Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228451 5 警告 sflog - sflog! におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0703 2012-12-20 18:34 2008-02-11 Show GitHub Exploit DB Packet Storm
228452 9.3 危険 south river technologies - Titan FTP Server におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-0702 2012-12-20 18:34 2008-02-11 Show GitHub Exploit DB Packet Storm
228453 7.8 危険 print manager plus - Print Manager Plus 2008 Client Billing and Authentication におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-0693 2012-12-20 18:34 2008-02-11 Show GitHub Exploit DB Packet Storm
228454 4.3 警告 simon elvery
WordPress.org
- WordPress 用の Simon Elvery WP-Footnotes プラグイにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0691 2012-12-20 18:34 2008-02-11 Show GitHub Exploit DB Packet Storm
228455 4.3 警告 smartscript - Smartscript Domain Trader の catalog.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0688 2012-12-20 18:34 2008-02-11 Show GitHub Exploit DB Packet Storm
228456 7.5 危険 youtube - Youtube Clone Script の siteadmin/editor_files/includes/load_message.php におけるクロスサイトスクリプティングの脆弱性 CWE-94
コード・インジェクション
CVE-2008-0687 2012-12-20 18:34 2008-02-11 Show GitHub Exploit DB Packet Storm
228457 7.5 危険 WordPress.org - WordPress 用の st_newsletter プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0683 2012-12-20 18:34 2008-02-11 Show GitHub Exploit DB Packet Storm
228458 7.5 危険 WordPress.org - WordPress 用の Wordspew プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0682 2012-12-20 18:34 2008-02-11 Show GitHub Exploit DB Packet Storm
228459 6.8 警告 phpshop - PHPShop の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0681 2012-12-20 18:34 2008-02-11 Show GitHub Exploit DB Packet Storm
228460 7.5 危険 the everything development company - The Everything Development System の The Everything Development Engine における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0675 2012-12-20 18:34 2008-02-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
221841 7.8 HIGH
Local
centrify authentication_service
privilege_elevation_service
The Windows component of Centrify Authentication and Privilege Elevation Services 3.4.0, 3.4.1, 3.4.2, 3.4.3, 3.5.0, 3.5.1 (18.8), 3.5.2 (18.11), and 3.6.0 (19.6) does not properly handle an unspecif… CWE-502
 Deserialization of Untrusted Data
CVE-2019-18631 2024-11-21 13:33 2019-11-6 Show GitHub Exploit DB Packet Storm
221842 9.8 CRITICAL
Network
isl arp-guard A SQL injection vulnerability in a /login/forgot1 POST request in ARP-GUARD 4.0.0-5 allows unauthenticated remote attackers to execute arbitrary SQL commands via the user_id parameter. CWE-89
SQL Injection
CVE-2019-18663 2024-11-21 13:33 2019-11-5 Show GitHub Exploit DB Packet Storm
221843 7.0 HIGH
Local
sudo_project sudo Sudo through 1.8.29 allows local users to escalate to root if they have write access to file descriptor 3 of the sudo process. This occurs because of a race condition between determining a uid, and t… CWE-362
Race Condition
CVE-2019-18684 2024-11-21 13:33 2019-11-5 Show GitHub Exploit DB Packet Storm
221844 7.0 HIGH
Local
linux
canonical
opensuse
netapp
broadcom
debian
linux_kernel
ubuntu_linux
leap
cloud_backup
element_software
steelstore_cloud_integrated_storage
data_availability_services
solidfire
hci_management_node
active_iq_unified_…
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 ac… CWE-362
CWE-416
Race Condition
 Use After Free
CVE-2019-18683 2024-11-21 13:33 2019-11-5 Show GitHub Exploit DB Packet Storm
221845 7.5 HIGH
Network
linux linux_kernel An issue was discovered in the Linux kernel 4.4.x before 4.4.195. There is a NULL pointer dereference in rds_tcp_kill_sock() in net/rds/tcp.c that will cause denial of service, aka CID-91573ae4aed0. CWE-476
 NULL Pointer Dereference
CVE-2019-18680 2024-11-21 13:33 2019-11-5 Show GitHub Exploit DB Packet Storm
221846 4.6 MEDIUM
Physics
shiftcrypto bitbox02 On SHIFT BitBox02 devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a parti… CWE-203
 Information Exposure Through Discrepancy
CVE-2019-18673 2024-11-21 13:33 2019-11-3 Show GitHub Exploit DB Packet Storm
221847 6.1 MEDIUM
Network
pfsense pfsense-pkg-freeradius3 /usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15.7_3 for pfSense on FreeBSD allows a user with an XSS payload as password or username to execute arbitrary javascript c… CWE-79
Cross-site Scripting
CVE-2019-18667 2024-11-21 13:33 2019-11-3 Show GitHub Exploit DB Packet Storm
221848 7.5 HIGH
Network
secudos domos The Log module in SECUDOS DOMOS before 5.6 allows local file inclusion. CWE-22
Path Traversal
CVE-2019-18665 2024-11-21 13:33 2019-11-3 Show GitHub Exploit DB Packet Storm
221849 5.4 MEDIUM
Network
secudos domos The Log module in SECUDOS DOMOS before 5.6 allows XSS. CWE-79
Cross-site Scripting
CVE-2019-18664 2024-11-21 13:33 2019-11-3 Show GitHub Exploit DB Packet Storm
221850 7.5 HIGH
Network
fastweb fastgate_firmware Fastweb FASTGate 1.0.1b devices allow partial authentication bypass by changing a certain check_pwd return value from 0 to 1. An attack does not achieve administrative control of a device; however, t… CWE-287
Improper Authentication
CVE-2019-18661 2024-11-21 13:33 2019-11-2 Show GitHub Exploit DB Packet Storm