Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 15, 2026, 12:10 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229201 4.3 警告 Simple Machines - SMF におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0284 2012-12-20 18:34 2008-01-15 Show GitHub Exploit DB Packet Storm
229202 7.5 危険 xforum - Xforum の liretopic.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0279 2012-12-20 18:34 2008-01-15 Show GitHub Exploit DB Packet Storm
229203 6 警告 X7 Group - X7 Chat の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0278 2012-12-20 18:34 2008-01-15 Show GitHub Exploit DB Packet Storm
229204 6 警告 taskfreak - TaskFreak! の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0270 2012-12-20 18:34 2008-01-15 Show GitHub Exploit DB Packet Storm
229205 6.8 警告 wavelink media - TutorialCMS の activate.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0254 2012-12-20 18:34 2008-01-15 Show GitHub Exploit DB Packet Storm
229206 5 警告 php webquest - PHP Webquest におけるデータベースの資格情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2008-0249 2012-12-20 18:34 2008-01-11 Show GitHub Exploit DB Packet Storm
229207 9.3 危険 streamaudio - StreamAudio ChainCast ProxyManager の ccpm_0237.dll におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-0248 2012-12-20 18:34 2008-01-11 Show GitHub Exploit DB Packet Storm
229208 10 危険 uploadscript - UploadScript の admin.php における管理者の権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-0246 2012-12-20 18:34 2008-01-11 Show GitHub Exploit DB Packet Storm
229209 7.5 危険 uploadscript - UploadImage の admin.php における管理者の権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-0245 2012-12-20 18:34 2008-01-11 Show GitHub Exploit DB Packet Storm
229210 10 危険 SAP - SAP MaxDB における任意のコマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2008-0244 2012-12-20 18:34 2008-01-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 15, 2026, 4:28 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
224261 7.8 HIGH
Local
notepad-plus-plus
scintilla
notepad\+\+
scintilla
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file. CWE-787
 Out-of-bounds Write
CVE-2019-16294 2024-11-21 13:30 2019-09-15 Show GitHub Exploit DB Packet Storm
224262 8.8 HIGH
Network
mobatek mobaxterm In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup asking whether the user wants to run MobaXterm to handle the link. If accepted,… CWE-77
Command Injection
CVE-2019-16305 2024-11-21 13:30 2019-09-15 Show GitHub Exploit DB Packet Storm
224263 9.8 CRITICAL
Network
jhipster jhipster
jhipster_kotlin
A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an insecure source of randomness (apache.commons.lang3 RandomStringUtils). This a… CWE-338
 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2019-16303 2024-11-21 13:30 2019-09-14 Show GitHub Exploit DB Packet Storm
224264 8.8 HIGH
Network
opmantek open-audit The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field. CWE-78
OS Command 
CVE-2019-16293 2024-11-21 13:30 2019-09-14 Show GitHub Exploit DB Packet Storm
224265 5.4 MEDIUM
Network
webcraftic woody_ad_snippets The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter. CWE-79
Cross-site Scripting
CVE-2019-16289 2024-11-21 13:30 2019-09-14 Show GitHub Exploit DB Packet Storm
224266 7.5 HIGH
Network
tenda n301_firmware On Tenda N301 wireless routers, a long string in the wifiSSID parameter of a goform/setWifi POST request causes the device to crash. NVD-CWE-noinfo
CVE-2019-16288 2024-11-21 13:30 2019-09-14 Show GitHub Exploit DB Packet Storm
224267 7.8 HIGH
Local
picoc_project picoc PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called from ExpressionParseFunctionCall in expression.c. CWE-787
 Out-of-bounds Write
CVE-2019-16277 2024-11-21 13:30 2019-09-13 Show GitHub Exploit DB Packet Storm
224268 6.5 MEDIUM
Adjacent
w1.fi
debian
canonical
hostapd
wpa_supplicant
debian_linux
ubuntu_linux
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service th… CWE-346
 Origin Validation Error
CVE-2019-16275 2024-11-21 13:30 2019-09-13 Show GitHub Exploit DB Packet Storm
224269 6.1 MEDIUM
Network
afterlogic aurora Afterlogic Aurora through 8.3.9-build-a3 has XSS that can be leveraged for session hijacking by retrieving the session cookie from the administrator login. CWE-79
Cross-site Scripting
CVE-2019-16238 2024-11-21 13:30 2019-09-13 Show GitHub Exploit DB Packet Storm
224270 9.1 CRITICAL
Network
tripplite pdumh15at_firmware Tripp Lite PDUMH15AT 12.04.0053 devices allow unauthenticated POST requests to the /Forms/ directory, as demonstrated by changing the manager or admin password, or shutting off power to an outlet. NO… CWE-287
Improper Authentication
CVE-2019-16261 2024-11-21 13:30 2019-09-13 Show GitHub Exploit DB Packet Storm