Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228931 6.8 警告 phppm - PHP Project Management におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-5642 2012-12-20 18:33 2007-10-23 Show GitHub Exploit DB Packet Storm
228932 6.8 警告 phppm - PHP Project Management における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-5641 2012-12-20 18:33 2007-10-23 Show GitHub Exploit DB Packet Storm
228933 10 危険 The Support Incident Tracker Project - Salford Software SiT! における脆弱性 CWE-noinfo
情報不足
CVE-2007-5635 2012-12-20 18:33 2007-10-23 Show GitHub Exploit DB Packet Storm
228934 6.8 警告 towels - TOWels の src/scripture.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-5628 2012-12-20 18:33 2007-10-23 Show GitHub Exploit DB Packet Storm
228935 6.8 警告 Creative Digital Resources - SocketMail の content/fnc-readmail3.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-5627 2012-12-20 18:33 2007-10-23 Show GitHub Exploit DB Packet Storm
228936 4.3 警告 simongibson - ASP Site Search SearchSimon Lite の filename.asp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-5625 2012-12-20 18:33 2007-10-23 Show GitHub Exploit DB Packet Storm
228937 7.5 危険 zehnet - ZZ:FlashChat の admin/inc/help.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-5620 2012-12-20 18:33 2007-10-22 Show GitHub Exploit DB Packet Storm
228938 7.2 危険 VMware - VMware Server における権限を取得される脆弱性 CWE-noinfo
情報不足
CVE-2007-5619 2012-12-20 18:33 2007-10-21 Show GitHub Exploit DB Packet Storm
228939 7.2 危険 VMware - VMware Playerなどの製品における Authorization などのサービスにおける権限を取得される脆弱性 CWE-noinfo
情報不足
CVE-2007-5618 2012-12-20 18:33 2007-10-21 Show GitHub Exploit DB Packet Storm
228940 10 危険 VMware - VMware Player および Workstation における脆弱性 CWE-noinfo
情報不足
CVE-2007-5617 2012-12-20 18:33 2007-10-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
224331 9.8 CRITICAL
Network
musl-libc musl musl libc through 1.1.23 has an x87 floating-point stack adjustment imbalance, related to the math/i386/ directory. In some cases, use of this library could introduce out-of-bounds writes that are no… CWE-787
 Out-of-bounds Write
CVE-2019-14697 2024-11-21 13:27 2019-08-7 Show GitHub Exploit DB Packet Storm
224332 6.1 MEDIUM
Network
open-school open-school Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter. CWE-79
Cross-site Scripting
CVE-2019-14696 2024-11-21 13:27 2019-08-7 Show GitHub Exploit DB Packet Storm
224333 9.8 CRITICAL
Network
sygnoos popup_builder A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQ… CWE-89
SQL Injection
CVE-2019-14695 2024-11-21 13:27 2019-08-6 Show GitHub Exploit DB Packet Storm
224334 8.8 HIGH
Network
adplug_project
fedoraproject
adplug
fedora
AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp. CWE-787
 Out-of-bounds Write
CVE-2019-14692 2024-11-21 13:27 2019-08-6 Show GitHub Exploit DB Packet Storm
224335 8.8 HIGH
Network
adplug_project
fedoraproject
adplug
fedora
AdPlug 2.3.1 has a heap-based buffer overflow in CdtmLoader::load() in dtm.cpp. CWE-787
 Out-of-bounds Write
CVE-2019-14691 2024-11-21 13:27 2019-08-6 Show GitHub Exploit DB Packet Storm
224336 8.8 HIGH
Network
adplug_project
fedoraproject
adplug
fedora
AdPlug 2.3.1 has a heap-based buffer overflow in CxadbmfPlayer::__bmf_convert_stream() in bmf.cpp. CWE-787
 Out-of-bounds Write
CVE-2019-14690 2024-11-21 13:27 2019-08-6 Show GitHub Exploit DB Packet Storm
224337 5.4 MEDIUM
Network
firefly-iii firefly_iii Firefly III 4.7.17.5 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the liability name field. The JavaScript code is executed upon an error condition during a visi… CWE-79
Cross-site Scripting
CVE-2019-14672 2024-11-21 13:27 2019-08-6 Show GitHub Exploit DB Packet Storm
224338 3.3 LOW
Local
firefly-iii firefly_iii Firefly III 4.7.17.3 is vulnerable to local file enumeration. An attacker can enumerate local files due to the lack of protocol scheme sanitization, such as for file:/// URLs. This is related to fint… CWE-20
 Improper Input Validation 
CVE-2019-14671 2024-11-21 13:27 2019-08-6 Show GitHub Exploit DB Packet Storm
224339 5.4 MEDIUM
Network
firefly-iii firefly_iii Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the bill name field. The JavaScript code is executed during rule-from-bill creation. CWE-79
Cross-site Scripting
CVE-2019-14670 2024-11-21 13:27 2019-08-6 Show GitHub Exploit DB Packet Storm
224340 5.4 MEDIUM
Network
firefly-iii firefly_iii Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the asset account name. The JavaScript code is executed during a visit to the audit account sta… CWE-79
Cross-site Scripting
CVE-2019-14669 2024-11-21 13:27 2019-08-6 Show GitHub Exploit DB Packet Storm