脆弱性 CWE-310
暗号の問題
CVE-2008-4905 2012-12-20 18:52 2008-11-3 Show GitHub Exploit DB Packet Storm
227493 6 警告 typosphere - Typo の "ページを管理する" 機能における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4904 2012-12-20 18:52 2008-11-3 Show GitHub Exploit DB Packet Storm
227494 4.3 警告 typosphere - Typo のコメントを残す機能におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-4903 2012-12-20 18:52 2008-11-3 Show GitHub Exploit DB Packet Storm
227495 7.5 危険 scripts frenzy - Article Publisher Pro の contact_author.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4902 2012-12-20 18:52 2008-11-3 Show GitHub Exploit DB Packet Storm
227496 7.5 危険 scripts frenzy - Article Publisher Pro の admin/admin.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4901 2012-12-20 18:52 2008-11-3 Show GitHub Exploit DB Packet Storm
227497 9.3 危険 SAP - SAP GUI の KWEdit ActiveX コントロールにおける任意のファイルを上書きされる脆弱性 CWE-Other
その他
CVE-2008-4830 2012-12-20 18:52 2009-04-16 Show GitHub Exploit DB Packet Storm
227498 7.5 危険 YourFreeWorld.com - YourFreeWorld Classifieds Blaster Script の tr.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4900 2012-12-20 18:52 2008-11-3 Show GitHub Exploit DB Packet Storm
227499 6.8 警告 planetluc - Planetluc RateMe におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-4899 2012-12-20 18:52 2008-11-3 Show GitHub Exploit DB Packet Storm
227500 4.3 警告 planetluc - planetluc RateMe におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-4898 2012-12-20 18:52 2008-11-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
222121 8.8 HIGH
Network
sitemagic sitemagic Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to validate incoming requests, allowing the execution of critical functionalities via s… CWE-352
 Origin Validation Error
CVE-2019-18220 2024-11-21 13:32 2019-10-23 Show GitHub Exploit DB Packet Storm
222122 7.5 HIGH
Network
haproxy haproxy A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing the "chunked" value were not being correctly rejected. The impact was limited but if co… CWE-444
HTTP Request Smuggling
CVE-2019-18277 2024-11-21 13:32 2019-10-23 Show GitHub Exploit DB Packet Storm
222123 6.1 MEDIUM
Network
sitemagic sitemagic Sitemagic CMS 4.4.1 is affected by a Cross-Site-Scripting (XSS) vulnerability, as it fails to validate user input. The affected components (index.php, upgrade.php) allow for JavaScript injection with… CWE-79
Cross-site Scripting
CVE-2019-18219 2024-11-21 13:32 2019-10-23 Show GitHub Exploit DB Packet Storm
222124 7.8 HIGH
Local
nipper-ng_project nipper-ng A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows remote attackers (serving firewall configuration files) to achieve Remote Code Ex… CWE-787
 Out-of-bounds Write
CVE-2019-17424 2024-11-21 13:32 2019-10-22 Show GitHub Exploit DB Packet Storm
222125 7.5 HIGH
Network
universal_office_converter_project universal_office_converter The unoconv package before 0.9 mishandles untrusted pathnames, leading to SSRF and local file inclusion. CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2019-17400 2024-11-21 13:32 2019-10-22 Show GitHub Exploit DB Packet Storm
222126 8.1 HIGH
Network
libssh2
fedoraproject
opensuse
debian
netapp
libssh2
fedora
leap
debian_linux
element_software
ontap_select_deploy_administration_utility
solidfire
hci_management_node
active_iq_unified_manager
bootstrap_os
In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a s… CWE-190
 Integer Overflow or Wraparound
CVE-2019-17498 2024-11-21 13:32 2019-10-22 Show GitHub Exploit DB Packet Storm
222127 9.8 CRITICAL
Network
citrix application_delivery_controller_firmware
netscaler_gateway_firmware
gateway_firmware
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway before 10.5 build 70.8, 11.x before 11.1 build 63.9, 12.0 before build 62.10, 12.1 before build 54.16, and 13.0 bef… NVD-CWE-noinfo
CVE-2019-18225 2024-11-21 13:32 2019-10-22 Show GitHub Exploit DB Packet Storm
222128 6.1 MEDIUM
Network
ricoh mp_501_firmware On the RICOH MP 501 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn and KeyDisplay parameter to /web/entry/en/address/a… CWE-79
Cross-site Scripting
CVE-2019-18203 2024-11-21 13:32 2019-10-22 Show GitHub Exploit DB Packet Storm
222129 9.8 CRITICAL
Network
gnu libidn2 idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string. CWE-787
 Out-of-bounds Write
CVE-2019-18224 2024-11-21 13:32 2019-10-22 Show GitHub Exploit DB Packet Storm
222130 7.8 HIGH
Local
file_project
debian
opensuse
netapp
fedoraproject
canonical
file
debian_linux
leap
active_iq_unified_manager
fedora
ubuntu_linux
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write). CWE-787
 Out-of-bounds Write
CVE-2019-18218 2024-11-21 13:32 2019-10-21 Show GitHub Exploit DB Packet Storm