Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228261 7.5 危険 qdblog - QDBlog の authenticate.php における SQL インジェクションの脆弱性 - CVE-2007-2305 2012-12-20 18:19 2007-04-26 Show GitHub Exploit DB Packet Storm
228262 7.5 危険 qdblog - QDBlog におけるディレクトリトラバーサルの脆弱性 - CVE-2007-2304 2012-12-20 18:19 2007-04-26 Show GitHub Exploit DB Packet Storm
228263 4.3 警告 surat kabar - Endy Kristanto Surat kabar / News Management Online におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-2300 2012-12-20 18:19 2007-04-26 Show GitHub Exploit DB Packet Storm
228264 7.5 危険 wf-links - XOOPS 用の WF-Links モジュールにおける SQL インジェクションの脆弱性 - CVE-2007-2373 2012-12-20 18:19 2005-06-22 Show GitHub Exploit DB Packet Storm
228265 9.3 危険 シマンテック - Windows 用の Symantec Storage Foundation における認証を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-2279 2012-12-20 18:19 2007-06-1 Show GitHub Exploit DB Packet Storm
228266 7.5 危険 Plogger Project - Plogger におけるセッションをハイジャックされる脆弱性 CWE-287
不適切な認証
CVE-2007-2277 2012-12-20 18:19 2007-04-25 Show GitHub Exploit DB Packet Storm
228267 9.4 危険 rajneel lal totaram - Rajneel Lal TotaRam USP FOSS におけるディレクトリトラバーサルの脆弱性 - CVE-2007-2271 2012-12-20 18:19 2007-04-25 Show GitHub Exploit DB Packet Storm
228268 5 警告 swsoft - Windows 用の SWsoft Plesk の top.php3 におけるディレクトリトラバーサルの脆弱性 - CVE-2007-2269 2012-12-20 18:19 2007-04-25 Show GitHub Exploit DB Packet Storm
228269 5 警告 swsoft - Windows 用の SWsoft Plesk におけるディレクトリトラバーサルの脆弱性 - CVE-2007-2268 2012-12-20 18:19 2007-04-25 Show GitHub Exploit DB Packet Storm
228270 6.8 警告 サン・マイクロシステムズ - Sun Cluster および Solaris Cluster におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2267 2012-12-20 18:19 2007-04-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 1, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
223311 8.1 HIGH
Network
ttlock ttlock TTLock devices do not properly restrict password-reset attempts, leading to incorrect access control and disclosure of sensitive information about valid account names. CWE-640
 Weak Password Recovery Mechanism for Forgotten Password
CVE-2019-12943 2024-11-21 13:23 2019-09-11 Show GitHub Exploit DB Packet Storm
223312 6.5 MEDIUM
Adjacent
ttlock ttlock TTLock devices do not properly block guest access in certain situations where the network connection to the cloud is unavailable. CWE-862
 Missing Authorization
CVE-2019-12942 2024-11-21 13:23 2019-09-11 Show GitHub Exploit DB Packet Storm
223313 5.3 MEDIUM
Network
mendix mendix In Mendix 7.23.5 and earlier, issue in XML import mappings allow DOCTYPE declarations in the XML input that is potentially unsafe. CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2019-12996 2024-11-21 13:23 2019-09-11 Show GitHub Exploit DB Packet Storm
223314 7.8 HIGH
Local
cisco jabber A vulnerability in Cisco Jabber Client Framework (JCF) for Mac Software, installed as part of the Cisco Jabber for Mac client, could allow an authenticated, local attacker to execute arbitrary code o… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2019-12645 2024-11-21 13:23 2019-09-5 Show GitHub Exploit DB Packet Storm
223315 6.1 MEDIUM
Network
cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack a… CWE-79
Cross-site Scripting
CVE-2019-12644 2024-11-21 13:23 2019-09-5 Show GitHub Exploit DB Packet Storm
223316 4.3 MEDIUM
Network
cisco content_security_management_appliance A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software could allow an authenticated, remote attacker to gain out-of-scope access to email. The vulne… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2019-12635 2024-11-21 13:23 2019-09-5 Show GitHub Exploit DB Packet Storm
223317 7.5 HIGH
Network
cisco unified_contact_center_express A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2019-12633 2024-11-21 13:23 2019-09-5 Show GitHub Exploit DB Packet Storm
223318 7.5 HIGH
Network
cisco finesse A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on an affected system. The vulnerabi… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2019-12632 2024-11-21 13:23 2019-09-5 Show GitHub Exploit DB Packet Storm
223319 6.5 MEDIUM
Adjacent
espressif esp-idf
arduino-esp32
esp8266_nonos_sdk
The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK 2.2.0 through 3.1.0 processes EAP Success messages before any EAP method completion or failure, which allows… NVD-CWE-noinfo
CVE-2019-12586 2024-11-21 13:23 2019-09-5 Show GitHub Exploit DB Packet Storm
223320 6.5 MEDIUM
Adjacent
espressif esp8266_nonos_sdk
arduino_esp8266
The client 802.11 mac implementation in Espressif ESP8266_NONOS_SDK 2.2.0 through 3.1.0 does not validate correctly the RSN AuthKey suite list count in beacon frames, probe responses, and association… CWE-20
 Improper Input Validation 
CVE-2019-12588 2024-11-21 13:23 2019-09-4 Show GitHub Exploit DB Packet Storm