Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 1, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228371 9.3 危険 phpPgAdmin - phpPgAdmin の sqledit.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-2865 2012-12-20 18:19 2007-05-25 Show GitHub Exploit DB Packet Storm
228372 7.5 危険 saxon - SAXON における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2861 2012-12-20 18:19 2007-05-24 Show GitHub Exploit DB Packet Storm
228373 7.5 危険 simpgb - SimpGB における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2859 2012-12-20 18:19 2007-05-24 Show GitHub Exploit DB Packet Storm
228374 6.5 警告 phpBB - phpBB 用の IP-Tracking Mod における SQL インジェクションの脆弱性 - CVE-2007-2858 2012-12-20 18:19 2007-05-24 Show GitHub Exploit DB Packet Storm
228375 7.5 危険 zakkis technology corporation - ABC Excel Parser の sample/xls2mysql における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2857 2012-12-20 18:19 2007-05-24 Show GitHub Exploit DB Packet Storm
228376 10 危険 sky software - Sky Software Shell MegaPack ActiveX の shComboBox ActiveX コントロールにおけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-2848 2012-12-20 18:19 2007-05-24 Show GitHub Exploit DB Packet Storm
228377 6.8 警告 unicon-imc2 - unicon-imc2 の ImmModules/cce/ におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-2835 2012-12-20 18:19 2007-07-1 Show GitHub Exploit DB Packet Storm
228378 9.3 危険 wavelink media - TutorialCMS における認証を回避される脆弱性 - CVE-2007-2822 2012-12-20 18:19 2007-05-22 Show GitHub Exploit DB Packet Storm
228379 7.5 危険 WordPress.org - WordPress の wp-admin/admin-ajax.php における SQL インジェクションの脆弱性 - CVE-2007-2821 2012-12-20 18:19 2007-05-22 Show GitHub Exploit DB Packet Storm
228380 4.3 警告 track+ - Track+ の reportItem.do におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-2819 2012-12-20 18:19 2007-05-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 2, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
223321 8.8 HIGH
Network
fortinet fcm-mb40_firmware /usr/sbin/default.sh and /usr/apache/htdocs/cgi-bin/admin/hardfactorydefault.cgi on Dynacolor FCM-MB40 v1.2.0.0 devices implement an incomplete factory-reset process. A backdoor can persist because n… CWE-212
 Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2019-13402 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
223322 8.8 HIGH
Network
fortinet fcm-mb40_firmware Dynacolor FCM-MB40 v1.2.0.0 devices have CSRF in all scripts under cgi-bin/. CWE-352
 Origin Validation Error
CVE-2019-13401 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
223323 9.8 CRITICAL
Network
fortinet fcm-mb40_firmware Dynacolor FCM-MB40 v1.2.0.0 use /etc/appWeb/appweb.pass to store administrative web-interface credentials in cleartext. These credentials can be retrieved via cgi-bin/getuserinfo.cgi?mode=info. CWE-522
 Insufficiently Protected Credentials
CVE-2019-13400 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
223324 5.9 MEDIUM
Network
fortinet fcm-mb40_firmware Dynacolor FCM-MB40 v1.2.0.0 devices have a hard-coded SSL/TLS key that is used during an administrator's SSL conversation. CWE-798
 Use of Hard-coded Credentials
CVE-2019-13399 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
223325 7.2 HIGH
Network
fortinet fcm-mb40_firmware Dynacolor FCM-MB40 v1.2.0.0 devices allow remote attackers to execute arbitrary commands via a crafted parameter to a CGI script, as demonstrated by sed injection in cgi-bin/camctrl_save_profile.cgi … CWE-78
OS Command 
CVE-2019-13398 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
223326 8.8 HIGH
Network
imagemagick imagemagick In ImageMagick 7.0.8-50 Q16, ComplexImages in MagickCore/fourier.c has a heap-based buffer over-read because of incorrect calls to GetCacheViewVirtualPixels. CWE-125
Out-of-bounds Read
CVE-2019-13391 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
223327 6.5 MEDIUM
Network
ffmpeg ffmpeg In FFmpeg 4.1.3, there is a division by zero at adx_write_trailer in libavformat/rawenc.c. CWE-369
 Divide By Zero
CVE-2019-13390 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
223328 8.8 HIGH
Network
avtech room_alert_3e_firmware On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?actio… CWE-668
 Exposure of Resource to Wrong Sphere
CVE-2019-13379 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
223329 8.8 HIGH
Network
flarum flarum Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings. CWE-352
 Origin Validation Error
CVE-2019-13183 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
223330 9.8 CRITICAL
Network
dlink central_wifimanager A SQL Injection was discovered in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 in PayAction.class.php with the index.php/Pay/passcodeAuth parameter passcode. The vulnerability does no… CWE-89
SQL Injection
CVE-2019-13375 2024-11-21 13:24 2019-07-7 Show GitHub Exploit DB Packet Storm