Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 22, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229261 7.5 危険 pozscripts - PozScripts Classified Auctions Script の gotourl.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4755 2012-12-20 18:52 2008-10-27 Show GitHub Exploit DB Packet Storm
229262 5.8 警告 scripts-for-sites - SFS Ez Forum の forum.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4754 2012-12-20 18:52 2008-10-27 Show GitHub Exploit DB Packet Storm
229263 7.5 危険 tech logic - TlNews における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2008-4752 2012-12-20 18:52 2008-10-27 Show GitHub Exploit DB Packet Storm
229264 7.5 危険 uniwin - Uniwin eCart Professional における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4746 2012-12-20 18:52 2008-10-27 Show GitHub Exploit DB Packet Storm
229265 4.3 警告 uniwin - Uniwin eCart Professional の emailFriend.asp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-4745 2012-12-20 18:52 2008-10-27 Show GitHub Exploit DB Packet Storm
229266 7.5 危険 quidascript - QuidaScript FAQ Management Script の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4743 2012-12-20 18:52 2008-10-27 Show GitHub Exploit DB Packet Storm
229267 4.3 警告 timetrex - TimeTrex の interface/Login.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-4742 2012-12-20 18:52 2008-10-27 Show GitHub Exploit DB Packet Storm
229268 5.1 警告 tinycms - TinyCMS 内の ZZ_Templater モジュール内におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-4740 2012-12-20 18:52 2008-10-27 Show GitHub Exploit DB Packet Storm
229269 6.8 警告 plugspace - PlugSpace の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-4739 2012-12-20 18:52 2008-10-24 Show GitHub Exploit DB Packet Storm
229270 7.5 危険 tufat - MyCard の gallery.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4738 2012-12-20 18:52 2008-10-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 22, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
224781 9.8 CRITICAL
Network
skymee
petwant
petalk_ai_firmware
pf-103_firmware
processCommandSetUid() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user. CWE-78
OS Command 
CVE-2019-16733 2024-11-21 13:31 2019-12-14 Show GitHub Exploit DB Packet Storm
224782 8.1 HIGH
Network
skymee
petwant
petalk_ai_firmware
pf-103_firmware
Unencrypted HTTP communications for firmware upgrades in Petalk AI and PF-103 allow man-in-the-middle attackers to run arbitrary code as the root user. CWE-347
CWE-319
 Improper Verification of Cryptographic Signature
Cleartext Transmission of Sensitive Information
CVE-2019-16732 2024-11-21 13:31 2019-12-14 Show GitHub Exploit DB Packet Storm
224783 7.5 HIGH
Network
skymee
petwant
petalk_ai_firmware
pf-103_firmware
The udpServerSys service in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to initiate firmware upgrades and alter device settings. CWE-306
Missing Authentication for Critical Function
CVE-2019-16731 2024-11-21 13:31 2019-12-14 Show GitHub Exploit DB Packet Storm
224784 9.8 CRITICAL
Network
skymee
petwant
petalk_ai_firmware
pf-103_firmware
processCommandUpgrade() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user. CWE-78
OS Command 
CVE-2019-16730 2024-11-21 13:31 2019-12-14 Show GitHub Exploit DB Packet Storm
224785 7.5 HIGH
Network
egain mail The eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email) are mishandled, as demonstrated by fromName header injection with a %0a or %0d… CWE-74
Injection
CVE-2019-17123 2024-11-21 13:31 2019-12-14 Show GitHub Exploit DB Packet Storm
224786 9.8 CRITICAL
Network
phpfastcache phpfastcache In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver. CWE-502
 Deserialization of Untrusted Data
CVE-2019-16774 2024-11-21 13:31 2019-12-13 Show GitHub Exploit DB Packet Storm
224787 6.5 MEDIUM
Network
npmjs
opensuse
oracle
fedoraproject
redhat
npm
leap
graalvm
fedora
enterprise_linux
enterprise_linux_eus
Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For e… CWE-269
 Improper Privilege Management
CVE-2019-16777 2024-11-21 13:31 2019-12-13 Show GitHub Exploit DB Packet Storm
224788 8.1 HIGH
Network
npmjs
opensuse
oracle
fedoraproject
redhat
npm
leap
graalvm
fedora
enterprise_linux
enterprise_linux_eus
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly … CWE-22
Path Traversal
CVE-2019-16776 2024-11-21 13:31 2019-12-13 Show GitHub Exploit DB Packet Storm
224789 6.5 MEDIUM
Network
redhat
npmjs
opensuse
oracle
fedoraproject
enterprise_linux
enterprise_linux_eus
npm
leap
graalvm
fedora
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon… - CVE-2019-16775 2024-11-21 13:31 2019-12-13 Show GitHub Exploit DB Packet Storm
224790 7.5 HIGH
Network
microfocus acutoweb Unauthorized file download vulnerability in all supported versions of Micro Focus AcuToWeb. The vulnerability could be exploited to enumerate and download files from the filesystem of the system runn… NVD-CWE-noinfo
CVE-2019-17087 2024-11-21 13:31 2019-12-12 Show GitHub Exploit DB Packet Storm