Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229371 2.3 注意 BlackBerry - Research in Motion BlackBerry 7270 におけるフォーマットストリングの脆弱性 - CVE-2007-3442 2012-12-20 18:19 2007-06-26 Show GitHub Exploit DB Packet Storm
229372 6.4 警告 snom - Snom 320 SIP Phone における任意の電話番号へ発信される脆弱性 - CVE-2007-3440 2012-12-20 18:19 2007-06-26 Show GitHub Exploit DB Packet Storm
229373 5 警告 snom - Snom 320 SIP Phone における不在着信を読まれる脆弱性 - CVE-2007-3439 2012-12-20 18:19 2007-06-26 Show GitHub Exploit DB Packet Storm
229374 9.3 危険 rkd software - RKD Software の BarCodeAx.dll におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-3435 2012-12-20 18:19 2007-06-26 Show GitHub Exploit DB Packet Storm
229375 7.5 危険 PluXml - Pluxml の admin/images.php における任意のコードをアップロードおよび実行される脆弱性 - CVE-2007-3432 2012-12-20 18:19 2007-06-26 Show GitHub Exploit DB Packet Storm
229376 6.8 警告 valerio capello - Valerio Capello Dagger - The Cutting Edge r23jan2007 の cal.func.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-3431 2012-12-20 18:19 2007-06-26 Show GitHub Exploit DB Packet Storm
229377 7.5 危険 Simple Invoices - Simple Invoices 2007 の index.php における SQL インジェクションの脆弱性 - CVE-2007-3430 2012-12-20 18:19 2007-06-26 Show GitHub Exploit DB Packet Storm
229378 7.5 危険 ZoneO-soft - phpTrafficA における脆弱性 - CVE-2007-3428 2012-12-20 18:19 2007-06-26 Show GitHub Exploit DB Packet Storm
229379 7.5 危険 ZoneO-soft - phpTrafficA の index.php における SQL インジェクションの脆弱性 - CVE-2007-3427 2012-12-20 18:19 2007-06-26 Show GitHub Exploit DB Packet Storm
229380 4.3 警告 ZoneO-soft - phpTrafficA の index.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3426 2012-12-20 18:19 2007-06-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
223681 9.8 CRITICAL
Network
yikesinc easy_forms_for_mailchimp The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field. CWE-94
Code Injection
CVE-2019-15318 2024-11-21 13:28 2019-08-22 Show GitHub Exploit DB Packet Storm
223682 5.4 MEDIUM
Network
givewp givewp The give plugin before 2.4.7 for WordPress has XSS via a donor name. CWE-79
Cross-site Scripting
CVE-2019-15317 2024-11-21 13:28 2019-08-22 Show GitHub Exploit DB Packet Storm
223683 5.4 MEDIUM
Network
tiki tikiwiki_cms\/groupware tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php?display&fileId= URI. CWE-79
Cross-site Scripting
CVE-2019-15314 2024-11-21 13:28 2019-08-22 Show GitHub Exploit DB Packet Storm
223684 7.0 HIGH
Local
valvesoftware steam_client Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via crafted use of CreateMountPoint.exe and SetOpLock.exe to le… CWE-367
CWE-732
 Time-of-check Time-of-use (TOCTOU) Race Condition
 Incorrect Permission Assignment for Critical Resource
CVE-2019-15316 2024-11-21 13:28 2019-08-22 Show GitHub Exploit DB Packet Storm
223685 7.8 HIGH
Local
valvesoftware steam_client Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the current versions of SteamService.exe and SteamService.dll wi… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2019-15315 2024-11-21 13:28 2019-08-22 Show GitHub Exploit DB Packet Storm
223686 5.4 MEDIUM
Network
vanderbilt redcap REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data import file. CWE-79
Cross-site Scripting
CVE-2019-15127 2024-11-21 13:28 2019-08-22 Show GitHub Exploit DB Packet Storm
223687 9.6 CRITICAL
Network
mantisbt mantisbt The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploa… CWE-79
Cross-site Scripting
CVE-2019-15074 2024-11-21 13:28 2019-08-22 Show GitHub Exploit DB Packet Storm
223688 7.8 HIGH
Local
bitdefender antivirus_2020 An Untrusted Search Path vulnerability in the ServiceInstance.dll library versions 1.0.15.119 and lower, as used in Bitdefender Antivirus Free 2020 versions prior to 1.0.15.138, allows an attacker to… CWE-426
 Untrusted Search Path
CVE-2019-15295 2024-11-21 13:28 2019-08-22 Show GitHub Exploit DB Packet Storm
223689 6.1 MEDIUM
Network
wp-slimstat slimstat_analytics The wp-slimstat plugin before 4.8.1 for WordPress has XSS. CWE-79
Cross-site Scripting
CVE-2019-15112 2024-11-21 13:28 2019-08-21 Show GitHub Exploit DB Packet Storm
223690 9.8 CRITICAL
Network
wp_front_end_profile_project wp_front_end_profile The wp-front-end-profile plugin before 0.2.2 for WordPress has a privilege escalation issue. NVD-CWE-noinfo
CVE-2019-15111 2024-11-21 13:28 2019-08-21 Show GitHub Exploit DB Packet Storm