Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 13, 2026, 12:06 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228681 6.8 警告 phpip - phpIP Management における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0538 2012-12-20 18:34 2008-02-1 Show GitHub Exploit DB Packet Storm
228682 4.3 警告 softcart - SoftCart の SoftCart.exe におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0523 2012-12-20 18:34 2008-01-31 Show GitHub Exploit DB Packet Storm
228683 7.5 危険 WordPress.org - WordPress 用の WassUp プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0520 2012-12-20 18:34 2008-01-31 Show GitHub Exploit DB Packet Storm
228684 9.3 危険 SQLiteManager - SQLiteManager の spaw/dialogs/confirm.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-0516 2012-12-20 18:34 2008-01-31 Show GitHub Exploit DB Packet Storm
228685 7.8 危険 Phpcms - phpCMS の parser/include/class.cache_phpcms.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0513 2012-12-20 18:34 2008-01-31 Show GitHub Exploit DB Packet Storm
228686 6.8 警告 WordPress.org - WordPress 用の Dean's Permalinks Migration プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-0508 2012-12-20 18:34 2008-01-31 Show GitHub Exploit DB Packet Storm
228687 7.5 危険 WordPress.org - WordPress 用の AdServe プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0507 2012-12-20 18:34 2008-01-31 Show GitHub Exploit DB Packet Storm
228688 5.8 警告 加藤和良 - phpMyClub におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0501 2012-12-20 18:34 2008-01-30 Show GitHub Exploit DB Packet Storm
228689 7.5 危険 WordPress.org - WordPress 用の fGallery プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0491 2012-12-20 18:34 2008-01-30 Show GitHub Exploit DB Packet Storm
228690 7.5 危険 WordPress.org - WordPress 用の WP-Cal プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0490 2012-12-20 18:34 2008-01-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
224601 7.8 HIGH
Local
intel raid_web_console_3 Improper permissions in the installer for Intel(R) RWC 3 for Windows before version 7.010.009.000 may allow an authenticated user to potentially enable escalation of privilege via local access. CWE-276
Incorrect Default Permissions 
CVE-2019-14601 2024-11-21 13:27 2020-01-18 Show GitHub Exploit DB Packet Storm
224602 6.7 MEDIUM
Local
intel snmp_subagent_stand-alone Uncontrolled search path element in the installer for Intel(R) SNMP Subagent Stand-Alone for Windows* may allow an authenticated user to potentially enable escalation of privilege via local access. CWE-427
 Uncontrolled Search Path Element
CVE-2019-14600 2024-11-21 13:27 2020-01-18 Show GitHub Exploit DB Packet Storm
224603 8.8 HIGH
Network
atlassian bitbucket Bitbucket Server and Bitbucket Data Center from version 4.13. before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 be… CWE-269
 Improper Privilege Management
CVE-2019-15012 2024-11-21 13:27 2020-01-16 Show GitHub Exploit DB Packet Storm
224604 8.8 HIGH
Network
atlassian bitbucket Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.… CWE-77
Command Injection
CVE-2019-15010 2024-11-21 13:27 2020-01-16 Show GitHub Exploit DB Packet Storm
224605 8.8 HIGH
Network
billion sg600_r2_firmware Billion Smart Energy Router SG600R2 Firmware v3.02.rc6 allows an authenticated attacker to gain root execution privileges over the device via a hidden etc_ro/web/adm/system_command.asp shell feature. NVD-CWE-noinfo
CVE-2019-14920 2024-11-21 13:27 2020-01-10 Show GitHub Exploit DB Packet Storm
224606 7.8 HIGH
Local
billion sg600_r2_firmware An exposed Telnet Service on the Billion Smart Energy Router SG600R2 with firmware v3.02.rc6 allows a local network attacker to authenticate via hardcoded credentials into a shell, gaining root execu… CWE-798
 Use of Hard-coded Credentials
CVE-2019-14919 2024-11-21 13:27 2020-01-10 Show GitHub Exploit DB Packet Storm
224607 5.4 MEDIUM
Network
billion sg600_r2_firmware XSS in the DHCP lease-status table in Billion Smart Energy Router SG600R2 Firmware v3.02.rc6 allows an attacker to inject arbitrary HTML/JavaScript code to achieve client-side code execution via craf… CWE-79
Cross-site Scripting
CVE-2019-14918 2024-11-21 13:27 2020-01-10 Show GitHub Exploit DB Packet Storm
224608 4.3 MEDIUM
Network
redhat keycloak
single_sign-on
jboss_enterprise_application_platform
jboss_fuse
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability cou… NVD-CWE-noinfo
CVE-2019-14820 2024-11-21 13:27 2020-01-9 Show GitHub Exploit DB Packet Storm
224609 9.8 CRITICAL
Network
libsdl
redhat
simple_directmedia_layer
enterprise_linux
A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL packages, SDL versions through 1.2.15 and 2.x through … - CVE-2019-14906 2024-11-21 13:27 2020-01-8 Show GitHub Exploit DB Packet Storm
224610 8.8 HIGH
Network
redhat openshift_container_platform A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the … - CVE-2019-14819 2024-11-21 13:27 2020-01-8 Show GitHub Exploit DB Packet Storm