Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 13, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228131 7.5 危険 v-webmail - V-webmail の login.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3063 2012-12-20 18:52 2008-10-7 Show GitHub Exploit DB Packet Storm
228132 7.5 危険 TYPO3 Association - TYPO3 用の DAM Frontend エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3039 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
228133 7.5 危険 TYPO3 Association - TYPO3 用の Address Directory エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3038 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
228134 4.3 警告 TYPO3 Association - TYPO3 用の Address Directory エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3037 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
228135 6.5 警告 xchangeboard - XchangeBoard の newThread.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3035 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
228136 7.5 危険 rss aggregator - RSS-aggregator における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3034 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
228137 9.3 危険 rss aggregator - RSS-aggregator における admin 関数へアクセスされ脆弱性 CWE-287
不適切な認証
CVE-2008-3033 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
228138 4.3 警告 The phpMyAdmin Project - TYPO3 用の phpMyAdmin エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3032 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
228139 7.5 危険 Thomas Abeel - Simple PHP Agenda の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-3031 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
228140 4.3 警告 Web-Empowered Church Team - TYPO3 用の WEC Discussion Forum エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3029 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 14, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
224901 8.8 HIGH
Network
adplug_project
fedoraproject
adplug
fedora
AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp. CWE-787
 Out-of-bounds Write
CVE-2019-14692 2024-11-21 13:27 2019-08-6 Show GitHub Exploit DB Packet Storm
224902 8.8 HIGH
Network
adplug_project
fedoraproject
adplug
fedora
AdPlug 2.3.1 has a heap-based buffer overflow in CdtmLoader::load() in dtm.cpp. CWE-787
 Out-of-bounds Write
CVE-2019-14691 2024-11-21 13:27 2019-08-6 Show GitHub Exploit DB Packet Storm
224903 8.8 HIGH
Network
adplug_project
fedoraproject
adplug
fedora
AdPlug 2.3.1 has a heap-based buffer overflow in CxadbmfPlayer::__bmf_convert_stream() in bmf.cpp. CWE-787
 Out-of-bounds Write
CVE-2019-14690 2024-11-21 13:27 2019-08-6 Show GitHub Exploit DB Packet Storm
224904 5.4 MEDIUM
Network
firefly-iii firefly_iii Firefly III 4.7.17.5 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the liability name field. The JavaScript code is executed upon an error condition during a visi… CWE-79
Cross-site Scripting
CVE-2019-14672 2024-11-21 13:27 2019-08-6 Show GitHub Exploit DB Packet Storm
224905 3.3 LOW
Local
firefly-iii firefly_iii Firefly III 4.7.17.3 is vulnerable to local file enumeration. An attacker can enumerate local files due to the lack of protocol scheme sanitization, such as for file:/// URLs. This is related to fint… CWE-20
 Improper Input Validation 
CVE-2019-14671 2024-11-21 13:27 2019-08-6 Show GitHub Exploit DB Packet Storm
224906 5.4 MEDIUM
Network
firefly-iii firefly_iii Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the bill name field. The JavaScript code is executed during rule-from-bill creation. CWE-79
Cross-site Scripting
CVE-2019-14670 2024-11-21 13:27 2019-08-6 Show GitHub Exploit DB Packet Storm
224907 5.4 MEDIUM
Network
firefly-iii firefly_iii Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the asset account name. The JavaScript code is executed during a visit to the audit account sta… CWE-79
Cross-site Scripting
CVE-2019-14669 2024-11-21 13:27 2019-08-6 Show GitHub Exploit DB Packet Storm
224908 5.4 MEDIUM
Network
firefly-iii firefly_iii Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the transaction description field. The JavaScript code is executed during deletion of a transac… CWE-79
Cross-site Scripting
CVE-2019-14668 2024-11-21 13:27 2019-08-6 Show GitHub Exploit DB Packet Storm
224909 6.1 MEDIUM
Network
firefly-iii firefly_iii Firefly III 4.7.17.4 is vulnerable to multiple stored XSS issues due to the lack of filtration of user-supplied data in the transaction description field and the asset account name. The JavaScript co… CWE-79
Cross-site Scripting
CVE-2019-14667 2024-11-21 13:27 2019-08-6 Show GitHub Exploit DB Packet Storm
224910 6.5 MEDIUM
Network
enigmail
fedoraproject
enigmail
fedora
In Enigmail below 2.1, an attacker in possession of PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASC… CWE-319
Cleartext Transmission of Sensitive Information
CVE-2019-14664 2024-11-21 13:27 2019-08-6 Show GitHub Exploit DB Packet Storm