Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228061 6.5 警告 xigla - Xigla Absolute Live Support XE の search.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2763 2012-12-20 18:52 2008-06-18 Show GitHub Exploit DB Packet Storm
228062 6.5 警告 xigla - Xigla Absolute Form Processor XE の search.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2762 2012-12-20 18:52 2008-06-18 Show GitHub Exploit DB Packet Storm
228063 3.5 注意 xigla - Xigla Absolute Banner Manager XE におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2761 2012-12-20 18:52 2008-06-18 Show GitHub Exploit DB Packet Storm
228064 6.5 警告 xigla - Xigla Absolute Banner Manager XE の searchbanners.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2760 2012-12-20 18:52 2008-06-18 Show GitHub Exploit DB Packet Storm
228065 4.3 警告 xigla - Xigla Absolute Form Processor XE におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2759 2012-12-20 18:52 2008-06-18 Show GitHub Exploit DB Packet Storm
228066 3.5 注意 xigla - Xigla Absolute News Manager XE におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2758 2012-12-20 18:52 2008-06-18 Show GitHub Exploit DB Packet Storm
228067 6.5 警告 xigla - Xigla Absolute News Manager XE の search.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2757 2012-12-20 18:52 2008-06-18 Show GitHub Exploit DB Packet Storm
228068 4.3 警告 xigla - Xigla Absolute Control Panel XE の admin/users.asp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2756 2012-12-20 18:52 2008-06-18 Show GitHub Exploit DB Packet Storm
228069 7.1 危険 サン・マイクロシステムズ - Sun Java System Calendar Server などの cshttpd におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2008-2749 2012-12-20 18:52 2008-06-13 Show GitHub Exploit DB Packet Storm
228070 5 警告 skulltag team - Skulltag におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2008-2748 2012-12-20 18:52 2008-06-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
224801 9.1 CRITICAL
Network
stb_project stb stb_image.h (aka the stb image loader) 2.23 has a heap-based buffer over-read in stbi__tga_load, leading to Information Disclosure or Denial of Service. CWE-125
Out-of-bounds Read
CVE-2019-15058 2024-11-21 13:27 2019-08-15 Show GitHub Exploit DB Packet Storm
224802 9.8 CRITICAL
Network
gradle gradle The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subs… CWE-522
 Insufficiently Protected Credentials
CVE-2019-15052 2024-11-21 13:27 2019-08-15 Show GitHub Exploit DB Packet Storm
224803 6.8 MEDIUM
Network
atlassian html_include_and_replace_macro The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism via vectors involving an IFRAME element. CWE-79
Cross-site Scripting
CVE-2019-15053 2024-11-21 13:27 2019-08-15 Show GitHub Exploit DB Packet Storm
224804 8.8 HIGH
Network
axiosys bento4 An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_AvccAtom class at Core/Ap4AvccAtom.cpp. CWE-125
Out-of-bounds Read
CVE-2019-15050 2024-11-21 13:27 2019-08-15 Show GitHub Exploit DB Packet Storm
224805 8.8 HIGH
Network
axiosys bento4 An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_Dec3Atom class at Core/Ap4Dec3Atom.cpp. CWE-125
Out-of-bounds Read
CVE-2019-15049 2024-11-21 13:27 2019-08-15 Show GitHub Exploit DB Packet Storm
224806 8.8 HIGH
Network
axiosys bento4 An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer overflow in the AP4_RtpAtom class at Core/Ap4RtpAtom.cpp. CWE-787
 Out-of-bounds Write
CVE-2019-15048 2024-11-21 13:27 2019-08-15 Show GitHub Exploit DB Packet Storm
224807 8.8 HIGH
Network
axiosys bento4 An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the function AP4_BitReader::SkipBits at Core/Ap4Utils.cpp. CWE-125
Out-of-bounds Read
CVE-2019-15047 2024-11-21 13:27 2019-08-15 Show GitHub Exploit DB Packet Storm
224808 6.1 MEDIUM
Network
sugarcrm sugarcrm SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS. CWE-79
Cross-site Scripting
CVE-2019-14974 2024-11-21 13:27 2019-08-15 Show GitHub Exploit DB Packet Storm
224809 7.5 HIGH
Network
zohocorp manageengine_servicedesk_plus Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS) replication, aka SD-79989. CWE-287
Improper Authentication
CVE-2019-15046 2024-11-21 13:27 2019-08-15 Show GitHub Exploit DB Packet Storm
224810 9.8 CRITICAL
Network
ninjaforms ninjaforms The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page. CWE-89
SQL Injection
CVE-2019-15025 2024-11-21 13:27 2019-08-15 Show GitHub Exploit DB Packet Storm