Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 7, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228061 4.3 警告 Trolltech - Trolltech Qt の QSslSocket における偽装サービスの無効なサーバ証明書を承認するようにユーザを騙す脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-5965 2012-12-20 18:33 2008-01-7 Show GitHub Exploit DB Packet Storm
228062 4.3 警告 レッドハット - RHN および Red Hat Network Satellite で使用されている Red Hat Network チャンネル検索機能におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-5961 2012-12-20 18:33 2008-05-20 Show GitHub Exploit DB Packet Storm
228063 6.5 警告 SoftbizScripts - Softbiz Ad Management plus Script の ads.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-5998 2012-12-20 18:33 2007-11-15 Show GitHub Exploit DB Packet Storm
228064 6.5 警告 SoftbizScripts - Softbiz Banner Exchange Network Script の campaign_stats.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-5997 2012-12-20 18:33 2007-11-15 Show GitHub Exploit DB Packet Storm
228065 7.5 危険 SoftbizScripts - Softbiz Link Directory Script の searchresult.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-5996 2012-12-20 18:33 2007-11-15 Show GitHub Exploit DB Packet Storm
228066 6.8 警告 php-tools - patBBcode の examples/patExampleGen/bbcodeSource.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-5995 2012-12-20 18:33 2007-11-15 Show GitHub Exploit DB Packet Storm
228067 6.8 警告 yappa-ng - Fritz Berger yappa-ng の check_noimage.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-5994 2012-12-20 18:33 2007-11-15 Show GitHub Exploit DB Packet Storm
228068 4.3 警告 vtls - VTLS vtls.web.gateway の Visionary Technology におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-5993 2012-12-20 18:33 2007-11-15 Show GitHub Exploit DB Packet Storm
228069 6.8 警告 Skype Technologies S.A. - Skype の skype4com URI ハンドラにおける任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2007-5989 2012-12-20 18:33 2007-12-13 Show GitHub Exploit DB Packet Storm
228070 4.3 警告 X7 Group - X7 Chat におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-5982 2012-12-20 18:33 2007-11-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 7, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
224261 8.8 HIGH
Network
dlink dir-823g_firmware An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the IPAddress or Gateway … CWE-78
OS Command 
CVE-2019-13128 2024-11-21 13:24 2019-07-2 Show GitHub Exploit DB Packet Storm
224262 6.1 MEDIUM
Network
draw
jgraph
draw.io_diagrams
mxgraph
An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field lea… CWE-79
CWE-20
Cross-site Scripting
 Improper Input Validation 
CVE-2019-13127 2024-11-21 13:24 2019-07-2 Show GitHub Exploit DB Packet Storm
224263 7.8 HIGH
Local
tencent habomalhunter HaboMalHunter through 2.0.0.3 in Tencent Habo allows attackers to evade dynamic malware analysis via PIE compilation. CWE-264
Permissions, Privileges, and Access Controls
CVE-2019-13125 2024-11-21 13:24 2019-07-1 Show GitHub Exploit DB Packet Storm
224264 5.3 MEDIUM
Network
xmlsoft
opensuse
netapp
oracle
fedoraproject
canonical
apple
libxslt
leap
cloud_backup
steelstore_cloud_integrated_storage
oncommand_workflow_automation
oncommand_insight
ontap_select_deploy_administration_utility
clustered_data_ontap
e…
In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, … CWE-843
Type Confusion
CVE-2019-13118 2024-11-21 13:24 2019-07-1 Show GitHub Exploit DB Packet Storm
224265 5.3 MEDIUM
Network
xmlsoft
debian
canonical
fedoraproject
opensuse
oracle
libxslt
debian_linux
ubuntu_linux
fedora
leap
openjdk
In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte o… CWE-908
 Use of Uninitialized Resource
CVE-2019-13117 2024-11-21 13:24 2019-07-1 Show GitHub Exploit DB Packet Storm
224266 6.5 MEDIUM
Network
exiv2
fedoraproject
debian
canonical
exiv2
fedora
debian_linux
ubuntu_linux
http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character. CWE-476
 NULL Pointer Dereference
CVE-2019-13114 2024-11-21 13:24 2019-07-1 Show GitHub Exploit DB Packet Storm
224267 6.5 MEDIUM
Network
exiv2
fedoraproject
canonical
exiv2
fedora
ubuntu_linux
Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid data location in a CRW image file. CWE-617
 Reachable Assertion
CVE-2019-13113 2024-11-21 13:24 2019-07-1 Show GitHub Exploit DB Packet Storm
224268 6.5 MEDIUM
Network
exiv2
fedoraproject
canonical
debian
exiv2
fedora
ubuntu_linux
debian_linux
A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to an std::bad_alloc exception) via a crafted PNG image… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2019-13112 2024-11-21 13:24 2019-07-1 Show GitHub Exploit DB Packet Storm
224269 5.5 MEDIUM
Local
exiv2
fedoraproject
exiv2
fedora
A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by a very long running loop) via a crafted WEBP imag… CWE-190
 Integer Overflow or Wraparound
CVE-2019-13111 2024-11-21 13:24 2019-07-1 Show GitHub Exploit DB Packet Storm
224270 6.5 MEDIUM
Network
exiv2
fedoraproject
canonical
debian
exiv2
fedora
ubuntu_linux
debian_linux
A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted CRW image file. CWE-125
CWE-190
Out-of-bounds Read
 Integer Overflow or Wraparound
CVE-2019-13110 2024-11-21 13:24 2019-07-1 Show GitHub Exploit DB Packet Storm