Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 8, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229181 7.5 危険 taskdriver - TaskDriver における SQL インジェクションの脆弱性 - CVE-2007-2622 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
229182 4.6 警告 シマンテック - Symantec pcAnywhere における資格情報を取得される脆弱性 - CVE-2007-2619 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
229183 2.1 注意 サン・マイクロシステムズ - Sun Solaris の SRS Net Connect Software Proxy Core パッケージにおける任意のファイルの最初の行を読まれる脆弱性 - CVE-2007-2617 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
229184 7.5 危険 phphtmllib - phpHtmlLib の examples/widget8.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2614 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
229185 8.3 危険 Wikka Development Team - WikkaWiki における任意の設定ファイルをアップロードされる脆弱性 - CVE-2007-2613 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
229186 7.5 危険 Wikka Development Team - WikkaWiki の libs/Wakka.class.php における SQL インジェクションの脆弱性 - CVE-2007-2612 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
229187 6.8 警告 wavelink media - TutorialCMS におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-2600 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
229188 7.5 危険 wavelink media - TutorialCMS における SQL インジェクションの脆弱性 - CVE-2007-2599 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
229189 10 危険 Simplenews Project - SimpleNews の print.php における SQL インジェクションの脆弱性 - CVE-2007-2598 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
229190 7.5 危険 telltargetcms - telltarget CMS における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2597 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 8, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
223021 9.8 CRITICAL
Network
optiontree_project optiontree The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled. CWE-502
 Deserialization of Untrusted Data
CVE-2019-15321 2024-11-21 13:28 2019-08-22 Show GitHub Exploit DB Packet Storm
223022 9.8 CRITICAL
Network
optiontree_project optiontree The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled. CWE-502
 Deserialization of Untrusted Data
CVE-2019-15320 2024-11-21 13:28 2019-08-22 Show GitHub Exploit DB Packet Storm
223023 9.8 CRITICAL
Network
optiontree_project optiontree The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce. CWE-502
 Deserialization of Untrusted Data
CVE-2019-15319 2024-11-21 13:28 2019-08-22 Show GitHub Exploit DB Packet Storm
223024 9.8 CRITICAL
Network
yikesinc easy_forms_for_mailchimp The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field. CWE-94
Code Injection
CVE-2019-15318 2024-11-21 13:28 2019-08-22 Show GitHub Exploit DB Packet Storm
223025 5.4 MEDIUM
Network
givewp givewp The give plugin before 2.4.7 for WordPress has XSS via a donor name. CWE-79
Cross-site Scripting
CVE-2019-15317 2024-11-21 13:28 2019-08-22 Show GitHub Exploit DB Packet Storm
223026 5.4 MEDIUM
Network
tiki tikiwiki_cms\/groupware tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php?display&fileId= URI. CWE-79
Cross-site Scripting
CVE-2019-15314 2024-11-21 13:28 2019-08-22 Show GitHub Exploit DB Packet Storm
223027 7.0 HIGH
Local
valvesoftware steam_client Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via crafted use of CreateMountPoint.exe and SetOpLock.exe to le… CWE-367
CWE-732
 Time-of-check Time-of-use (TOCTOU) Race Condition
 Incorrect Permission Assignment for Critical Resource
CVE-2019-15316 2024-11-21 13:28 2019-08-22 Show GitHub Exploit DB Packet Storm
223028 7.8 HIGH
Local
valvesoftware steam_client Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the current versions of SteamService.exe and SteamService.dll wi… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2019-15315 2024-11-21 13:28 2019-08-22 Show GitHub Exploit DB Packet Storm
223029 5.4 MEDIUM
Network
vanderbilt redcap REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data import file. CWE-79
Cross-site Scripting
CVE-2019-15127 2024-11-21 13:28 2019-08-22 Show GitHub Exploit DB Packet Storm
223030 9.6 CRITICAL
Network
mantisbt mantisbt The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploa… CWE-79
Cross-site Scripting
CVE-2019-15074 2024-11-21 13:28 2019-08-22 Show GitHub Exploit DB Packet Storm