Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 3, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228111 6.8 警告 xlightftpd - Xlight FTP Server における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4795 2012-12-20 19:28 2010-04-22 Show GitHub Exploit DB Packet Storm
228112 7.5 危険 ryan haudenschilt - Family Connections における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4791 2012-12-20 19:28 2010-04-22 Show GitHub Exploit DB Packet Storm
228113 5 警告 XOOPS - XOOPS の Profiles モジュールにおける管理者による承認を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-4851 2012-12-20 19:28 2009-11-11 Show GitHub Exploit DB Packet Storm
228114 7.5 危険 phplivesupport - PHP Live! における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4749 2012-12-20 19:28 2010-03-26 Show GitHub Exploit DB Packet Storm
228115 7.5 危険 Tecnick.com - AIOCP の public/code/cp_html2xhtmlbasic.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-4747 2012-12-20 19:28 2010-03-26 Show GitHub Exploit DB Packet Storm
228116 10 危険 Skype Technologies S.A. - Windows 上で稼動する Skype の Extras Manager における脆弱性 CWE-noinfo
情報不足
CVE-2009-4741 2012-12-20 19:28 2010-03-26 Show GitHub Exploit DB Packet Storm
228117 7.5 危険 TYPO3 Association - TYPO3 用の Webesse E-Card エクステンションにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-4740 2012-12-20 19:28 2010-03-26 Show GitHub Exploit DB Packet Storm
228118 6.8 警告 skadate - SkaDate Dating の index.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-4739 2012-12-20 19:28 2010-03-26 Show GitHub Exploit DB Packet Storm
228119 4.3 警告 sensesites - CommonSense CMS の search.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4736 2012-12-20 19:28 2010-03-23 Show GitHub Exploit DB Packet Storm
228120 6.8 警告 supercrackmunkey - SimpleLoginSys の checkuser.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4733 2012-12-20 19:28 2010-03-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 3, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
225991 10.0 CRITICAL
Network
eleveo call_recording Zoom Call Recording 6.3.1 from Eleveo is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A remote unauthenticated attacker can exploit this vulnerability by sending craf… CWE-502
 Deserialization of Untrusted Data
CVE-2019-19810 2024-11-21 13:35 2021-10-28 Show GitHub Exploit DB Packet Storm
225992 7.5 HIGH
Network
br-automation industrial_automation_aprol An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to historical data from AprolSqlServer by bypassing authentication, a different vulnerability … NVD-CWE-noinfo
CVE-2019-19878 2024-11-21 13:35 2020-11-28 Show GitHub Exploit DB Packet Storm
225993 5.3 MEDIUM
Network
br-automation industrial_automation_aprol An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to sensitive information outside the working directory via Directory Traversal attacks against… CWE-22
Path Traversal
CVE-2019-19877 2024-11-21 13:35 2020-11-28 Show GitHub Exploit DB Packet Storm
225994 9.8 CRITICAL
Network
br-automation industrial_automation_aprol An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An EnMon PHP script was vulnerable to SQL injection, a different vulnerability than CVE-2019-10006. CWE-89
SQL Injection
CVE-2019-19876 2024-11-21 13:35 2020-11-28 Show GitHub Exploit DB Packet Storm
225995 9.8 CRITICAL
Network
br-automation industrial_automation_aprol An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Arbitrary commands could be injected (using Python scripts) via the AprolCluster script that is invoked via sudo and thus… CWE-77
Command Injection
CVE-2019-19875 2024-11-21 13:35 2020-11-28 Show GitHub Exploit DB Packet Storm
225996 9.8 CRITICAL
Network
br-automation industrial_automation_aprol An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Some web scripts in the web interface allowed injection and execution of arbitrary unintended commands on the web server,… CWE-77
Command Injection
CVE-2019-19874 2024-11-21 13:35 2020-11-28 Show GitHub Exploit DB Packet Storm
225997 7.5 HIGH
Network
br-automation industrial_automation_aprol An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get information from the AprolSqlServer DBMS by bypassing authentication, a different vulnerability than … NVD-CWE-noinfo
CVE-2019-19873 2024-11-21 13:35 2020-11-28 Show GitHub Exploit DB Packet Storm
225998 9.8 CRITICAL
Network
br-automation industrial_automation_aprol An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. The AprolLoader could be used to inject and execute arbitrary unintended commands via an unspecified attack scenario, a d… CWE-77
Command Injection
CVE-2019-19872 2024-11-21 13:35 2020-11-28 Show GitHub Exploit DB Packet Storm
225999 7.5 HIGH
Network
br-automation industrial_automation_aprol An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. PVs could be changed (unencrypted) by using the IosHttp service and the JSON interface. NVD-CWE-noinfo
CVE-2019-19869 2024-11-21 13:35 2020-11-28 Show GitHub Exploit DB Packet Storm
226000 9.1 CRITICAL
Network
bender com465ip_firmware
com465dp_firmware
com465id_firmware
cp700_firmware
cp907_firmware
cp915_firmware
In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system. A user with knowledge about the routes can read and write configuration data without prior authorizati… CWE-862
 Missing Authorization
CVE-2019-19885 2024-11-21 13:35 2020-10-16 Show GitHub Exploit DB Packet Storm