Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229031 7.5 危険 ultrashareware - Ultra Crypto コンポーネントの CryptoX.dll におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-4903 2012-12-20 18:33 2007-09-17 Show GitHub Exploit DB Packet Storm
229032 6.4 警告 ultrashareware - Ultra Crypto コンポーネントの CryptoX.dll における絶対パストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-4902 2012-12-20 18:33 2007-09-17 Show GitHub Exploit DB Packet Storm
229033 4.3 警告 RSAセキュリティ - RSA EnVision のログオンページにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-4900 2012-12-20 18:33 2007-09-14 Show GitHub Exploit DB Packet Storm
229034 2.1 注意 XWiki - XWiki Enterprise の Multiwiki プラグインにおける重要な情報を取得される脆弱性 CWE-noinfo
情報不足
CVE-2007-4898 2012-12-20 18:33 2007-09-14 Show GitHub Exploit DB Packet Storm
229035 4.3 警告 toms-seiten.at - Toms Gaestebuch の admin/header.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-4896 2012-12-20 18:33 2007-09-14 Show GitHub Exploit DB Packet Storm
229036 5 警告 sisfo kampus - Semarang 3 の dwoprn.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-4895 2012-12-20 18:33 2007-09-14 Show GitHub Exploit DB Packet Storm
229037 7.5 危険 WordPress.org - Wordpress および MU における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-4894 2012-12-20 18:33 2007-09-8 Show GitHub Exploit DB Packet Storm
229038 4.3 警告 WordPress.org - Wordpress および MU の wp-admin/admin-functions.php におけるクロスサイトスクリプティング (XSS) 攻撃を実行される脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2007-4893 2012-12-20 18:33 2007-09-8 Show GitHub Exploit DB Packet Storm
229039 7.5 危険 swsoft - Windows 用の SWSoft Plesk における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-4892 2012-12-20 18:33 2007-09-14 Show GitHub Exploit DB Packet Storm
229040 3.5 注意 XWiki - XWiki の "You are not allowed ..." のエラーハンドラにおける任意のドキュメントを読み取られる脆弱性 CWE-DesignError
CVE-2007-4888 2012-12-20 18:33 2007-01-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
222351 6.5 MEDIUM
Network
koji_project koji Koji through 1.18.0 allows remote Directory Traversal, with resultant Privilege Escalation. CWE-22
Path Traversal
CVE-2019-17109 2024-11-21 13:31 2019-10-10 Show GitHub Exploit DB Packet Storm
222352 4.3 MEDIUM
Network
zohocorp manageengine_datasecurity_plus An issue was discovered in Zoho ManageEngine DataSecurity Plus before 5.0.1 5012. An exposed service allows a basic user ("Operator" access level) to access the configuration file of the mail server … CWE-552
 Files or Directories Accessible to External Parties
CVE-2019-17112 2024-11-21 13:31 2019-10-10 Show GitHub Exploit DB Packet Storm
222353 7.8 HIGH
Local
openbsd
netapp
siemens
openssh
cloud_backup
steelstore_cloud_integrated_storage
scalance_x204rna_firmware
scalance_x204rna_ecc_firmware
OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This … CWE-190
 Integer Overflow or Wraparound
CVE-2019-16905 2024-11-21 13:31 2019-10-10 Show GitHub Exploit DB Packet Storm
222354 6.1 MEDIUM
Network
openproject openproject An XSS vulnerability in project list in OpenProject before 9.0.4 and 10.x before 10.0.2 allows remote attackers to inject arbitrary web script or HTML via the sortBy parameter because error messages … CWE-79
Cross-site Scripting
CVE-2019-17092 2024-11-21 13:31 2019-10-10 Show GitHub Exploit DB Packet Storm
222355 7.5 HIGH
Network
netreo omnicenter Netreo OmniCenter through 12.1.1 allows unauthenticated SQL Injection (Boolean Based Blind) in the redirect parameters and parameter name of the login page through a GET request. The injection allows… CWE-89
SQL Injection
CVE-2019-17128 2024-11-21 13:31 2019-10-10 Show GitHub Exploit DB Packet Storm
222356 9.8 CRITICAL
Network
kramerav viaware Kramer VIAware 2.5.0719.1034 has Incorrect Access Control. CWE-276
Incorrect Default Permissions 
CVE-2019-17124 2024-11-21 13:31 2019-10-10 Show GitHub Exploit DB Packet Storm
222357 8.8 HIGH
Network
fiberhome hg2201t_firmware /var/WEB-GUI/cgi-bin/telnet.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication remote code execution. CWE-306
Missing Authentication for Critical Function
CVE-2019-17186 2024-11-21 13:31 2019-10-9 Show GitHub Exploit DB Packet Storm
222358 9.1 CRITICAL
Network
opendev
canonical
octavia
ubuntu_linux
Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and retrieve … CWE-287
Improper Authentication
CVE-2019-17134 2024-11-21 13:31 2019-10-9 Show GitHub Exploit DB Packet Storm
222359 7.5 HIGH
Network
fiberhome hg2201t_firmware /var/WEB-GUI/cgi-bin/downloadfile.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication Directory Traversal for reading arbitrary files. CWE-22
Path Traversal
CVE-2019-17187 2024-11-21 13:31 2019-10-9 Show GitHub Exploit DB Packet Storm
222360 5.3 MEDIUM
Network
centreon centreon_web The token generator in index.php in Centreon Web before 2.8.27 is predictable. CWE-330
 Use of Insufficiently Random Values
CVE-2019-17105 2024-11-21 13:31 2019-10-9 Show GitHub Exploit DB Packet Storm