Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 21, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228631 4.3 警告 Pro Chat Rooms - Pro Chat Rooms の profiles/index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6501 2012-12-20 19:10 2009-03-20 Show GitHub Exploit DB Packet Storm
228632 7.8 危険 tp - Neostrada Livebox ADSL ルータにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2008-6497 2012-12-20 19:10 2009-03-19 Show GitHub Exploit DB Packet Storm
228633 8.8 危険 visagesoft - VISAGESOFT eXPert PDF EditorX の VSPDFEditorX.VSPDFEdit ActiveX コントロールにおける任意のファイルを作成される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-6496 2012-12-20 19:10 2009-03-19 Show GitHub Exploit DB Packet Storm
228634 4.3 警告 zirkon box - Fritz Berger yappa-ng の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6495 2012-12-20 19:10 2009-03-19 Show GitHub Exploit DB Packet Storm
228635 5 警告 robs-projects - ASP User Engine.NET におけるデータベースをダウンロードされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-6494 2012-12-20 19:10 2009-03-19 Show GitHub Exploit DB Packet Storm
228636 6.8 警告 tizag - Tizag Countdown Creator の process.php における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2008-6492 2012-12-20 19:10 2009-03-19 Show GitHub Exploit DB Packet Storm
228637 7.5 危険 softcomplex - SoftComplex PHP Image Gallery の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6488 2012-12-20 19:10 2009-03-18 Show GitHub Exploit DB Packet Storm
228638 6.8 警告 shatm - SharedLog の slideshow_uploadvideo.content.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-6486 2012-12-20 19:10 2009-03-18 Show GitHub Exploit DB Packet Storm
228639 7.5 危険 softcomplex - SoftComplex PHP Image Gallery の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6485 2012-12-20 19:10 2009-03-18 Show GitHub Exploit DB Packet Storm
228640 7.5 危険 virtuemart-solutions - Joomla! 用の Ecom Solutions VirtueMart Google Base コンポーネントにおける PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-6483 2012-12-20 19:10 2009-03-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 21, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
225211 6.1 MEDIUM
Network
wordpress
debian
wordpress
debian_linux
WordPress before 5.2.3 allows reflected XSS in the dashboard. CWE-79
Cross-site Scripting
CVE-2019-16221 2024-11-21 13:30 2019-09-11 Show GitHub Exploit DB Packet Storm
225212 6.1 MEDIUM
Network
wordpress
debian
wordpress
debian_linux
In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forwar… CWE-601
Open Redirect
CVE-2019-16220 2024-11-21 13:30 2019-09-11 Show GitHub Exploit DB Packet Storm
225213 6.1 MEDIUM
Network
wordpress
debian
wordpress
debian_linux
WordPress before 5.2.3 allows XSS in shortcode previews. CWE-79
Cross-site Scripting
CVE-2019-16219 2024-11-21 13:30 2019-09-11 Show GitHub Exploit DB Packet Storm
225214 6.1 MEDIUM
Network
wordpress
debian
wordpress
debian_linux
WordPress before 5.2.3 allows XSS in stored comments. CWE-79
Cross-site Scripting
CVE-2019-16218 2024-11-21 13:30 2019-09-11 Show GitHub Exploit DB Packet Storm
225215 6.1 MEDIUM
Network
wordpress
debian
wordpress
debian_linux
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled. CWE-79
Cross-site Scripting
CVE-2019-16217 2024-11-21 13:30 2019-09-11 Show GitHub Exploit DB Packet Storm
225216 5.4 MEDIUM
Network
esri arcgis_enterprise In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack through the EDIT MY PROFILE feature. CWE-79
Cross-site Scripting
CVE-2019-16193 2024-11-21 13:30 2019-09-11 Show GitHub Exploit DB Packet Storm
225217 5.7 MEDIUM
Network
libra libra_core Libra Core before 2019-09-03 has an erroneous regular expression for inline comments, which makes it easier for attackers to interfere with code auditing by using a nonstandard line-break character f… NVD-CWE-noinfo
CVE-2019-16214 2024-11-21 13:30 2019-09-11 Show GitHub Exploit DB Packet Storm
225218 7.5 HIGH
Network
humanica humatrix The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm t… CWE-276
Incorrect Default Permissions 
CVE-2019-16106 2024-11-21 13:30 2019-09-11 Show GitHub Exploit DB Packet Storm
225219 6.5 MEDIUM
Network
misp misp MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts are blocked by the __checkLoggedActions function with a "This could be an indicat… CWE-269
 Improper Privilege Management
CVE-2019-16202 2024-11-21 13:30 2019-09-10 Show GitHub Exploit DB Packet Storm
225220 9.8 CRITICAL
Network
doccms doccms upload_model() in /admini/controllers/system/managemodel.php in DocCms 2016.5.17 allow remote attackers to execute arbitrary PHP code through module management files, as demonstrated by a .php file i… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2019-16192 2024-11-21 13:30 2019-09-10 Show GitHub Exploit DB Packet Storm