Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 7, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227821 7.5 危険 tuned studios - Tuned Studios Subwoofer などの Web ページテンプレートにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0231 2012-12-20 18:34 2008-01-10 Show GitHub Exploit DB Packet Storm
227822 6.4 警告 Xine - xine-lib の input/libreal/rmff.c におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-0225 2012-12-20 18:34 2008-01-10 Show GitHub Exploit DB Packet Storm
227823 7.5 危険 runcms - RunCMS の Newbb_plus モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0224 2012-12-20 18:34 2008-01-10 Show GitHub Exploit DB Packet Storm
227824 7.5 危険 WordPress.org - WordPress 用の Wp-FileManager プラグインにおける任意の PHP コードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2008-0222 2012-12-20 18:34 2008-01-10 Show GitHub Exploit DB Packet Storm
227825 6.4 警告 uebimiau - Uebimiau Webmail における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2008-0210 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
227826 5.8 警告 snitz forums 2000 - Snitz Forums 2000 の Forums/login.asp におけるオープンリダイレクトの脆弱性 CWE-20
不適切な入力確認
CVE-2008-0209 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
227827 4.3 警告 snitz forums 2000 - Snitz Forums 2000 の login.asp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0208 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
227828 4.3 警告 pro search - PRO-Search におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0207 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
227829 4.3 警告 WordPress.org - WordPress 用の Captcha! プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0206 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
227830 4.3 警告 WordPress.org - WordPress 用の Math Comment Spam Protection プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0205 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 7, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
224141 6.5 MEDIUM
Network
ringcentral
zoom
ringcentral
zoom
In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a video call with the video camera active. This occurs because any web site can in… CWE-862
 Missing Authorization
CVE-2019-13450 2024-11-21 13:24 2019-07-9 Show GitHub Exploit DB Packet Storm
224142 6.5 MEDIUM
Network
zoom zoom In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a sequence of invalid launch?action=join&confno= requests to localhost port 19421. CWE-20
 Improper Input Validation 
CVE-2019-13449 2024-11-21 13:24 2019-07-9 Show GitHub Exploit DB Packet Storm
224143 6.1 MEDIUM
Network
boiteasite rencontre The Rencontre plugin before 3.1.3 for WordPress allows XSS via inc/rencontre_widget.php. CWE-79
Cross-site Scripting
CVE-2019-13414 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
224144 9.8 CRITICAL
Network
boiteasite rencontre The Rencontre plugin before 3.1.3 for WordPress allows SQL Injection via inc/rencontre_widget.php. CWE-89
SQL Injection
CVE-2019-13413 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
224145 9.8 CRITICAL
Network
strong_password_project strong_password The strong_password gem 0.0.7 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 0.0.6. CWE-94
Code Injection
CVE-2019-13354 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
224146 7.8 HIGH
Local
python python The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for local users to deploy Trojan horse code. (This also affects old 3.x releases be… CWE-552
 Files or Directories Accessible to External Parties
CVE-2019-13404 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
224147 8.8 HIGH
Network
fortinet fcm-mb40_firmware /usr/sbin/default.sh and /usr/apache/htdocs/cgi-bin/admin/hardfactorydefault.cgi on Dynacolor FCM-MB40 v1.2.0.0 devices implement an incomplete factory-reset process. A backdoor can persist because n… CWE-212
 Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2019-13402 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
224148 8.8 HIGH
Network
fortinet fcm-mb40_firmware Dynacolor FCM-MB40 v1.2.0.0 devices have CSRF in all scripts under cgi-bin/. CWE-352
 Origin Validation Error
CVE-2019-13401 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
224149 9.8 CRITICAL
Network
fortinet fcm-mb40_firmware Dynacolor FCM-MB40 v1.2.0.0 use /etc/appWeb/appweb.pass to store administrative web-interface credentials in cleartext. These credentials can be retrieved via cgi-bin/getuserinfo.cgi?mode=info. CWE-522
 Insufficiently Protected Credentials
CVE-2019-13400 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
224150 5.9 MEDIUM
Network
fortinet fcm-mb40_firmware Dynacolor FCM-MB40 v1.2.0.0 devices have a hard-coded SSL/TLS key that is used during an administrator's SSL conversation. CWE-798
 Use of Hard-coded Credentials
CVE-2019-13399 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm