Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 2, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228441 7.5 危険 XOOPS - XOOPS 用の wfquotes モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-2571 2012-12-20 18:19 2007-05-9 Show GitHub Exploit DB Packet Storm
228442 7.5 危険 practical creative and code - Friendly における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2569 2012-12-20 18:19 2007-05-9 Show GitHub Exploit DB Packet Storm
228443 9.3 危険 vcdgear - VCDGear におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-2568 2012-12-20 18:19 2007-05-16 Show GitHub Exploit DB Packet Storm
228444 9.3 危険 taltech - Taltech Tal Bar Code ActiveX コントロールの SaveBarCode 関数におけるバッファオーバーフローの脆弱性 - CVE-2007-2567 2012-12-20 18:19 2007-05-9 Show GitHub Exploit DB Packet Storm
228445 5 警告 taltech - Taltech Tal Bar Code ActiveX コントロールの SaveBarCode 関数におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2566 2012-12-20 18:19 2007-05-9 Show GitHub Exploit DB Packet Storm
228446 10 危険 sienzo - Sienzo DMM ActiveX コントロール におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-2564 2012-12-20 18:19 2007-05-9 Show GitHub Exploit DB Packet Storm
228447 9.3 危険 versalsoft - VersalSoft HTTP File Upload ActiveX コントロール の AddFile 関数におけるバッファオーバーフローの脆弱性 - CVE-2007-2563 2012-12-20 18:19 2007-05-9 Show GitHub Exploit DB Packet Storm
228448 4.3 警告 podium cms - Podium CMS の Default.aspx におけるセッションをハイジャックされる脆弱性 CWE-287
不適切な認証
CVE-2007-2555 2012-12-20 18:19 2007-05-9 Show GitHub Exploit DB Packet Storm
228449 5 警告 Wikka Development Team - WikkaWiki の RecentChanges 機能における非公開ページの名前などを取得される脆弱性 CWE-200
情報漏えい
CVE-2007-2552 2012-12-20 18:19 2007-05-9 Show GitHub Exploit DB Packet Storm
228450 4.3 警告 Wikka Development Team - WikkaWiki の usersettings.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-2551 2012-12-20 18:19 2007-05-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 2, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
223221 6.1 MEDIUM
Network
xymon
debian
xymon
debian_linux
In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter. CWE-79
Cross-site Scripting
CVE-2019-13274 2024-11-21 13:24 2019-08-28 Show GitHub Exploit DB Packet Storm
223222 9.8 CRITICAL
Network
xymon
debian
xymon
debian_linux
In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited by sending a crafted GET request that triggers an sprintf of the srcdb paramet… CWE-787
 Out-of-bounds Write
CVE-2019-13273 2024-11-21 13:24 2019-08-28 Show GitHub Exploit DB Packet Storm
223223 8.8 HIGH
Adjacent
edimax br-6208ac_v1_firmware Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, which are sent as bro… NVD-CWE-noinfo
CVE-2019-13271 2024-11-21 13:24 2019-08-28 Show GitHub Exploit DB Packet Storm
223224 4.3 MEDIUM
Network
alkacon opencms_apollo_template In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.js… CWE-22
Path Traversal
CVE-2019-13237 2024-11-21 13:24 2019-08-27 Show GitHub Exploit DB Packet Storm
223225 6.1 MEDIUM
Network
alkacon opencms In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the management interface. CWE-79
Cross-site Scripting
CVE-2019-13236 2024-11-21 13:24 2019-08-27 Show GitHub Exploit DB Packet Storm
223226 6.1 MEDIUM
Network
alkacon opencms_apollo_template In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form. CWE-79
Cross-site Scripting
CVE-2019-13235 2024-11-21 13:24 2019-08-27 Show GitHub Exploit DB Packet Storm
223227 6.1 MEDIUM
Network
alkacon opencms_apollo_template In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine. CWE-79
Cross-site Scripting
CVE-2019-13234 2024-11-21 13:24 2019-08-27 Show GitHub Exploit DB Packet Storm
223228 10.0 CRITICAL
Network
trms tightrope_media_carousel The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas for abuse. First, a specially crafted URL could be used in a phishing attack to… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2019-13020 2024-11-21 13:24 2019-08-27 Show GitHub Exploit DB Packet Storm
223229 5.5 MEDIUM
Local
obdev little_snitch Little Snitch versions 4.4.0 fixes a vulnerability in a privileged helper tool. However, the operating system may have made a copy of the privileged helper which is not removed or updated immediately… CWE-459
 Incomplete Cleanup
CVE-2019-13014 2024-11-21 13:24 2019-08-24 Show GitHub Exploit DB Packet Storm
223230 5.5 MEDIUM
Local
obdev little_snitch Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. The privileged helper tool implements an XPC interface which is available to any… CWE-862
 Missing Authorization
CVE-2019-13013 2024-11-21 13:24 2019-08-24 Show GitHub Exploit DB Packet Storm