Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 4, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227841 4.3 警告 phpgedview - PhpGedView におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-5051 2012-12-20 18:33 2007-09-23 Show GitHub Exploit DB Packet Storm
227842 7.2 危険 シマンテック - Norton Internet Security におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2007-5047 2012-12-20 18:33 2007-09-23 Show GitHub Exploit DB Packet Storm
227843 6.9 警告 zonelabs - ZoneAlarm におけるサービス運用妨害 (DoS) の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-5044 2012-12-20 18:33 2007-09-23 Show GitHub Exploit DB Packet Storm
227844 4.3 警告 phpbb xs - phpBB XS の profile.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-5033 2012-12-20 18:33 2007-09-21 Show GitHub Exploit DB Packet Storm
227845 9.3 危険 VMware - EMC VMware ACE における脆弱性 CWE-noinfo
情報不足
CVE-2007-5025 2012-12-20 18:33 2007-09-21 Show GitHub Exploit DB Packet Storm
227846 6.9 警告 VMware - EMC VMware Workstation などにおける権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-5023 2012-12-20 18:33 2007-09-21 Show GitHub Exploit DB Packet Storm
227847 10 危険 サン・マイクロシステムズ - JRE の Sun Java Web Start ActiveX コントロールにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-5019 2012-12-20 18:33 2007-09-20 Show GitHub Exploit DB Packet Storm
227848 5 警告 Yahoo! - Yahoo! Messenger の ft60.dll における絶対パストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-5017 2012-12-20 18:33 2007-09-20 Show GitHub Exploit DB Packet Storm
227849 6.8 警告 streamline - Streamline PHP Media Server における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-5015 2012-12-20 18:33 2007-09-20 Show GitHub Exploit DB Packet Storm
227850 4.3 警告 phpwebgallery - PhpWebGallery の picture.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-5012 2012-12-20 18:33 2007-09-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 5, 2026, 4:51 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
222571 4.8 MEDIUM
Network
una una studio/polyglot.php?page=etemplates in UNA 10.0.0-RC1 allows XSS via the System Name field under Emails during template editing. CWE-79
Cross-site Scripting
CVE-2019-14804 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm
222572 9.8 CRITICAL
Network
foliovision fv_flowplayer_video_player The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection. CWE-89
SQL Injection
CVE-2019-14801 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm
222573 4.9 MEDIUM
Network
10web photo_gallery The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter. CWE-22
Path Traversal
CVE-2019-14798 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm
222574 5.4 MEDIUM
Network
10web photo_gallery The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS. CWE-79
Cross-site Scripting
CVE-2019-14797 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm
222575 5.4 MEDIUM
Network
mq-woocommerce-products-price-bulk-edit_project mq-woocommerce-products-price-bulk-edit The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=update_options show_products_page_lim… CWE-79
Cross-site Scripting
CVE-2019-14796 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm
222576 7.5 HIGH
Network
metabox meta_box The Meta Box plugin before 4.16.2 for WordPress mishandles the uploading of files to custom folders. CWE-19
 Data Processing Errors
CVE-2019-14794 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm
222577 6.1 MEDIUM
Network
codepeople appointment_booking_calendar The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter. CWE-79
Cross-site Scripting
CVE-2019-14791 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm
222578 6.1 MEDIUM
Network
foliovision fv_flowplayer_video_player The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS. CWE-79
Cross-site Scripting
CVE-2019-14799 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm
222579 6.5 MEDIUM
Network
metabox meta_box The Meta Box plugin before 4.16.3 for WordPress allows file deletion via ajax, with the wp-admin/admin-ajax.php?action=rwmb_delete_file attachment_id parameter. CWE-862
 Missing Authorization
CVE-2019-14793 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm
222580 5.4 MEDIUM
Network
codecabin wp_go_maps The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter. CWE-79
Cross-site Scripting
CVE-2019-14792 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm