Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 5, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228471 7.5 危険 postnuke software foundation - PostNuke 用の v4bJournal モジュールにおける SQL インジェクションの脆弱性 - CVE-2007-2492 2012-12-20 18:19 2007-05-3 Show GitHub Exploit DB Packet Storm
228472 7.2 危険 VMware - EMC VMware Workstation などの PIIX4 電源管理サブシステムにおける任意のメモリ領域に書き込まれる脆弱性 - CVE-2007-2491 2012-12-20 18:19 2007-05-3 Show GitHub Exploit DB Packet Storm
228473 7.5 危険 ruben boelinger - WordPress 用の myflash プラグインにおける PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2485 2012-12-20 18:19 2007-05-3 Show GitHub Exploit DB Packet Storm
228474 6.8 警告 ruben boelinger - WordPress 用の wp-Table プラグインにおける PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2484 2012-12-20 18:19 2007-05-3 Show GitHub Exploit DB Packet Storm
228475 6.8 警告 ruben boelinger - WordPress 用の wp-Table プラグインにおけるディレクトリトラバーサルの脆弱性 - CVE-2007-2483 2012-12-20 18:19 2007-05-3 Show GitHub Exploit DB Packet Storm
228476 6.8 警告 ruben boelinger - WordPress 用の wordTube プラグインにおけるディレクトリトラバーサルの脆弱性 - CVE-2007-2482 2012-12-20 18:19 2007-05-3 Show GitHub Exploit DB Packet Storm
228477 6.8 警告 ruben boelinger - WordPress 用の wordTube プラグインの wordtube-button.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2481 2012-12-20 18:19 2007-05-3 Show GitHub Exploit DB Packet Storm
228478 7.5 危険 turnkey web tools - Turnkey Web Tools SunShop Shopping Cart における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2474 2012-12-20 18:19 2007-05-2 Show GitHub Exploit DB Packet Storm
228479 4.3 警告 sendcard - Sendcard の sendcard.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-2472 2012-12-20 18:19 2007-05-2 Show GitHub Exploit DB Packet Storm
228480 5 警告 sendcard - Sendcard の sendcard.php におけるディレクトリトラバーサルの脆弱性 - CVE-2007-2471 2012-12-20 18:19 2007-05-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 5, 2026, 4:51 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
223901 8.1 HIGH
Network
ttlock ttlock TTLock devices do not properly restrict password-reset attempts, leading to incorrect access control and disclosure of sensitive information about valid account names. CWE-640
 Weak Password Recovery Mechanism for Forgotten Password
CVE-2019-12943 2024-11-21 13:23 2019-09-11 Show GitHub Exploit DB Packet Storm
223902 6.5 MEDIUM
Adjacent
ttlock ttlock TTLock devices do not properly block guest access in certain situations where the network connection to the cloud is unavailable. CWE-862
 Missing Authorization
CVE-2019-12942 2024-11-21 13:23 2019-09-11 Show GitHub Exploit DB Packet Storm
223903 5.3 MEDIUM
Network
mendix mendix In Mendix 7.23.5 and earlier, issue in XML import mappings allow DOCTYPE declarations in the XML input that is potentially unsafe. CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2019-12996 2024-11-21 13:23 2019-09-11 Show GitHub Exploit DB Packet Storm
223904 7.8 HIGH
Local
cisco jabber A vulnerability in Cisco Jabber Client Framework (JCF) for Mac Software, installed as part of the Cisco Jabber for Mac client, could allow an authenticated, local attacker to execute arbitrary code o… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2019-12645 2024-11-21 13:23 2019-09-5 Show GitHub Exploit DB Packet Storm
223905 6.1 MEDIUM
Network
cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack a… CWE-79
Cross-site Scripting
CVE-2019-12644 2024-11-21 13:23 2019-09-5 Show GitHub Exploit DB Packet Storm
223906 4.3 MEDIUM
Network
cisco content_security_management_appliance A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software could allow an authenticated, remote attacker to gain out-of-scope access to email. The vulne… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2019-12635 2024-11-21 13:23 2019-09-5 Show GitHub Exploit DB Packet Storm
223907 7.5 HIGH
Network
cisco unified_contact_center_express A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2019-12633 2024-11-21 13:23 2019-09-5 Show GitHub Exploit DB Packet Storm
223908 7.5 HIGH
Network
cisco finesse A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on an affected system. The vulnerabi… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2019-12632 2024-11-21 13:23 2019-09-5 Show GitHub Exploit DB Packet Storm
223909 6.5 MEDIUM
Adjacent
espressif esp-idf
arduino-esp32
esp8266_nonos_sdk
The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK 2.2.0 through 3.1.0 processes EAP Success messages before any EAP method completion or failure, which allows… NVD-CWE-noinfo
CVE-2019-12586 2024-11-21 13:23 2019-09-5 Show GitHub Exploit DB Packet Storm
223910 6.5 MEDIUM
Adjacent
espressif esp8266_nonos_sdk
arduino_esp8266
The client 802.11 mac implementation in Espressif ESP8266_NONOS_SDK 2.2.0 through 3.1.0 does not validate correctly the RSN AuthKey suite list count in beacon frames, probe responses, and association… CWE-20
 Improper Input Validation 
CVE-2019-12588 2024-11-21 13:23 2019-09-4 Show GitHub Exploit DB Packet Storm