Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 29, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229001 7.5 危険 web-scripts - Visual Events Calendar の calendar.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4060 2012-12-20 18:02 2006-08-9 Show GitHub Exploit DB Packet Storm
229002 7.5 危険 usolved - USOLVED NEWSolved Lite における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4059 2012-12-20 18:02 2006-08-9 Show GitHub Exploit DB Packet Storm
229003 6.8 警告 simplog - Simpliciti Locked Browser におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-4058 2012-12-20 18:02 2006-08-9 Show GitHub Exploit DB Packet Storm
229004 7.5 危険 the address book reloaded
the address book
- katzlbt Address Book などの認証プロセスにおける SQL インジェクションの脆弱性 - CVE-2006-4056 2012-12-20 18:02 2006-08-9 Show GitHub Exploit DB Packet Storm
229005 7.5 危険 tsep - Olaf Noehring TSEP における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4055 2012-12-20 18:02 2006-08-9 Show GitHub Exploit DB Packet Storm
229006 7.5 危険 turnkey web tools - Turnkey Web Tools PHP Simple Shop における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4052 2012-12-20 18:02 2006-08-9 Show GitHub Exploit DB Packet Storm
229007 7.5 危険 turnkey web tools - Turnkey Web Tools PHP Live Helper の global.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4051 2012-12-20 18:02 2006-08-9 Show GitHub Exploit DB Packet Storm
229008 2.1 注意 サン・マイクロシステムズ - Sun Ray Server Software のユーティリティ utxconfig における任意のファイルを上書きされる脆弱性 - CVE-2006-4049 2012-12-20 18:02 2006-07-7 Show GitHub Exploit DB Packet Storm
229009 7.5 危険 torbstoff - Torbstoff News の news.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4045 2012-12-20 18:02 2006-08-9 Show GitHub Exploit DB Packet Storm
229010 7.5 危険 pike - Pike における SQL インジェクションの脆弱性 - CVE-2006-4041 2012-12-20 18:02 2006-08-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 29, 2026, 4:51 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
212751 7.4 HIGH
Network
amazon fire_os Amazon Fire OS before 5.3.6.4 allows a man-in-the-middle attack against HTTP requests for "Terms of Use" and Privacy pages. CWE-346
 Origin Validation Error
CVE-2019-7399 2024-11-21 13:48 2019-02-17 Show GitHub Exploit DB Packet Storm
212752 5.3 MEDIUM
Network
jforum jforum In JForum 2.1.8, an unauthenticated, remote attacker can enumerate whether a user exists by using the "create user" function. If a register/check/username?username= request corresponds to a username … CWE-209
Information Exposure Through an Error Message
CVE-2019-7550 2024-11-21 13:48 2019-02-13 Show GitHub Exploit DB Packet Storm
212753 6.1 MEDIUM
Network
joomla joomla\! An issue was discovered in Joomla! before 3.9.3. Inadequate filtering on URL fields in various core components could lead to an XSS vulnerability. CWE-79
Cross-site Scripting
CVE-2019-7744 2024-11-21 13:48 2019-02-13 Show GitHub Exploit DB Packet Storm
212754 9.8 CRITICAL
Network
joomla joomla\! An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper… CWE-502
CWE-917
 Deserialization of Untrusted Data
 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
CVE-2019-7743 2024-11-21 13:48 2019-02-13 Show GitHub Exploit DB Packet Storm
212755 6.1 MEDIUM
Network
joomla joomla\! An issue was discovered in Joomla! before 3.9.3. A combination of specific web server configurations, in connection with specific file types and browser-side MIME-type sniffing, causes an XSS attack … CWE-79
Cross-site Scripting
CVE-2019-7742 2024-11-21 13:48 2019-02-13 Show GitHub Exploit DB Packet Storm
212756 6.1 MEDIUM
Network
joomla joomla\! An issue was discovered in Joomla! before 3.9.3. Inadequate checks at the Global Configuration helpurl settings allowed stored XSS. CWE-79
Cross-site Scripting
CVE-2019-7741 2024-11-21 13:48 2019-02-13 Show GitHub Exploit DB Packet Storm
212757 6.1 MEDIUM
Network
joomla joomla\! An issue was discovered in Joomla! before 3.9.3. Inadequate parameter handling in JavaScript code (core.js writeDynaList) could lead to an XSS attack vector. CWE-79
Cross-site Scripting
CVE-2019-7740 2024-11-21 13:48 2019-02-13 Show GitHub Exploit DB Packet Storm
212758 6.1 MEDIUM
Network
joomla joomla\! An issue was discovered in Joomla! before 3.9.3. The "No Filtering" textfilter overrides child settings in the Global Configuration. This is intended behavior. However, it might be unexpected for the… NVD-CWE-noinfo
CVE-2019-7739 2024-11-21 13:48 2019-02-13 Show GitHub Exploit DB Packet Storm
212759 6.1 MEDIUM
Network
verydows verydows Verydows 2.0 has XSS via the index.php?m=api&c=stats&a=count referrer parameter. CWE-79
Cross-site Scripting
CVE-2019-7753 2024-11-21 13:48 2019-02-12 Show GitHub Exploit DB Packet Storm
212760 6.1 MEDIUM
Network
dbninja dbninja _includes\online.php in DbNinja 3.2.7 allows XSS via the data.php task parameter if _users/admin/tasks.php exists. CWE-79
Cross-site Scripting
CVE-2019-7748 2024-11-21 13:48 2019-02-12 Show GitHub Exploit DB Packet Storm