Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228411 7.5 危険 PreProject.com - Pre Shopping Mall の detail.php における SQL インジェクションの脆弱性 - CVE-2007-2674 2012-12-20 18:19 2007-05-14 Show GitHub Exploit DB Packet Storm
228412 7.5 危険 thinc4orce marketing group - PHP Coupon Script の index.php における SQL インジェクションの脆弱性 - CVE-2007-2672 2012-12-20 18:19 2007-05-14 Show GitHub Exploit DB Packet Storm
228413 6.8 警告 webdesproxy - webdesproxy におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-2668 2012-12-20 18:19 2007-05-14 Show GitHub Exploit DB Packet Storm
228414 7.5 危険 tomasz rekawek - Yaap の includes/common.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2664 2012-12-20 18:19 2007-05-14 Show GitHub Exploit DB Packet Storm
228415 7.8 危険 precisionid barcode - PrecisionID_DataMatrix.DLL の PrecisionID Barcode ActiveX コントロールにおけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2657 2012-12-20 18:19 2007-05-14 Show GitHub Exploit DB Packet Storm
228416 4.4 警告 SUSE
xfsdump
- xfsdump の xfs_fsr における xfs ファイルシステム上で任意のファイルを上書きされる脆弱性 CWE-362
CWE-Other
CVE-2007-2654 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
228417 7.5 危険 voodoo circle - VooDoo cIRCle におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2651 2012-12-20 18:19 2007-05-14 Show GitHub Exploit DB Packet Storm
228418 7.8 危険 t-com - T-com Speedport W 700v における遅延を回避される脆弱性 - CVE-2007-2649 2012-12-20 18:19 2007-05-14 Show GitHub Exploit DB Packet Storm
228419 6.8 警告 yenc32 - yEnc32 におけるヒープベースのバッファオーバーフローの脆弱性 - CVE-2007-2646 2012-12-20 18:19 2007-05-14 Show GitHub Exploit DB Packet Storm
228420 5 警告 pinkcrow designs - PinkCrow Designs Gallery または maGAZIn の phpThumb.php におけるディレクトリトラバーサルの脆弱性 - CVE-2007-2643 2012-12-20 18:19 2007-05-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
222451 7.8 HIGH
Local
verifone mx900_firmware Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow multiple arbitrary command injections, as demonstrated by the file manager. CWE-77
Command Injection
CVE-2019-14719 2024-11-21 13:27 2020-10-23 Show GitHub Exploit DB Packet Storm
222452 6.7 MEDIUM
Local
verifone mx900_firmware Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have Insecure Permissions, with resultant svc_netcontrol arbitrary command injection and privilege escalation. CWE-276
Incorrect Default Permissions 
CVE-2019-14718 2024-11-21 13:27 2020-10-23 Show GitHub Exploit DB Packet Storm
222453 7.8 HIGH
Local
verifone verix_os Verifone Verix OS on VerixV Pinpad Payment Terminals with QT000530 have a Buffer Overflow via the Run system call. CWE-120
Classic Buffer Overflow
CVE-2019-14717 2024-11-21 13:27 2020-10-23 Show GitHub Exploit DB Packet Storm
222454 6.6 MEDIUM
Physics
verifone verix_os Verifone VerixV Pinpad Payment Terminals with QT000530 have an undocumented physical access mode (aka VerixV shell.out). NVD-CWE-noinfo
CVE-2019-14716 2024-11-21 13:27 2020-10-23 Show GitHub Exploit DB Packet Storm
222455 6.8 MEDIUM
Physics
verifone p400_firmware
p200_firmware
vx_820_firmware
vx_805_firmware
Verifone Pinpad Payment Terminals allow undocumented physical access to the system via an SBI bootloader memory write operation. CWE-787
 Out-of-bounds Write
CVE-2019-14715 2024-11-21 13:27 2020-10-23 Show GitHub Exploit DB Packet Storm
222456 5.5 MEDIUM
Local
verifone mx900_firmware Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow installation of unsigned packages. NVD-CWE-noinfo
CVE-2019-14713 2024-11-21 13:27 2020-10-23 Show GitHub Exploit DB Packet Storm
222457 7.8 HIGH
Local
verifone verix_os Verifone VerixV Pinpad Payment Terminals with QT000530 allow bypass of integrity and origin control for S1G file generation. NVD-CWE-noinfo
CVE-2019-14712 2024-11-21 13:27 2020-10-23 Show GitHub Exploit DB Packet Storm
222458 7.0 HIGH
Local
verifone mx900_firmware Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have a race condition for RBAC bypass. CWE-362
Race Condition
CVE-2019-14711 2024-11-21 13:27 2020-10-23 Show GitHub Exploit DB Packet Storm
222459 4.4 MEDIUM
Local
kaiostech kaios An issue was discovered in KaiOS 2.5. The pre-installed Note application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Note application. … CWE-79
Cross-site Scripting
CVE-2019-14761 2024-11-21 13:27 2020-09-15 Show GitHub Exploit DB Packet Storm
222460 4.4 MEDIUM
Local
kaiostech kaios An issue was discovered in KaiOS 2.5. The pre-installed Recorder application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Recorder appli… CWE-79
Cross-site Scripting
CVE-2019-14760 2024-11-21 13:27 2020-09-15 Show GitHub Exploit DB Packet Storm