Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228421 7.5 危険 PHPNUKE - PHP-Nuke 用の EasyContent モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0880 2012-12-20 18:34 2008-02-21 Show GitHub Exploit DB Packet Storm
228422 7.5 危険 PHPNUKE - PHP-Nuke 用の Web_Links モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0879 2012-12-20 18:34 2008-02-21 Show GitHub Exploit DB Packet Storm
228423 7.5 危険 runcms - RunCMS 用の MyAnnonces モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0878 2012-12-20 18:34 2008-02-21 Show GitHub Exploit DB Packet Storm
228424 4.3 警告 SmarterTools Inc. - SmarterTools SmarterMail Enterprise におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0872 2012-12-20 18:34 2008-02-21 Show GitHub Exploit DB Packet Storm
228425 7.5 危険 woltlab - WoltLab Burning Board の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0857 2012-12-20 18:34 2008-02-20 Show GitHub Exploit DB Packet Storm
228426 7.5 危険 WordPress.org - WordPress 用の Dean Logan WP-People プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0845 2012-12-20 18:34 2008-02-20 Show GitHub Exploit DB Packet Storm
228427 6.4 警告 statcountex - StatCounteX における重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-0843 2012-12-20 18:34 2008-02-20 Show GitHub Exploit DB Packet Storm
228428 4.4 警告 publicwarehouse - Public Warehouse LightBlog の view_member.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0840 2012-12-20 18:34 2008-02-20 Show GitHub Exploit DB Packet Storm
228429 4.3 警告 ソフォス - Sophos ES1000 および ES4000 Email Security Appliance の Web の管理インターフェースにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0838 2012-12-20 18:34 2008-02-20 Show GitHub Exploit DB Packet Storm
228430 7.5 危険 simple cms - Simple CMS の indexen.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0835 2012-12-20 18:34 2008-02-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
221871 7.2 HIGH
Network
netapp ontap_select_deploy_administration_utility All versions of ONTAP Select Deploy administration utility are susceptible to a vulnerability which when successfully exploited could allow an administrative user to escalate their privileges. NVD-CWE-noinfo
CVE-2019-17272 2024-11-21 13:32 2019-11-22 Show GitHub Exploit DB Packet Storm
221872 7.8 HIGH
Local
zohocorp manageengine_firewall_analyzer
manageengine_opmanager
Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting… CWE-276
Incorrect Default Permissions 
CVE-2019-17421 2024-11-21 13:32 2019-11-22 Show GitHub Exploit DB Packet Storm
221873 7.8 HIGH
Local
comodo comodo_internet_security An issue was discovered in signmgr.dll 6.5.0.819 in Comodo Internet Security through 12.0. A DLL Preloading vulnerability allows an attacker to implant an unsigned DLL named iLog.dll in a partially u… CWE-427
 Uncontrolled Search Path Element
CVE-2019-18215 2024-11-21 13:32 2019-11-19 Show GitHub Exploit DB Packet Storm
221874 4.6 MEDIUM
Physics
espressif esp32-d0wd_firmware
esp32-d2wd_firmware
esp32-s0wd_firmware
esp32-pico-d4_firmware
An issue was discovered in the Espressif ESP32 mask ROM code 2016-06-08 0 through 2. Lack of anti-glitch mitigations in the first stage bootloader of the ESP32 chip allows an attacker (with physical … CWE-755
 Improper Handling of Exceptional Conditions
CVE-2019-17391 2024-11-21 13:32 2019-11-15 Show GitHub Exploit DB Packet Storm
221875 9.8 CRITICAL
Network
fujielectric v-server In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an attacker to remotely execute arbitrary code. CWE-787
 Out-of-bounds Write
CVE-2019-18240 2024-11-21 13:32 2019-11-14 Show GitHub Exploit DB Packet Storm
221876 6.1 MEDIUM
Network
adenion blog2social The Blog2Social plugin before 5.9.0 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the b2s_id parameter.… CWE-79
Cross-site Scripting
CVE-2019-17550 2024-11-21 13:32 2019-11-14 Show GitHub Exploit DB Packet Storm
221877 6.1 MEDIUM
Network
cleantalk spam_protection\
_antispam\
_firewall
The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code vi… CWE-79
Cross-site Scripting
CVE-2019-17515 2024-11-21 13:32 2019-11-14 Show GitHub Exploit DB Packet Storm
221878 8.8 HIGH
Network
phoenix securecore_technology In Phoenix SCT WinFlash 1.1.12.0 through 1.5.74.0, the included drivers could be used by a malicious Windows application to gain elevated privileges. Adverse impacts are limited to the Windows enviro… NVD-CWE-noinfo
CVE-2019-18279 2024-11-21 13:32 2019-11-14 Show GitHub Exploit DB Packet Storm
221879 5.4 MEDIUM
Network
technicolor tc7300.b0_firmware An XSS vulnerability on Technicolor TC7300 STFA.51.20 devices allows remote attackers to inject arbitrary web script via the "Connected Clients" field to /wlanAccess.asp. An intranet host can use a c… CWE-79
Cross-site Scripting
CVE-2019-17524 2024-11-21 13:32 2019-11-14 Show GitHub Exploit DB Packet Storm
221880 5.4 MEDIUM
Network
technicolor tc7300.b0_firmware An XSS vulnerability on Technicolor TC7300 STFA.51.20 devices allows remote attackers to inject arbitrary web script via the FileName parameter to /FTPDiag.asp. CWE-79
Cross-site Scripting
CVE-2019-17523 2024-11-21 13:32 2019-11-14 Show GitHub Exploit DB Packet Storm