Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227741 6.8 警告 phpdj - PHPDJ の djpage.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-5574 2012-12-20 18:33 2007-10-18 Show GitHub Exploit DB Packet Storm
227742 4.3 警告 sphpblog - Simple PHP Blog におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2007-5572 2012-12-20 18:33 2007-10-18 Show GitHub Exploit DB Packet Storm
227743 2.6 注意 simple php forum - NSSboard におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-5564 2012-12-20 18:33 2007-10-18 Show GitHub Exploit DB Packet Storm
227744 7.5 危険 VirtueMart - VirtueMart における任意の PHP コードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2007-5563 2012-12-20 18:33 2007-10-18 Show GitHub Exploit DB Packet Storm
227745 6.9 警告 シマンテック - Symantec Altiris Deployment Solution における認証資格情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2007-5555 2012-12-20 18:33 2007-08-13 Show GitHub Exploit DB Packet Storm
227746 9.3 危険 TIBCO Software - TIBCO SmartPGM FX におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-5546 2012-12-20 18:33 2007-10-18 Show GitHub Exploit DB Packet Storm
227747 7.5 危険 TIBCO Software - TIBCO SmartPGM FX におけるフォーマットストリングの脆弱性 CWE-134
書式文字列の問題
CVE-2007-5545 2012-12-20 18:33 2007-10-18 Show GitHub Exploit DB Packet Storm
227748 10 危険 runcms - RunCms の newbb_plus における脆弱性 CWE-noinfo
情報不足
CVE-2007-5535 2012-12-20 18:33 2007-10-17 Show GitHub Exploit DB Packet Storm
227749 4.6 警告 sitebar - SiteBar の translator.php における任意の PHP コードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2007-5492 2012-12-20 18:33 2007-10-17 Show GitHub Exploit DB Packet Storm
227750 9 危険 sitebar - SiteBar の translator.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-5491 2012-12-20 18:33 2007-10-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
222431 6.1 MEDIUM
Network
diaowen dwsurvey DWSurvey through 2019-07-22 has reflected XSS via the design/qu-multi-fillblank!answers.action surveyId parameter. CWE-79
Cross-site Scripting
CVE-2019-15095 2024-11-21 13:28 2019-08-16 Show GitHub Exploit DB Packet Storm
222432 6.7 MEDIUM
Local
linux
canonical
opensuse
linux_kernel
ubuntu_linux
leap
An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-bounds read. CWE-125
Out-of-bounds Read
CVE-2019-15090 2024-11-21 13:28 2019-08-16 Show GitHub Exploit DB Packet Storm
222433 7.8 HIGH
Local
maxx waves_maxx_audio Realtek Waves MaxxAudio driver 1.6.2.0, as used on Dell laptops, installs with incorrect file permissions. As a result, a local attacker can escalate to SYSTEM. CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2019-15084 2024-11-21 13:28 2019-08-16 Show GitHub Exploit DB Packet Storm
222434 4.8 MEDIUM
Network
opencart opencart OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing feature of the Categories, Product, and Information pages. CWE-79
Cross-site Scripting
CVE-2019-15081 2024-11-21 13:28 2019-08-16 Show GitHub Exploit DB Packet Storm
222435 6.5 MEDIUM
Network
gitlab gitlab An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection of command-line flags. This sometimes leads to pri… CWE-77
Command Injection
CVE-2019-14944 2024-11-21 13:27 2023-04-16 Show GitHub Exploit DB Packet Storm
222436 5.9 MEDIUM
Network
gitlab gitlab An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Cookies for GitLab Pages (which have access control) could be sent over cl… CWE-319
Cleartext Transmission of Sensitive Information
CVE-2019-14942 2024-11-21 13:27 2023-04-16 Show GitHub Exploit DB Packet Storm
222437 5.3 MEDIUM
Network
hashicorp nomad HashiCorp Nomad 0.5.0 through 0.9.4 (fixed in 0.9.5) reveals unintended environment variables to the rendering task during template rendering, aka GHSA-6hv3-7c34-4hx8. This applies to nomad/client/al… NVD-CWE-noinfo
CVE-2019-14802 2024-11-21 13:27 2022-12-27 Show GitHub Exploit DB Packet Storm
222438 8.8 HIGH
Network
redhat decision_manager
process_automation
A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin privileges in the Business Central Cons… CWE-281
 Improper Preservation of Permissions
CVE-2019-14841 2024-11-21 13:27 2022-10-18 Show GitHub Exploit DB Packet Storm
222439 7.5 HIGH
Network
redhat decision_manager A flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of credentials. - CVE-2019-14840 2024-11-21 13:27 2022-10-18 Show GitHub Exploit DB Packet Storm
222440 7.5 HIGH
Network
redhat process_automation
descision_manager
business-central
It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc. CWE-200
Information Exposure
CVE-2019-14839 2024-11-21 13:27 2022-04-2 Show GitHub Exploit DB Packet Storm