Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 1, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228541 7.5 危険 post revolution - Post Revolution における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2201 2012-12-20 18:19 2007-04-24 Show GitHub Exploit DB Packet Storm
228542 6.8 警告 supasite - Supasite における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-2185 2012-12-20 18:19 2007-04-24 Show GitHub Exploit DB Packet Storm
228543 7.5 危険 php-ring - PHP-Ring Webring System の index.php における SQL インジェクションの脆弱性 - CVE-2007-2183 2012-12-20 18:19 2007-04-24 Show GitHub Exploit DB Packet Storm
228544 6.8 警告 webinsta - Webinsta FM Manager の admin/login.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2181 2012-12-20 18:19 2007-04-24 Show GitHub Exploit DB Packet Storm
228545 7.8 危険 raiden professional servers - RaidenFTPD の XceddZipLib におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2179 2012-12-20 18:19 2007-04-24 Show GitHub Exploit DB Packet Storm
228546 5.1 警告 ProFTPD Project - ProFTPD の Auth API における認証を回避される脆弱性 - CVE-2007-2165 2012-12-20 18:19 2007-04-16 Show GitHub Exploit DB Packet Storm
228547 7.8 危険 zomplog - Zomplog の upload/force_download.php におけるディレクトリトラバーサルの脆弱性 - CVE-2007-2157 2012-12-20 18:19 2007-04-19 Show GitHub Exploit DB Packet Storm
228548 7.5 危険 rezervi generic - Rezervi Generic における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2156 2012-12-20 18:19 2007-04-19 Show GitHub Exploit DB Packet Storm
228549 7.8 危険 phpfaber - phpFaber TopSites の template.php におけるディレクトリトラバーサルの脆弱性 - CVE-2007-2155 2012-12-20 18:19 2007-04-19 Show GitHub Exploit DB Packet Storm
228550 10 危険 stephen craton - Stephen Craton Chatness における権限を取得される脆弱性 - CVE-2007-2149 2012-12-20 18:19 2007-04-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 2, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
213191 7.2 HIGH
Network
magento magento A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with admin privileges to layouts can execute… NVD-CWE-noinfo
CVE-2019-7895 2024-11-21 13:48 2019-08-3 Show GitHub Exploit DB Packet Storm
213192 7.2 HIGH
Network
magento magento A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with administrator privileges to access ship… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2019-7892 2024-11-21 13:48 2019-08-3 Show GitHub Exploit DB Packet Storm
213193 7.3 HIGH
Network
magento magento An Insecure Direct Object Reference (IDOR) vulnerability exists in the order processing workflow of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can lead … CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2019-7890 2024-11-21 13:48 2019-08-3 Show GitHub Exploit DB Packet Storm
213194 6.5 MEDIUM
Network
magento magento An injection vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.… CWE-74
Injection
CVE-2019-7889 2024-11-21 13:48 2019-08-3 Show GitHub Exploit DB Packet Storm
213195 6.5 MEDIUM
Network
magento magento An information disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to create email templates … NVD-CWE-noinfo
CVE-2019-7888 2024-11-21 13:48 2019-08-3 Show GitHub Exploit DB Packet Storm
213196 4.8 MEDIUM
Network
magento magento A reflected cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prio… CWE-79
Cross-site Scripting
CVE-2019-7887 2024-11-21 13:48 2019-08-3 Show GitHub Exploit DB Packet Storm
213197 7.5 HIGH
Network
magento magento A cryptograhic flaw exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. A weak cryptograhic mechanism is used to generate the intialization vector in multip… CWE-330
 Use of Insufficiently Random Values
CVE-2019-7886 2024-11-21 13:48 2019-08-3 Show GitHub Exploit DB Packet Storm
213198 8.8 HIGH
Network
magento magento Insufficient input validation in the config builder of the Elastic search module could lead to remote code execution in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2… CWE-20
 Improper Input Validation 
CVE-2019-7885 2024-11-21 13:48 2019-08-3 Show GitHub Exploit DB Packet Storm
213199 5.4 MEDIUM
Network
magento magento A stored cross-site scripting vulnerability exists in the WYSIWYG editor of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prio… CWE-79
Cross-site Scripting
CVE-2019-7882 2024-11-21 13:48 2019-08-3 Show GitHub Exploit DB Packet Storm
213200 5.4 MEDIUM
Network
magento magento A cross-site scripting mitigation bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user to escalate pr… CWE-79
Cross-site Scripting
CVE-2019-7881 2024-11-21 13:48 2019-08-3 Show GitHub Exploit DB Packet Storm