Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229161 6.8 警告 szymon kosok - Szymon Kosok Best Top List の banner-upload.php における banners/ 配下の任意の PHP ファイルを実行される脆弱性 - CVE-2007-4376 2012-12-20 18:33 2007-08-16 Show GitHub Exploit DB Packet Storm
229162 4 警告 rndlabs - Babo Violent におけるメッセージを偽造される脆弱性 - CVE-2007-4374 2012-12-20 18:33 2007-08-16 Show GitHub Exploit DB Packet Storm
229163 6.8 警告 rndlabs - Babo Violent のサーバにおける認証を回避される脆弱性 - CVE-2007-4373 2012-12-20 18:33 2007-08-16 Show GitHub Exploit DB Packet Storm
229164 7.5 危険 racer - Racer の client などにおけるバッファオーバーフローの脆弱性 - CVE-2007-4370 2012-12-20 18:33 2007-08-15 Show GitHub Exploit DB Packet Storm
229165 5 警告 sote - SOTEeSKLEP の go/_files におけるディレクトリトラバーサルの脆弱性 - CVE-2007-4369 2012-12-20 18:33 2007-08-15 Show GitHub Exploit DB Packet Storm
229166 5 警告 wengo - WengoPhone におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-4366 2012-12-20 18:33 2007-08-15 Show GitHub Exploit DB Packet Storm
229167 6.8 警告 prozilla - Prozilla Webring の category.php における SQL インジェクションの脆弱性 - CVE-2007-4362 2012-12-20 18:33 2007-08-15 Show GitHub Exploit DB Packet Storm
229168 6.8 警告 skilmatch staffing systems - SkilMatch Staffing Systems JobLister3 における SQL インジェクションの脆弱性 - CVE-2007-4359 2012-12-20 18:33 2007-08-15 Show GitHub Exploit DB Packet Storm
229169 4.3 警告 zoidcom - Zoidcom におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-4358 2012-12-20 18:33 2007-08-15 Show GitHub Exploit DB Packet Storm
229170 7.5 危険 phpcentral - PHPCentral Login の include.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-4342 2012-12-20 18:33 2007-08-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
222501 9.8 CRITICAL
Network
linea_project linea An issue was discovered in the linea crate through 0.9.4 for Rust. There is double free in the Matrix::zip_elements method. CWE-415
 Double Free
CVE-2019-16880 2024-11-21 13:31 2019-09-26 Show GitHub Exploit DB Packet Storm
222502 8.8 HIGH
Network
netgate pfsense pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metacharacters in a parameter value. CWE-78
OS Command 
CVE-2019-16701 2024-11-21 13:31 2019-09-26 Show GitHub Exploit DB Packet Storm
222503 9.8 CRITICAL
Network
emlog emlog emlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dell_all_bak request with directory traversal sequences in the bak[] parameter. CWE-22
Path Traversal
CVE-2019-16868 2024-11-21 13:31 2019-09-25 Show GitHub Exploit DB Packet Storm
222504 6.5 MEDIUM
Network
hongcms_project hongcms HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/database/ajax?action=delete, a similar issue to CVE-2018-16774. (If the attacker deletes config.php and… CWE-22
Path Traversal
CVE-2019-16867 2024-11-21 13:31 2019-09-25 Show GitHub Exploit DB Packet Storm
222505 9.8 CRITICAL
Network
vbulletin vbulletin vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request. CWE-94
Code Injection
CVE-2019-16759 2024-11-21 13:31 2019-09-25 Show GitHub Exploit DB Packet Storm
222506 6.1 MEDIUM
Network
joomla joomla\! In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates. CWE-79
Cross-site Scripting
CVE-2019-16725 2024-11-21 13:31 2019-09-25 Show GitHub Exploit DB Packet Storm
222507 9.8 CRITICAL
Network
upredsun file_sharing_wizard File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Exception Handler (SEH) based buffer overflow in an HTTP POST parameter, a similar iss… CWE-120
Classic Buffer Overflow
CVE-2019-16724 2024-11-21 13:31 2019-09-25 Show GitHub Exploit DB Packet Storm
222508 7.5 HIGH
Network
riot-os riot RIOT 2019.07 contains a NULL pointer dereference in the MQTT-SN implementation (asymcute), potentially allowing an attacker to crash a network node running RIOT. This requires spoofing an MQTT server… CWE-476
 NULL Pointer Dereference
CVE-2019-16754 2024-11-21 13:31 2019-09-25 Show GitHub Exploit DB Packet Storm
222509 6.1 MEDIUM
Network
devise_token_auth_project devise_token_auth An issue was discovered in Devise Token Auth through 1.1.2. The omniauth failure endpoint is vulnerable to Reflected Cross Site Scripting (XSS) through the message parameter. Unauthenticated attacker… CWE-79
Cross-site Scripting
CVE-2019-16751 2024-11-21 13:31 2019-09-25 Show GitHub Exploit DB Packet Storm
222510 9.8 CRITICAL
Network
wolfssl wolfssl In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer over-read in Chec… CWE-125
Out-of-bounds Read
CVE-2019-16748 2024-11-21 13:31 2019-09-24 Show GitHub Exploit DB Packet Storm