Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 2, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228481 4.9 警告 zonelabs - ZoneAlarm におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2467 2012-12-20 18:19 2007-05-2 Show GitHub Exploit DB Packet Storm
228482 7.8 危険 サン・マイクロシステムズ - Sun Java System Directory Server および Sun ONE Directory Server で使用されている C 用の LDAP SDK におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2466 2012-12-20 18:19 2007-05-1 Show GitHub Exploit DB Packet Storm
228483 7.8 危険 tony cook - Imager perl モジュールの BMP リーダにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-2459 2012-12-20 18:19 2007-05-2 Show GitHub Exploit DB Packet Storm
228484 7.5 危険 pixaria - Pixaria Gallery における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-2458 2012-12-20 18:19 2007-04-15 Show GitHub Exploit DB Packet Storm
228485 7.5 危険 pixaria - Pixaria Gallery の resources/includes/class.Smarty.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2457 2012-12-20 18:19 2007-04-15 Show GitHub Exploit DB Packet Storm
228486 2.1 注意 CollabNet, Inc. - Subversion における重要な情報 (プロパティの改定) を取得される脆弱性 - CVE-2007-2448 2012-12-20 18:19 2007-06-14 Show GitHub Exploit DB Packet Storm
228487 6.8 警告 tecnick.com - TCExam の shared/config/tce_config.php におけるクロスサイトスクリプティング攻撃 (XSS) を実行される脆弱性 - CVE-2007-2431 2012-12-20 18:19 2007-05-1 Show GitHub Exploit DB Packet Storm
228488 7.8 危険 tecnick.com - TCExam の shared/code/tce_tmx.php における cache/ 配下の任意の PHP ファイルを作成される脆弱性 - CVE-2007-2430 2012-12-20 18:19 2007-05-1 Show GitHub Exploit DB Packet Storm
228489 7.5 危険 pnflashgames - PostNuke 用の pnFlashGames モジュールの index.php における SQL インジェクションの脆弱性 - CVE-2007-2427 2012-12-20 18:19 2007-05-1 Show GitHub Exploit DB Packet Storm
228490 7.5 危険 wildbits - WordPress 用の myGallery プラグインにおける PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2426 2012-12-20 18:19 2007-05-1 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 2, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
223321 8.8 HIGH
Network
fortinet fcm-mb40_firmware /usr/sbin/default.sh and /usr/apache/htdocs/cgi-bin/admin/hardfactorydefault.cgi on Dynacolor FCM-MB40 v1.2.0.0 devices implement an incomplete factory-reset process. A backdoor can persist because n… CWE-212
 Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2019-13402 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
223322 8.8 HIGH
Network
fortinet fcm-mb40_firmware Dynacolor FCM-MB40 v1.2.0.0 devices have CSRF in all scripts under cgi-bin/. CWE-352
 Origin Validation Error
CVE-2019-13401 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
223323 9.8 CRITICAL
Network
fortinet fcm-mb40_firmware Dynacolor FCM-MB40 v1.2.0.0 use /etc/appWeb/appweb.pass to store administrative web-interface credentials in cleartext. These credentials can be retrieved via cgi-bin/getuserinfo.cgi?mode=info. CWE-522
 Insufficiently Protected Credentials
CVE-2019-13400 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
223324 5.9 MEDIUM
Network
fortinet fcm-mb40_firmware Dynacolor FCM-MB40 v1.2.0.0 devices have a hard-coded SSL/TLS key that is used during an administrator's SSL conversation. CWE-798
 Use of Hard-coded Credentials
CVE-2019-13399 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
223325 7.2 HIGH
Network
fortinet fcm-mb40_firmware Dynacolor FCM-MB40 v1.2.0.0 devices allow remote attackers to execute arbitrary commands via a crafted parameter to a CGI script, as demonstrated by sed injection in cgi-bin/camctrl_save_profile.cgi … CWE-78
OS Command 
CVE-2019-13398 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
223326 8.8 HIGH
Network
imagemagick imagemagick In ImageMagick 7.0.8-50 Q16, ComplexImages in MagickCore/fourier.c has a heap-based buffer over-read because of incorrect calls to GetCacheViewVirtualPixels. CWE-125
Out-of-bounds Read
CVE-2019-13391 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
223327 6.5 MEDIUM
Network
ffmpeg ffmpeg In FFmpeg 4.1.3, there is a division by zero at adx_write_trailer in libavformat/rawenc.c. CWE-369
 Divide By Zero
CVE-2019-13390 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
223328 8.8 HIGH
Network
avtech room_alert_3e_firmware On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?actio… CWE-668
 Exposure of Resource to Wrong Sphere
CVE-2019-13379 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
223329 8.8 HIGH
Network
flarum flarum Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings. CWE-352
 Origin Validation Error
CVE-2019-13183 2024-11-21 13:24 2019-07-8 Show GitHub Exploit DB Packet Storm
223330 9.8 CRITICAL
Network
dlink central_wifimanager A SQL Injection was discovered in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 in PayAction.class.php with the index.php/Pay/passcodeAuth parameter passcode. The vulnerability does no… CWE-89
SQL Injection
CVE-2019-13375 2024-11-21 13:24 2019-07-7 Show GitHub Exploit DB Packet Storm