Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227761 6.8 警告 stafford.uklinux - libESMTP における任意の SSL サーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2010-1192 2012-12-20 19:29 2010-03-31 Show GitHub Exploit DB Packet Storm
227762 6.4 警告 sahanafoundation - Sahana 災害管理システムにおけるアクセス制限を回避される脆弱性 CWE-287
不適切な認証
CVE-2010-1191 2012-12-20 19:29 2010-03-31 Show GitHub Exploit DB Packet Storm
227763 10 危険 SAP - SAP MaxDB の serv.exe におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-1185 2012-12-20 19:29 2010-03-29 Show GitHub Exploit DB Packet Storm
227764 3.3 注意 サン・マイクロシステムズ - Oracle Solaris の特定の patch-installation スクリプトにおける任意のファイルへのデータを追加される脆弱性 CWE-59
リンク解釈の問題
CVE-2010-1183 2012-12-20 19:29 2010-03-29 Show GitHub Exploit DB Packet Storm
227765 4.3 警告 phpmysite - phpMySite の contact.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-1091 2012-12-20 19:29 2010-03-24 Show GitHub Exploit DB Packet Storm
227766 7.5 危険 phpmysite - phpMySite の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1090 2012-12-20 19:29 2010-03-24 Show GitHub Exploit DB Packet Storm
227767 7.5 危険 phptroubleticket - PHP Trouble Ticket の vedi_faq.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1089 2012-12-20 19:29 2010-03-24 Show GitHub Exploit DB Packet Storm
227768 4.3 警告 PulseCMS - Pulse CMS の view.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-1080 2012-12-20 19:29 2010-03-23 Show GitHub Exploit DB Packet Storm
227769 4.3 警告 Sawmill - Sawmill におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-1079 2012-12-20 19:29 2010-03-23 Show GitHub Exploit DB Packet Storm
227770 7.5 危険 sphere.xlentprojects - XlentProjects SphereCMSSpey の archive.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1078 2012-12-20 19:29 2010-03-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
225241 5.5 MEDIUM
Local
linux linux_kernel In the AppleTalk subsystem in the Linux kernel before 5.1, there is a potential NULL pointer dereference because register_snap_client may return NULL. This will lead to denial of service in net/apple… CWE-476
 NULL Pointer Dereference
CVE-2019-19227 2024-11-21 13:34 2019-11-22 Show GitHub Exploit DB Packet Storm
225242 5.5 MEDIUM
Local
libarchive
debian
fedoraproject
canonical
libarchive
debian_linux
fedora
ubuntu_linux
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive. CWE-125
Out-of-bounds Read
CVE-2019-19221 2024-11-21 13:34 2019-11-22 Show GitHub Exploit DB Packet Storm
225243 8.8 HIGH
Network
rconfig rconfig rConfig 3.9.2 allows devices.php?searchColumn= SQL injection. CWE-89
SQL Injection
CVE-2019-19207 2024-11-21 13:34 2019-11-22 Show GitHub Exploit DB Packet Storm
225244 7.5 HIGH
Network
oniguruma_project
debian
fedoraproject
oniguruma
debian_linux
fedora
An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. … CWE-125
Out-of-bounds Read
CVE-2019-19204 2024-11-21 13:34 2019-11-22 Show GitHub Exploit DB Packet Storm
225245 7.5 HIGH
Network
oniguruma_project
fedoraproject
oniguruma
fedora
An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced without checking if it passed the end of the matched … CWE-125
Out-of-bounds Read
CVE-2019-19203 2024-11-21 13:34 2019-11-22 Show GitHub Exploit DB Packet Storm
225246 8.8 HIGH
Network
vtiger vtiger_crm In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding roleid=H2 to a POST request. CWE-276
Incorrect Default Permissions 
CVE-2019-19202 2024-11-21 13:34 2019-11-22 Show GitHub Exploit DB Packet Storm
225247 7.8 HIGH
Local
kyrolsecuritylabs kyrol_internet_security IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an attacker to achieve privilege escalation, denial-of-service, and code execution via usermode because 0x9C402401 usi… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2019-19197 2024-11-21 13:34 2019-11-22 Show GitHub Exploit DB Packet Storm
225248 7.8 HIGH
Local
shibboleth service_provider Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the shibd account) after installation. This allows the u… CWE-59
Link Following
CVE-2019-19191 2024-11-21 13:34 2019-11-22 Show GitHub Exploit DB Packet Storm
225249 9.8 CRITICAL
Network
jalios jcms Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges via a backdoor account, by using any username and the hardcoded dev password. CWE-798
 Use of Hard-coded Credentials
CVE-2019-19033 2024-11-21 13:34 2019-11-22 Show GitHub Exploit DB Packet Storm
225250 5.5 MEDIUM
Local
linux linux_kernel ext4_empty_dir in fs/ext4/namei.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because ext4_read_dirblock(inode,0,DIRENT_HTREE) can be zero. CWE-476
 NULL Pointer Dereference
CVE-2019-19037 2024-11-21 13:34 2019-11-21 Show GitHub Exploit DB Packet Storm