Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 24, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229761 4.3 警告 telephone - Telephone Directory 2008 の edit1.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2677 2012-12-20 18:52 2008-06-12 Show GitHub Exploit DB Packet Storm
229762 4.3 警告 softcomplex - PHP Image Gallery の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2675 2012-12-20 18:52 2008-06-12 Show GitHub Exploit DB Packet Storm
229763 7.5 危険 Powie - Powie pNews の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2673 2012-12-20 18:52 2008-06-12 Show GitHub Exploit DB Packet Storm
229764 7.5 危険 y-blog - yBlog における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2669 2012-12-20 18:52 2008-06-11 Show GitHub Exploit DB Packet Storm
229765 4.3 警告 y-blog - yBlog におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2668 2012-12-20 18:52 2008-06-11 Show GitHub Exploit DB Packet Storm
229766 7.5 危険 smeweb - SMEWeb の catalog.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2652 2012-12-20 18:52 2008-06-10 Show GitHub Exploit DB Packet Storm
229767 4.3 警告 smeweb - SMEWeb における任意の Web スクリプトまたは HTML を挿入される脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2644 2012-12-20 18:52 2008-06-10 Show GitHub Exploit DB Packet Storm
229768 7.5 危険 theflashblog - FlashBlog の php/leer_comentarios.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2572 2012-12-20 18:52 2008-06-6 Show GitHub Exploit DB Packet Storm
229769 4.3 警告 samtodo - SamTodo の dsp_main.php などにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2563 2012-12-20 18:52 2008-06-6 Show GitHub Exploit DB Packet Storm
229770 6.5 警告 powerphlogger - PowerPhlogger の edCss.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2562 2012-12-20 18:52 2008-06-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 25, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
224061 5.5 MEDIUM
Local
virglrenderer_project
redhat
opensuse
debian
virglrenderer
enterprise_linux
leap
debian_linux
A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_RES… CWE-787
 Out-of-bounds Write
CVE-2019-18391 2024-11-21 13:33 2019-12-24 Show GitHub Exploit DB Packet Storm
224062 7.1 HIGH
Local
virglrenderer_project
redhat
opensuse
debian
virglrenderer
enterprise_linux
leap
debian_linux
An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_BLIT commands. CWE-125
Out-of-bounds Read
CVE-2019-18390 2024-11-21 13:33 2019-12-24 Show GitHub Exploit DB Packet Storm
224063 7.8 HIGH
Local
virglrenderer_project
redhat
opensuse
debian
virglrenderer
enterprise_linux
leap
debian_linux
A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service, or QEMU guest-to-… CWE-787
 Out-of-bounds Write
CVE-2019-18389 2024-11-21 13:33 2019-12-24 Show GitHub Exploit DB Packet Storm
224064 5.5 MEDIUM
Local
virglrenderer_project
opensuse
debian
virglrenderer
leap
debian_linux
A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via malformed commands. CWE-476
 NULL Pointer Dereference
CVE-2019-18388 2024-11-21 13:33 2019-12-24 Show GitHub Exploit DB Packet Storm
224065 6.1 MEDIUM
Network
lansweeper lansweeper The web console in Lansweeper 7.2.105.2 has XSS via the URL path. Product vulnerability has been fixed and disclosed within changelog as of 02 Dec 2019. CWE-79
Cross-site Scripting
CVE-2019-18955 2024-11-21 13:33 2019-12-20 Show GitHub Exploit DB Packet Storm
224066 4.9 MEDIUM
Network
arista cloudvision_portal In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially leading to user passwo… CWE-312
CWE-522
 Cleartext Storage of Sensitive Information
 Insufficiently Protected Credentials
CVE-2019-18615 2024-11-21 13:33 2019-12-20 Show GitHub Exploit DB Packet Storm
224067 6.1 MEDIUM
Network
zohocorp manageengine_adselfservice_plus An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent to a specified extern… CWE-601
Open Redirect
CVE-2019-18781 2024-11-21 13:33 2019-12-19 Show GitHub Exploit DB Packet Storm
224068 7.5 HIGH
Network
abb pb610_panel_builder_600 The HMISimulator component of ABB PB610 Panel Builder 600 uses the readFile/writeFile interface to manipulate the work file. Path configuration in PB610 HMISimulator versions 2.8.0.424 and earlier po… NVD-CWE-noinfo
CVE-2019-18997 2024-11-21 13:33 2019-12-19 Show GitHub Exploit DB Packet Storm
224069 7.8 HIGH
Local
abb pb610_panel_builder_600 Path settings in HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier accept DLLs outside of the program directory, potentially allowing an attacker with access to the lo… CWE-426
 Untrusted Search Path
CVE-2019-18996 2024-11-21 13:33 2019-12-19 Show GitHub Exploit DB Packet Storm
224070 5.3 MEDIUM
Network
abb pb610_panel_builder_600 The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests, exposing HMISimulator to denial of service via c… CWE-20
 Improper Input Validation 
CVE-2019-18995 2024-11-21 13:33 2019-12-19 Show GitHub Exploit DB Packet Storm