Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 5, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227611 4.3 警告 phpslideshow - PHPSlideShow の phpslideshow.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6135 2012-12-20 18:33 2007-11-27 Show GitHub Exploit DB Packet Storm
227612 7.5 危険 PHPKIT - PHPKIT の pkinc/public/article.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6134 2012-12-20 18:33 2007-11-27 Show GitHub Exploit DB Packet Storm
227613 2.1 注意 レッドハット - scanbuttond の buttonpressed.sh における任意のファイルを上書きされる脆弱性 CWE-16
環境設定
CVE-2007-6131 2012-12-20 18:33 2007-11-14 Show GitHub Exploit DB Packet Storm
227614 7.5 危険 project alumni - project alumni における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6127 2012-12-20 18:33 2007-11-26 Show GitHub Exploit DB Packet Storm
227615 4.3 警告 project alumni - project alumni におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6126 2012-12-20 18:33 2007-11-26 Show GitHub Exploit DB Packet Storm
227616 7.5 危険 softbiz - Softbiz Freelancers Script の search_form.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6125 2012-12-20 18:33 2007-11-26 Show GitHub Exploit DB Packet Storm
227617 4.3 警告 softbiz - Softbiz Freelancers Script の signin.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6124 2012-12-20 18:33 2007-11-26 Show GitHub Exploit DB Packet Storm
227618 6.8 警告 talkback - TalkBack における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-6105 2012-12-20 18:33 2007-11-23 Show GitHub Exploit DB Packet Storm
227619 2.6 注意 The phpMyAdmin Project - phpMyAdmin の libraries/auth/cookie.auth.lib.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6100 2012-12-20 18:33 2007-11-20 Show GitHub Exploit DB Packet Storm
227620 9.3 危険 phpbbviet - phpBBViet の includes/functions_mod_user.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-6088 2012-12-20 18:33 2007-11-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
213811 6.5 MEDIUM
Network
adobe acrobat_dc
acrobat_reader_dc
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier version, 2017.011.30138 and earlier version, 2015.006.30495 and earlier, and 2015.… CWE-125
Out-of-bounds Read
CVE-2019-7758 2024-11-21 13:48 2019-05-22 Show GitHub Exploit DB Packet Storm
213812 9.1 CRITICAL
Network
gitlab gitlab An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 11.7.x before 11.7.4. GitLab Releases were vulnerable to an authorization issue that allowed users to view … CWE-200
Information Exposure
CVE-2019-7353 2024-11-21 13:48 2019-05-18 Show GitHub Exploit DB Packet Storm
213813 9.8 CRITICAL
Network
mobatek mobaxterm In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from process memory for the lifetime of the process, even after the user disconnects from… CWE-255
Credentials Management
CVE-2019-7690 2024-11-21 13:48 2019-05-14 Show GitHub Exploit DB Packet Storm
213814 5.4 MEDIUM
Network
mythemeshop launcher Multiple stored cross-site scripting (XSS) in the MyThemeShop Launcher plugin 1.0.8 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via fields as follows: (1) Ti… CWE-79
Cross-site Scripting
CVE-2019-7411 2024-11-21 13:48 2019-05-13 Show GitHub Exploit DB Packet Storm
213815 6.1 MEDIUM
Network
vegadesign profiledesign_cms Multiple cross-site scripting (XSS) vulnerabilities in ProfileDesign CMS v6.0.2.5 allows remote attackers to inject arbitrary web script or HTML via the (1) page, (2) gbs, (3) side, (4) id, (5) imgid… CWE-79
Cross-site Scripting
CVE-2019-7409 2024-11-21 13:48 2019-05-13 Show GitHub Exploit DB Packet Storm
213816 7.5 HIGH
Network
lg gamp-7100_firmware
gapm-7200_firmware
gapm-8000_firmware
An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file via an HTTP request containing its full pathname, such as http://192.168.0.1/var… CWE-306
Missing Authentication for Critical Function
CVE-2019-7404 2024-11-21 13:48 2019-05-13 Show GitHub Exploit DB Packet Storm
213817 7.7 HIGH
Network
thehive-project cortex-analyzers TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the vulnerability, an attacker must create a new analysis, select URL for Data Type… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2019-7652 2024-11-21 13:48 2019-05-10 Show GitHub Exploit DB Packet Storm
213818 9.8 CRITICAL
Network
cyberark enterprise_password_vault An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attackers to read arbitrary files or potentially bypass a… CWE-611
XXE
CVE-2019-7442 2024-11-21 13:48 2019-05-9 Show GitHub Exploit DB Packet Storm
213819 8.1 HIGH
Network
jio jmr1140_firmware JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain an admin token by making a /cgi-bin/qcmap_auth type=getuser request and then reading the token field. This token value ca… CWE-352
 Origin Validation Error
CVE-2019-7746 2024-11-21 13:48 2019-05-8 Show GitHub Exploit DB Packet Storm
213820 9.8 CRITICAL
Network
jio jmr1140_firmware JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain the Wi-Fi password by making a cgi-bin/qcmap_web_cgi Page=GetWiFi_Setting request and then reading the wpa_security_key f… NVD-CWE-noinfo
CVE-2019-7745 2024-11-21 13:48 2019-05-8 Show GitHub Exploit DB Packet Storm