Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 5, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228751 7.5 危険 rediff - redifftoolbar.dll の Rediff Toolbar ActiveX コントロールにおけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-1402 2012-12-20 18:19 2007-03-10 Show GitHub Exploit DB Packet Storm
228752 6.9 警告 plesh - Plash における任意のコマンドを実行される脆弱性 - CVE-2007-1400 2012-12-20 18:19 2007-03-10 Show GitHub Exploit DB Packet Storm
228753 7.1 危険 Snort.org - Snort の frag3 プリプロセッサにおけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-1398 2012-12-20 18:19 2007-03-10 Show GitHub Exploit DB Packet Storm
228754 4.3 警告 The phpMyAdmin Project - phpMyAdmin の index.php におけるクロスサイトスクリプティング (XSS) 攻撃を実行される脆弱性 - CVE-2007-1395 2012-12-20 18:19 2007-03-10 Show GitHub Exploit DB Packet Storm
228755 10 危険 webo - Leo West WEBO の modules/abook/foldertree.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-1391 2012-12-20 18:19 2007-03-10 Show GitHub Exploit DB Packet Storm
228756 4.3 警告 Snitz - Snitz Forums 2000 の pop_profile.asp におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-1374 2012-12-20 18:19 2007-03-9 Show GitHub Exploit DB Packet Storm
228757 10 危険 Pegasus Mail - Mercury/32 におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-1373 2012-12-20 18:19 2007-03-9 Show GitHub Exploit DB Packet Storm
228758 10 危険 postguestbook - PHP-Nuke 用の PostGuestbook モジュールにおける PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-1372 2012-12-20 18:19 2007-03-9 Show GitHub Exploit DB Packet Storm
228759 6.9 警告 Jon Trulson - Conquest におけるバッファオーバーフローの脆弱性 - CVE-2007-1371 2012-12-20 18:19 2007-03-9 Show GitHub Exploit DB Packet Storm
228760 6.2 警告 Zend Technologies Ltd. - Zend Platform におけるルート権限を取得される脆弱性 - CVE-2007-1370 2012-12-20 18:19 2007-03-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
222771 4.3 MEDIUM
Network
acf\ _better_search_project The acf-better-search (aka ACF: Better Search) plugin before 3.3.1 for WordPress allows wp-admin/options-general.php?page=acfbs_admin_page CSRF. CWE-352
 Origin Validation Error
CVE-2019-14682 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm
222772 8.8 HIGH
Network
deny_all_firewall_project deny_all_firewall The Deny All Firewall plugin before 1.1.7 for WordPress allows wp-admin/options-general.php?page=daf_settings&daf_remove=true CSRF. CWE-352
 Origin Validation Error
CVE-2019-14681 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm
222773 5.7 MEDIUM
Network
mijnpress admin-renamer-extended The admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows wp-admin/plugins.php?page=admin-renamer-extended/admin.php CSRF. CWE-352
 Origin Validation Error
CVE-2019-14680 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm
222774 6.5 MEDIUM
Network
reputeinfosystems arprice_lite core/views/arprice_import_export.php in the ARPrice Lite plugin 2.2 for WordPress allows wp-admin/admin.php?page=arplite_import_export CSRF. CWE-352
 Origin Validation Error
CVE-2019-14679 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm
222775 8.1 HIGH
Network
zohocorp manageengine_assetexplorer Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attacker could exploit this vulnerability to expose sen… CWE-611
XXE
CVE-2019-14693 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm
222776 6.1 MEDIUM
Network
verdaccio verdaccio verdaccio before 3.12.0 allows XSS. CWE-79
Cross-site Scripting
CVE-2019-14772 2024-11-21 13:27 2019-08-8 Show GitHub Exploit DB Packet Storm
222777 9.8 CRITICAL
Network
open-school open-school Open-School 3.0, and Community Edition 2.3, allows SQL Injection via the index.php?r=students/students/document id parameter. CWE-89
SQL Injection
CVE-2019-14754 2024-11-21 13:27 2019-08-8 Show GitHub Exploit DB Packet Storm
222778 6.1 MEDIUM
Network
backdropcms backdrop_core In Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3, some menu links within the administration bar may be crafted to execute JavaScript when the administrator is logged in and uses the sear… CWE-79
Cross-site Scripting
CVE-2019-14770 2024-11-21 13:27 2019-08-8 Show GitHub Exploit DB Packet Storm
222779 6.1 MEDIUM
Network
backdropcms backdrop Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain block labels created by administrators. An attacker could potentially craft a spe… CWE-79
Cross-site Scripting
CVE-2019-14769 2024-11-21 13:27 2019-08-8 Show GitHub Exploit DB Packet Storm
222780 5.5 MEDIUM
Local
linux
canonical
linux_kernel
ubuntu_linux
In the Linux kernel before 4.16.4, a double-locking error in drivers/usb/dwc3/gadget.c may potentially cause a deadlock with f_hid. CWE-667
 Improper Locking
CVE-2019-14763 2024-11-21 13:27 2019-08-8 Show GitHub Exploit DB Packet Storm