Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 24, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228441 7.5 危険 tombstone - txtSQL 用の smNews example スクリプトにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0750 2012-12-20 19:10 2009-03-2 Show GitHub Exploit DB Packet Storm
228442 4.3 警告 Pebble - Pebble におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-0736 2012-12-20 19:10 2009-02-25 Show GitHub Exploit DB Packet Storm
228443 7.5 危険 tony iha kazungu - taifajobs の jobdetails.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0727 2012-12-20 19:10 2009-02-24 Show GitHub Exploit DB Packet Storm
228444 7.5 危険 potato-scripts - Potato News の admin.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-0722 2012-12-20 19:10 2009-02-24 Show GitHub Exploit DB Packet Storm
228445 5 警告 vlad alexa mancini - PHPFootball の filter.php におけるパスワードハッシュを取得される脆弱性 CWE-200
情報漏えい
CVE-2009-0711 2012-12-20 19:10 2009-02-23 Show GitHub Exploit DB Packet Storm
228446 4.3 警告 vlad alexa mancini - PHPFootball におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-0710 2012-12-20 19:10 2009-02-23 Show GitHub Exploit DB Packet Storm
228447 7.5 危険 vlad alexa mancini - PHPFootball の login.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0709 2012-12-20 19:10 2009-02-23 Show GitHub Exploit DB Packet Storm
228448 6.8 警告 SemanticScuttle - SemanticScuttle におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2009-0708 2012-12-20 19:10 2009-02-23 Show GitHub Exploit DB Packet Storm
228449 7.5 危険 powerscripts - PowerClan の admin/index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0707 2012-12-20 19:10 2009-02-23 Show GitHub Exploit DB Packet Storm
228450 7.5 危険 simple-review - Joomla! および Mambo 用の simple_review コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0706 2012-12-20 19:10 2009-02-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 24, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
225531 6.1 MEDIUM
Network
liferay liferay_portal Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib. CWE-79
Cross-site Scripting
CVE-2019-16147 2024-11-21 13:30 2019-09-10 Show GitHub Exploit DB Packet Storm
225532 6.1 MEDIUM
Network
padrinorb padrino-contrib The breadcrumbs contributed module through 0.2.0 for Padrino Framework allows XSS via a caption. CWE-79
Cross-site Scripting
CVE-2019-16145 2024-11-21 13:30 2019-09-10 Show GitHub Exploit DB Packet Storm
225533 9.8 CRITICAL
Network
dlink dir-868l_firmware
dir-885l_firmware
dir-895l_firmware
SharePort Web Access on D-Link DIR-868L REVB through 2.03, DIR-885L REVA through 1.20, and DIR-895L REVA through 1.21 devices allows Authentication Bypass, as demonstrated by a direct request to fold… CWE-287
Improper Authentication
CVE-2019-16190 2024-11-21 13:30 2019-09-10 Show GitHub Exploit DB Packet Storm
225534 5.4 MEDIUM
Network
limesurvey limesurvey LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php, CWE-79
Cross-site Scripting
CVE-2019-16173 2024-11-21 13:30 2019-09-10 Show GitHub Exploit DB Packet Storm
225535 5.4 MEDIUM
Network
limesurvey limesurvey LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript… CWE-79
Cross-site Scripting
CVE-2019-16172 2024-11-21 13:30 2019-09-10 Show GitHub Exploit DB Packet Storm
225536 5.5 MEDIUM
Local
sysstat_project
fedoraproject
opensuse
canonical
debian
sysstat
fedora
leap
ubuntu_linux
debian_linux
sysstat before 12.1.6 has memory corruption due to an Integer Overflow in remap_struct() in sa_common.c. CWE-787
CWE-190
 Out-of-bounds Write
 Integer Overflow or Wraparound
CVE-2019-16167 2024-11-21 13:30 2019-09-10 Show GitHub Exploit DB Packet Storm
225537 6.5 MEDIUM
Network
gnu cflow GNU cflow through 1.6 has a heap-based buffer over-read in the nexttoken function in parser.c. CWE-125
Out-of-bounds Read
CVE-2019-16166 2024-11-21 13:30 2019-09-10 Show GitHub Exploit DB Packet Storm
225538 6.5 MEDIUM
Network
gnu cflow GNU cflow through 1.6 has a use-after-free in the reference function in parser.c. CWE-416
 Use After Free
CVE-2019-16165 2024-11-21 13:30 2019-09-10 Show GitHub Exploit DB Packet Storm
225539 6.5 MEDIUM
Network
myhtml_project myhtml MyHTML through 4.0.5 has a NULL pointer dereference in myhtml_tree_node_remove in tree.c. CWE-476
 NULL Pointer Dereference
CVE-2019-16164 2024-11-21 13:30 2019-09-10 Show GitHub Exploit DB Packet Storm
225540 7.5 HIGH
Network
oniguruma_project
fedoraproject
debian
canonical
oniguruma
fedora
debian_linux
ubuntu_linux
Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c. CWE-674
 Uncontrolled Recursion
CVE-2019-16163 2024-11-21 13:30 2019-09-10 Show GitHub Exploit DB Packet Storm