Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 19, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227491 4.3 警告 realtysoft - PG Roommate Finder Solution におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2772 2012-12-20 19:10 2009-08-14 Show GitHub Exploit DB Packet Storm
227492 7.5 危険 powerupload - PowerUpload における管理者アクセス権を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-2770 2012-12-20 19:10 2009-08-14 Show GitHub Exploit DB Packet Storm
227493 6.8 警告 ultrize - Ultrize TimeSheet の include/timesheet.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-2769 2012-12-20 19:10 2009-08-14 Show GitHub Exploit DB Packet Storm
227494 7.5 危険 WordPress.org - WordPress の wp-login.php におけるデータベースの最初のユーザパスワードを強制的にリセットされる脆弱性 CWE-255
証明書・パスワード管理
CVE-2009-2762 2012-12-20 19:10 2009-08-12 Show GitHub Exploit DB Packet Storm
227495 5.5 警告 Roundup - Roundup の cgi/actions.py におけるクラス内の任意の項目を変更される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-2737 2012-12-20 19:10 2009-08-11 Show GitHub Exploit DB Packet Storm
227496 6.5 警告 sun-jester - sun-jester OpenNews の admin.php における任意の PHP コードを挿入される脆弱性 CWE-94
コード・インジェクション
CVE-2009-2736 2012-12-20 19:10 2009-08-11 Show GitHub Exploit DB Packet Storm
227497 6.8 警告 sun-jester - sun-jester OpenNews の admin.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2735 2012-12-20 19:10 2009-08-11 Show GitHub Exploit DB Packet Storm
227498 5 警告 サン・マイクロシステムズ - Sun Java SE の Swing 実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2009-2720 2012-12-20 19:10 2009-08-10 Show GitHub Exploit DB Packet Storm
227499 5 警告 サン・マイクロシステムズ - Sun Java SE の Java Web Start 実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2009-2719 2012-12-20 19:10 2009-08-10 Show GitHub Exploit DB Packet Storm
227500 6.8 警告 サン・マイクロシステムズ - Sun Java SE の AWT 実装におけるユーザに信頼されないアプレットと保護されない通信をさせる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-2718 2012-12-20 19:10 2009-08-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 19, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
224781 5.5 MEDIUM
Local
axiosys bento4 Bento4 1.5.1-628 has a NULL pointer dereference in AP4_ByteStream::ReadUI32 in Core/Ap4ByteStream.cpp when called from the AP4_TrunAtom class. CWE-476
 NULL Pointer Dereference
CVE-2019-16349 2024-11-21 13:30 2019-09-16 Show GitHub Exploit DB Packet Storm
224782 6.5 MEDIUM
Network
libwav_project libwav marc-q libwav through 2017-04-20 has a NULL pointer dereference in gain_file() at wav_gain.c. CWE-476
 NULL Pointer Dereference
CVE-2019-16348 2024-11-21 13:30 2019-09-16 Show GitHub Exploit DB Packet Storm
224783 8.8 HIGH
Network
miniupnp_project ngiflib ngiflib 0.4 has a heap-based buffer overflow in WritePixels() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pictures is mishandled. CWE-787
CWE-682
 Out-of-bounds Write
 Incorrect Calculation
CVE-2019-16347 2024-11-21 13:30 2019-09-16 Show GitHub Exploit DB Packet Storm
224784 8.8 HIGH
Network
miniupnp_project ngiflib ngiflib 0.4 has a heap-based buffer overflow in WritePixel() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pictures is mishandled. CWE-787
CWE-682
 Out-of-bounds Write
 Incorrect Calculation
CVE-2019-16346 2024-11-21 13:30 2019-09-16 Show GitHub Exploit DB Packet Storm
224785 9.8 CRITICAL
Network
egpp sistema_integrado_de_gestion_academica In Escuela de Gestion Publica Plurinacional (EGPP) Sistema Integrado de Gestion Academica (GESAC) v1, the username parameter of the authentication form is vulnerable to SQL injection, allowing attack… CWE-89
SQL Injection
CVE-2019-16264 2024-11-21 13:30 2019-09-16 Show GitHub Exploit DB Packet Storm
224786 6.1 MEDIUM
Network
dolibarr dolibarr_erp\/crm In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS. CWE-79
Cross-site Scripting
CVE-2019-16197 2024-11-21 13:30 2019-09-16 Show GitHub Exploit DB Packet Storm
224787 7.1 HIGH
Network
gitlab gitlab An issue was discovered in GitLab Enterprise Edition 11.x and 12.x before 12.0.9, 12.1.x before 12.1.9, and 12.2.x before 12.2.5. It has Incorrect Access Control. NVD-CWE-noinfo
CVE-2019-16170 2024-11-21 13:30 2019-09-16 Show GitHub Exploit DB Packet Storm
224788 9.8 CRITICAL
Network
fasterxml
fedoraproject
debian
netapp
redhat
oracle
jackson-databind
fedora
debian_linux
steelstore_cloud_integrated_storage
oncommand_workflow_automation
oncommand_api_services
jboss_enterprise_application_platform
retail_xstore_…
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540. CWE-502
 Deserialization of Untrusted Data
CVE-2019-16335 2024-11-21 13:30 2019-09-16 Show GitHub Exploit DB Packet Storm
224789 4.8 MEDIUM
Network
bludit bludit In Bludit v3.9.2, there is a persistent XSS vulnerability in the Categories -> Add New Category -> Name field. NOTE: this may overlap CVE-2017-16636. CWE-79
Cross-site Scripting
CVE-2019-16334 2024-11-21 13:30 2019-09-16 Show GitHub Exploit DB Packet Storm
224790 5.4 MEDIUM
Network
get-simple getsimple_cms GetSimple CMS v3.3.15 has Persistent Cross-Site Scripting (XSS) in admin/theme-edit.php. CWE-79
Cross-site Scripting
CVE-2019-16333 2024-11-21 13:30 2019-09-16 Show GitHub Exploit DB Packet Storm