Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 7, 2026, 2:09 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228931 7.5 危険 searchactivity - Searchactivity の searchbot.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2329 2012-12-20 18:19 2007-04-26 Show GitHub Exploit DB Packet Storm
228932 7.5 危険 phpmytgp - phpMYTGP の addvip.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2328 2012-12-20 18:19 2007-04-26 Show GitHub Exploit DB Packet Storm
228933 10 危険 SilverStripe - SilverStripe の検索機能における脆弱性 - CVE-2007-2321 2012-12-20 18:19 2007-04-17 Show GitHub Exploit DB Packet Storm
228934 7.5 危険 VWar - PHP-Nuke 用の VWar モジュールにおける SQL インジェクションの脆弱性 - CVE-2007-2312 2012-12-20 18:19 2007-04-26 Show GitHub Exploit DB Packet Storm
228935 7.5 危険 webkalk2 - WebKalk2 の engine/engine.inc.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2307 2012-12-20 18:19 2007-04-26 Show GitHub Exploit DB Packet Storm
228936 4.3 警告 VWar - PHP-Nuke 用の VWar モジュールにおけるクロスサイトスクリプティングの脆弱性 - CVE-2007-2306 2012-12-20 18:19 2007-04-26 Show GitHub Exploit DB Packet Storm
228937 7.5 危険 qdblog - QDBlog の authenticate.php における SQL インジェクションの脆弱性 - CVE-2007-2305 2012-12-20 18:19 2007-04-26 Show GitHub Exploit DB Packet Storm
228938 7.5 危険 qdblog - QDBlog におけるディレクトリトラバーサルの脆弱性 - CVE-2007-2304 2012-12-20 18:19 2007-04-26 Show GitHub Exploit DB Packet Storm
228939 4.3 警告 surat kabar - Endy Kristanto Surat kabar / News Management Online におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-2300 2012-12-20 18:19 2007-04-26 Show GitHub Exploit DB Packet Storm
228940 7.5 危険 wf-links - XOOPS 用の WF-Links モジュールにおける SQL インジェクションの脆弱性 - CVE-2007-2373 2012-12-20 18:19 2005-06-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 7, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
222771 8.8 HIGH
Network
ncrafts formcraft The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF. CWE-352
 Origin Validation Error
CVE-2019-15114 2024-11-21 13:28 2019-08-17 Show GitHub Exploit DB Packet Storm
222772 8.8 HIGH
Network
codeermeneer companion_sitemap_generator The companion-sitemap-generator plugin before 3.7.0 for WordPress has CSRF. CWE-352
 Origin Validation Error
CVE-2019-15113 2024-11-21 13:28 2019-08-17 Show GitHub Exploit DB Packet Storm
222773 5.4 MEDIUM
Network
kunena kunena The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode. CWE-79
Cross-site Scripting
CVE-2019-15120 2024-11-21 13:28 2019-08-17 Show GitHub Exploit DB Packet Storm
222774 5.5 MEDIUM
Local
nps_project nps lib/install/install.go in cnlh nps through 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps, leading to a file overwrite by a local user. CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2019-15119 2024-11-21 13:28 2019-08-17 Show GitHub Exploit DB Packet Storm
222775 5.5 MEDIUM
Local
linux
canonical
debian
opensuse
netapp
linux_kernel
ubuntu_linux
debian_linux
leap
data_availability_services
solidfire
hci_management_node
active_iq_unified_manager
solidfire_baseboard_management_controller_firmwa…
check_input_term in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles recursion, leading to kernel stack exhaustion. CWE-674
 Uncontrolled Recursion
CVE-2019-15118 2024-11-21 13:28 2019-08-16 Show GitHub Exploit DB Packet Storm
222776 7.8 HIGH
Local
linux linux_kernel parse_audio_mixer_unit in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles a short descriptor, leading to out-of-bounds memory access. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2019-15117 2024-11-21 13:28 2019-08-16 Show GitHub Exploit DB Packet Storm
222777 9.8 CRITICAL
Network
artica integria_ims filemgr.php in Artica Integria IMS 5.0.86 allows index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload arbitrary file upload. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2019-15091 2024-11-21 13:28 2019-08-16 Show GitHub Exploit DB Packet Storm
222778 4.8 MEDIUM
Network
wso2 api_manager An issue was discovered in WSO2 API Manager 2.6.0 before WSO2-CARBON-PATCH-4.4.0-4457. There is XSS via a crafted filename to the file-upload feature of the event simulator component. CWE-79
Cross-site Scripting
CVE-2019-15108 2024-11-21 13:28 2019-08-16 Show GitHub Exploit DB Packet Storm
222779 9.8 CRITICAL
Network
webmin webmin An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability. CWE-78
OS Command 
CVE-2019-15107 2024-11-21 13:28 2019-08-16 Show GitHub Exploit DB Packet Storm
222780 9.8 CRITICAL
Network
zohocorp manageengine_opmanager An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on the server. The "username+'@opm' string is used for… CWE-306
Missing Authentication for Critical Function
CVE-2019-15106 2024-11-21 13:28 2019-08-16 Show GitHub Exploit DB Packet Storm