Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 9, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228381 6.8 警告 swsoft - SWSoft Confixx Professional の fehler.inc.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-6042 2012-12-20 18:33 2007-11-20 Show GitHub Exploit DB Packet Storm
228382 7.5 危険 rigs of rogs - RoR のサーバの sequencer.cpp におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-6041 2012-12-20 18:33 2007-11-20 Show GitHub Exploit DB Packet Storm
228383 9 危険 Wonderware - Invensys Wonderware InTouch における任意のプログラムを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-6033 2012-12-20 18:33 2007-11-19 Show GitHub Exploit DB Packet Storm
228384 7.8 危険 van dyke technologies - VanDyke VShell におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2007-6031 2012-12-20 18:33 2007-11-19 Show GitHub Exploit DB Packet Storm
228385 10 危険 weird solutions - Weird Solutions BOOTPTurbo における脆弱性 CWE-noinfo
情報不足
CVE-2007-6030 2012-12-20 18:33 2007-11-19 Show GitHub Exploit DB Packet Storm
228386 7.1 危険 w1.fi - wpa_supplicant の driver_wext.c におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-6025 2012-12-20 18:33 2007-11-19 Show GitHub Exploit DB Packet Storm
228387 6.8 警告 WordPress.org - Wordpress における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2007-6013 2012-12-20 18:33 2007-11-19 Show GitHub Exploit DB Packet Storm
228388 7.8 危険 pioneers - pioneers におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2007-6010 2012-12-20 18:33 2007-11-15 Show GitHub Exploit DB Packet Storm
228389 10 危険 TestLink Development Team - TestLink における脆弱性 CWE-287
不適切な認証
CVE-2007-6006 2012-12-20 18:33 2007-11-15 Show GitHub Exploit DB Packet Storm
228390 4.3 警告 webex communications - WebEx の GpcContainer.GpcContainer.1 ActiveX コントロールにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2007-6005 2012-12-20 18:33 2007-11-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 9, 2026, 5:07 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
222081 6.1 MEDIUM
Network
fusionpbx fusionpbx In FusionPBX up to 4.5.7, the file app\contacts\contact_addresses.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS. CWE-79
Cross-site Scripting
CVE-2019-16972 2024-11-21 13:31 2019-10-23 Show GitHub Exploit DB Packet Storm
222082 6.1 MEDIUM
Network
fusionpbx fusionpbx In FusionPBX up to 4.5.7, the file app\messages\messages_thread.php uses an unsanitized "contact_uuid" variable coming from the URL, which is reflected on 3 occasions in HTML, leading to XSS. CWE-79
Cross-site Scripting
CVE-2019-16971 2024-11-21 13:31 2019-10-23 Show GitHub Exploit DB Packet Storm
222083 5.4 MEDIUM
Network
totemo totemodata totemodata 3.0.0_b936 has XSS via a folder name. CWE-79
Cross-site Scripting
CVE-2019-17189 2024-11-21 13:31 2019-10-23 Show GitHub Exploit DB Packet Storm
222084 6.1 MEDIUM
Network
rocket.chat rocket.chat Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line. CWE-79
Cross-site Scripting
CVE-2019-17220 2024-11-21 13:31 2019-10-22 Show GitHub Exploit DB Packet Storm
222085 6.1 MEDIUM
Network
fusionpbx fusionpbx In FusionPBX up to 4.5.7, the file app\contacts\contact_times.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS. CWE-79
Cross-site Scripting
CVE-2019-16974 2024-11-21 13:31 2019-10-22 Show GitHub Exploit DB Packet Storm
222086 6.1 MEDIUM
Network
fusionpbx fusionpbx In FusionPBX up to 4.5.7, the file app\fifo_list\fifo_interactive.php uses an unsanitized "c" variable coming from the URL, which is reflected in HTML, leading to XSS. CWE-79
Cross-site Scripting
CVE-2019-16969 2024-11-21 13:31 2019-10-22 Show GitHub Exploit DB Packet Storm
222087 6.1 MEDIUM
Network
fusionpbx fusionpbx In FusionPBX up to 4.5.7, the file app\sip_status\sip_status.php uses an unsanitized "savemsg" variable coming from the URL, which is reflected in HTML, leading to XSS. CWE-79
Cross-site Scripting
CVE-2019-16970 2024-11-21 13:31 2019-10-22 Show GitHub Exploit DB Packet Storm
222088 6.1 MEDIUM
Network
fusionpbx fusionpbx An issue was discovered in FusionPBX up to 4.5.7. In the file app\conference_controls\conference_control_details.php, an unsanitized id variable coming from the URL is reflected in HTML on 2 occasion… CWE-79
Cross-site Scripting
CVE-2019-16968 2024-11-21 13:31 2019-10-22 Show GitHub Exploit DB Packet Storm
222089 6.1 MEDIUM
Network
freepbx
sangoma
manager
freepbx
An issue was discovered in Manager 13.x before 13.0.2.6 and 15.x before 15.0.6 before FreePBX 14.0.10.3. In the Manager module form (html\admin\modules\manager\views\form.php), an unsanitized manager… CWE-79
Cross-site Scripting
CVE-2019-16967 2024-11-21 13:31 2019-10-22 Show GitHub Exploit DB Packet Storm
222090 6.1 MEDIUM
Network
freepbx
sangoma
contactmanager
freepbx
An issue was discovered in Contactmanager 13.x before 13.0.45.3, 14.x before 14.0.5.12, and 15.x before 15.0.8.21 for FreePBX 14.0.10.3. In the Contactmanager class (html\admin\modules\contactmanager… CWE-79
Cross-site Scripting
CVE-2019-16966 2024-11-21 13:31 2019-10-22 Show GitHub Exploit DB Packet Storm