Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228181 4.3 警告 WordPress.org - WordPress におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2068 2012-12-20 18:52 2008-04-25 Show GitHub Exploit DB Packet Storm
228182 7.5 危険 YourFreeWorld.com - YourFreeWorld Jokes Site Script の jokes.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2065 2012-12-20 18:52 2008-05-2 Show GitHub Exploit DB Packet Storm
228183 10 危険 phpgedview - PhpGedView における脆弱性 CWE-noinfo
情報不足
CVE-2008-2064 2012-12-20 18:52 2008-05-2 Show GitHub Exploit DB Packet Storm
228184 4.3 警告 softpedia - Softpedia SiteXS CMS の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2046 2012-12-20 18:52 2008-05-1 Show GitHub Exploit DB Packet Storm
228185 5 警告 SugarCRM - SugarCRM Sugar Community Edition における絶対パストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-2045 2012-12-20 18:52 2008-04-10 Show GitHub Exploit DB Packet Storm
228186 6.5 警告 turnkey solutions - Turnkey Web Tools SunShop Shopping Cart の admin/adminindex.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2038 2012-12-20 18:52 2008-04-30 Show GitHub Exploit DB Packet Storm
228187 7.5 危険 Mike Jolley - WordPress 用の Download Monitor プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2034 2012-12-20 18:52 2008-04-30 Show GitHub Exploit DB Packet Storm
228188 7.5 危険 WordPress.org - WordPress 用の Spreadsheet プラグインの ss_load.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1982 2012-12-20 18:52 2008-04-27 Show GitHub Exploit DB Packet Storm
228189 7.5 危険 phphq - phShoutBox Final における権限を取得される脆弱性 CWE-287
不適切な認証
CVE-2008-1971 2012-12-20 18:52 2008-04-27 Show GitHub Exploit DB Packet Storm
228190 7.5 危険 quate - Quate Grape Web Statistics の includes/functions.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-1963 2012-12-20 18:52 2008-04-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
224681 6.2 MEDIUM
Local
linux linux_kernel In the Linux kernel before 5.2.3, drivers/block/floppy.c allows a denial of service by setup_format_params division-by-zero. Two consecutive ioctls can trigger the bug: the first one should set the d… CWE-369
 Divide By Zero
CVE-2019-14284 2024-11-21 13:26 2019-07-26 Show GitHub Exploit DB Packet Storm
224682 6.8 MEDIUM
Physics
linux linux_kernel In the Linux kernel before 5.2.3, set_geometry in drivers/block/floppy.c does not validate the sect and head fields, as demonstrated by an integer overflow and out-of-bounds read. It can be triggered… CWE-125
CWE-190
Out-of-bounds Read
 Integer Overflow or Wraparound
CVE-2019-14283 2024-11-21 13:26 2019-07-26 Show GitHub Exploit DB Packet Storm
224683 6.1 MEDIUM
Network
angry-frog xavier Xavier PHP Management Panel 3.0 is vulnerable to Reflected POST-based XSS via the username parameter when registering a new user at admin/includes/adminprocess.php. If there is an error when register… CWE-352
CWE-79
 Origin Validation Error
Cross-site Scripting
CVE-2019-14228 2024-11-21 13:26 2019-07-26 Show GitHub Exploit DB Packet Storm
224684 9.8 CRITICAL
Network
simple_captcha2_project simple_captcha2 The simple_captcha2 gem 0.2.3 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. CWE-94
Code Injection
CVE-2019-14282 2024-11-21 13:26 2019-07-26 Show GitHub Exploit DB Packet Storm
224685 9.8 CRITICAL
Network
datagrid_project datagrid The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. CWE-94
Code Injection
CVE-2019-14281 2024-11-21 13:26 2019-07-26 Show GitHub Exploit DB Packet Storm
224686 5.3 MEDIUM
Network
craftcms craft_cms In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to… CWE-200
Information Exposure
CVE-2019-14280 2024-11-21 13:26 2019-07-26 Show GitHub Exploit DB Packet Storm
224687 9.8 CRITICAL
Network
axway securetransport Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injection (and XXE) in the resetPassword functionality via the RES… CWE-91
Blind XPath Injection
CVE-2019-14277 2024-11-21 13:26 2019-07-26 Show GitHub Exploit DB Packet Storm
224688 5.5 MEDIUM
Local
xfig_project
debian
opensuse
fig2dev
debian_linux
leap
Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c. CWE-787
 Out-of-bounds Write
CVE-2019-14275 2024-11-21 13:26 2019-07-26 Show GitHub Exploit DB Packet Storm
224689 5.5 MEDIUM
Local
mcpp_project
opensuse
mcpp
leap
backports_sle
MCPP 2.7.2 has a heap-based buffer overflow in the do_msg() function in support.c. CWE-787
 Out-of-bounds Write
CVE-2019-14274 2024-11-21 13:26 2019-07-26 Show GitHub Exploit DB Packet Storm
224690 7.1 HIGH
Local
comodo firewall
internet_security
antivirus
Comodo Antivirus through 12.0.0.6870, Comodo Firewall through 12.0.0.6870, and Comodo Internet Security Premium through 12.0.0.6870, with the Comodo Container feature, are vulnerable to Sandbox Escap… NVD-CWE-noinfo
CVE-2019-14270 2024-11-21 13:26 2019-07-26 Show GitHub Exploit DB Packet Storm