Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 14, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229021 10 危険 Winamp - Winamp の in_mp3.dll におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-0065 2012-12-20 18:34 2008-01-22 Show GitHub Exploit DB Packet Storm
229022 9.3 危険 pierreegougelet - Windows 上で稼動する GFL SDK の Pierre-emmanuel Gougelet XnView などにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-0064 2012-12-20 18:34 2008-01-31 Show GitHub Exploit DB Packet Storm
229023 10 危険 トレンドマイクロ - Trend Micro ServerProtect の不特定のプロシージャにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-0014 2012-12-20 18:34 2008-11-17 Show GitHub Exploit DB Packet Storm
229024 10 危険 トレンドマイクロ - Trend Micro ServerProtect の不特定のプロシージャにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-0013 2012-12-20 18:34 2008-11-17 Show GitHub Exploit DB Packet Storm
229025 10 危険 トレンドマイクロ - Trend Micro ServerProtect の不特定のプロシージャにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-0012 2012-12-20 18:34 2008-11-17 Show GitHub Exploit DB Packet Storm
229026 7.2 危険 PulseAudio - PulseAudio の pa_drop_root 関数における権限を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2008-0008 2012-12-20 18:34 2008-01-28 Show GitHub Exploit DB Packet Storm
229027 4.3 警告 xmb forum - XMB におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6728 2012-12-20 18:34 2009-07-5 Show GitHub Exploit DB Packet Storm
229028 10 危険 synce - SynCE (SynCE-dccm) の vdccm におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2007-6703 2012-12-20 18:34 2008-03-4 Show GitHub Exploit DB Packet Storm
229029 7.5 危険 Simple DirectMedia Layer - SDL_image の IMG_gif.c におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-6697 2012-12-20 18:34 2008-02-1 Show GitHub Exploit DB Packet Storm
229030 2.1 注意 webcalendar - WebCalendar におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6696 2012-12-20 18:34 2008-02-1 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 14, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
222131 5.4 MEDIUM
Network
hitachienergy esoms For ABB eSOMS versions 4.0 to 6.0.2, the X-XSS-Protection HTTP response header is not set in responses from the web server. For older web browser not supporting Content Security Policy, this might in… CWE-79
Cross-site Scripting
CVE-2019-19002 2024-11-21 13:33 2020-04-3 Show GitHub Exploit DB Packet Storm
222132 6.5 MEDIUM
Network
hitachienergy esoms For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an attacker can frame parts of the applicat… CWE-1021
 Improper Restriction of Rendered UI Layers or Frames
CVE-2019-19001 2024-11-21 13:33 2020-04-3 Show GitHub Exploit DB Packet Storm
222133 6.5 MEDIUM
Network
hitachienergy esoms For ABB eSOMS 4.0 to 6.0.3, the Cache-Control and Pragma HTTP header(s) have not been properly configured within the application response. This can potentially allow browsers and proxies to cache sen… CWE-200
Information Exposure
CVE-2019-19000 2024-11-21 13:33 2020-04-3 Show GitHub Exploit DB Packet Storm
222134 4.3 MEDIUM
Network
harriscomputer ormed_mis Harris Ormed Self Service before 2019.1.4 allows an authenticated user to view W-2 forms belonging to other users via an arbitrary empNo value to the ORMEDMIS/Data/PY/T4W2Service.svc/RetrieveW2Entrie… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2019-18626 2024-11-21 13:33 2020-03-26 Show GitHub Exploit DB Packet Storm
222135 7.5 HIGH
Network
bloq univalue UniValue::read() in UniValue before 1.0.5 allow attackers to cause a denial of service (the class internal data reaches an inconsistent state) via input data that triggers an error. CWE-674
 Uncontrolled Recursion
CVE-2019-18936 2024-11-21 13:33 2020-03-21 Show GitHub Exploit DB Packet Storm
222136 6.1 MEDIUM
Network
squid-cache
debian
canonical
opensuse
squid
debian_linux
ubuntu_linux
leap
Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi. CWE-74
Injection
CVE-2019-18860 2024-11-21 13:33 2020-03-21 Show GitHub Exploit DB Packet Storm
222137 9.8 CRITICAL
Network
sparkdevnetwork rock_rms Rock RMS before 1.8.6 mishandles vCard access control within the People/GetVCard/REST controller. NVD-CWE-noinfo
CVE-2019-18641 2024-11-21 13:33 2020-03-21 Show GitHub Exploit DB Packet Storm
222138 7.5 HIGH
Network
suitecrm suitecrm SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 mishandles API access tokens and credentials. CWE-522
 Insufficiently Protected Credentials
CVE-2019-18785 2024-11-21 13:33 2020-03-20 Show GitHub Exploit DB Packet Storm
222139 5.3 MEDIUM
Network
salesagility suitecrm SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 does not correctly implement the .htaccess protection mechanism. NVD-CWE-Other
CVE-2019-18782 2024-11-21 13:33 2020-03-20 Show GitHub Exploit DB Packet Storm
222140 7.8 HIGH
Local
claranova adaware_antivirus Adaware antivirus 12.6.1005.11662 and 12.7.1055.0 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junction to restore a malicious DLL from quarantine into … NVD-CWE-noinfo
CVE-2019-18979 2024-11-21 13:33 2020-03-19 Show GitHub Exploit DB Packet Storm