Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228561 6.8 警告 phpwcms-xt - phpWCMS XT における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-5185 2012-12-20 18:33 2007-10-3 Show GitHub Exploit DB Packet Storm
228562 7.5 危険 smbftpd - SmbFTPD の dirlist.c におけるフォーマットストリングの脆弱性 CWE-134
書式文字列の問題
CVE-2007-5184 2012-12-20 18:33 2007-09-30 Show GitHub Exploit DB Packet Storm
228563 4.3 警告 y&k iletisim formu - Y&K Iletisim Formu の iletisim.asp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-5179 2012-12-20 18:33 2007-10-3 Show GitHub Exploit DB Packet Storm
228564 5 警告 quicksilver forums - Quicksilver Forums における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2007-5172 2012-12-20 18:33 2007-10-1 Show GitHub Exploit DB Packet Storm
228565 5 警告 quicksilver forums - Quicksilver Forums における任意の PMs を削除される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-5171 2012-12-20 18:33 2007-10-1 Show GitHub Exploit DB Packet Storm
228566 5 警告 サン・マイクロシステムズ - Sun Fire X2100 M2 および ELOM の SP における任意のネットワークトラフィックを送信される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-5170 2012-12-20 18:33 2007-09-28 Show GitHub Exploit DB Packet Storm
228567 6.8 警告 phplister - phpLister の .systeme/fonctions.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-5167 2012-12-20 18:33 2007-10-1 Show GitHub Exploit DB Packet Storm
228568 5 警告 wzdftpd - wzdftpd の libwzd-core/wzd_login.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
CWE-189
CVE-2007-5300 2012-12-20 18:33 2007-10-9 Show GitHub Exploit DB Packet Storm
228569 5 警告 skadate - SkaDate におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-5299 2012-12-20 18:33 2007-10-9 Show GitHub Exploit DB Packet Storm
228570 4.3 警告 wikepage - Wikepage Opus および TipiWiki の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
CWE-94
CVE-2007-5295 2012-12-20 18:33 2007-10-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 10, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
222091 9.8 CRITICAL
Network
dlink dcs-935l_firmware
dcs-960l_firmware
This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07.102. Authentication is not required to exploit this vulnerability. The specific… CWE-306
Missing Authentication for Critical Function
CVE-2019-17146 2024-11-21 13:31 2020-01-8 Show GitHub Exploit DB Packet Storm
222092 6.1 MEDIUM
Network
open-xchange open-xchange_appsuite OX App Suite through 7.10.2 has XSS. CWE-79
Cross-site Scripting
CVE-2019-16717 2024-11-21 13:31 2020-01-7 Show GitHub Exploit DB Packet Storm
222093 6.6 MEDIUM
Network
open-xchange open-xchange_appsuite OX App Suite through 7.10.2 has Incorrect Access Control. CWE-276
Incorrect Default Permissions 
CVE-2019-16716 2024-11-21 13:31 2020-01-7 Show GitHub Exploit DB Packet Storm
222094 8.8 HIGH
Network
tiny_file_manager_project tiny_file_manager In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2019-16790 2024-11-21 13:31 2019-12-31 Show GitHub Exploit DB Packet Storm
222095 7.8 HIGH
Local
k7computing k7_ultimate_security In K7 Ultimate Security 16.0.0117, the module K7BKCExt.dll (aka the backup module) improperly validates the administrative privileges of the user, allowing an arbitrary file write via a symbolic link… CWE-59
Link Following
CVE-2019-16896 2024-11-21 13:31 2019-12-28 Show GitHub Exploit DB Packet Storm
222096 5.4 MEDIUM
Network
wordpress
debian
wordpress
debian_linux
In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admi… CWE-79
Cross-site Scripting
CVE-2019-16781 2024-11-21 13:31 2019-12-27 Show GitHub Exploit DB Packet Storm
222097 8.2 HIGH
Network
agendaless
oracle
debian
fedoraproject
redhat
waitress
communications_cloud_native_core_network_function_cloud_native_environment
debian_linux
fedora
openstack
In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress lead… CWE-444
HTTP Request Smuggling
CVE-2019-16789 2024-11-21 13:31 2019-12-27 Show GitHub Exploit DB Packet Storm
222098 5.4 MEDIUM
Network
wordpress
debian
wordpress
debian_linux
WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an a… CWE-79
Cross-site Scripting
CVE-2019-16780 2024-11-21 13:31 2019-12-27 Show GitHub Exploit DB Packet Storm
222099 7.5 HIGH
Network
agendaless
oracle
debian
fedoraproject
redhat
waitress
communications_cloud_native_core_network_function_cloud_native_environment
debian_linux
fedora
openstack
Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Content-Length header … CWE-444
HTTP Request Smuggling
CVE-2019-16786 2024-11-21 13:31 2019-12-21 Show GitHub Exploit DB Packet Storm
222100 7.5 HIGH
Network
agendaless
oracle
debian
fedoraproject
redhat
waitress
communications_cloud_native_core_network_function_cloud_native_environment
debian_linux
fedora
openstack
Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fields is the sequence CRLF, a recipient MAY recognize… CWE-444
HTTP Request Smuggling
CVE-2019-16785 2024-11-21 13:31 2019-12-21 Show GitHub Exploit DB Packet Storm