Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 17, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229871 4 警告 phpcoupon - phpCoupon の Billing Control Panel における Premium Member ステイタスを取得される脆弱性 - CVE-2007-4143 2012-12-20 18:33 2007-08-3 Show GitHub Exploit DB Packet Storm
229872 4.3 警告 WordPress.org - WordPress の Temporary Uploads 編集機能におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-4139 2012-12-20 18:33 2007-08-3 Show GitHub Exploit DB Packet Storm
229873 6.5 警告 レッドハット - Red Hat Network Satellite Server における任意のコードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2007-4132 2012-12-20 18:33 2007-08-29 Show GitHub Exploit DB Packet Storm
229874 7.5 危険 suskunduygular - SuskunDuygular Uyelik Sistemi の unuttum.asp における SQL インジェクションの脆弱性 - CVE-2007-4114 2012-12-20 18:33 2007-07-31 Show GitHub Exploit DB Packet Storm
229875 7.5 危険 phpmyforum - phpMyForum の editpost.php における SQL インジェクションの脆弱性 - CVE-2007-4107 2012-12-20 18:33 2007-06-7 Show GitHub Exploit DB Packet Storm
229876 4.3 警告 sblog - sBlog の search.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-4102 2012-12-20 18:33 2007-07-31 Show GitHub Exploit DB Packet Storm
229877 5.8 警告 The Tor Project - Tor における重要な情報を取得される脆弱性 - CVE-2007-4099 2012-12-20 18:33 2007-07-30 Show GitHub Exploit DB Packet Storm
229878 5.8 警告 The Tor Project - Tor における任意のストリームへセルを挿入される脆弱性 - CVE-2007-4098 2012-12-20 18:33 2007-07-30 Show GitHub Exploit DB Packet Storm
229879 6.4 警告 The Tor Project - Tor における仕様に反して重要な情報を取得される脆弱性 - CVE-2007-4097 2012-12-20 18:33 2007-07-30 Show GitHub Exploit DB Packet Storm
229880 5.8 警告 The Tor Project - Tor におけるバッファオーバーフローの脆弱性 - CVE-2007-4096 2012-12-20 18:33 2007-07-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 17, 2026, 4:15 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
223201 5.4 MEDIUM
Network
hitachienergy esoms For ABB eSOMS versions 4.0 to 6.0.2, the X-XSS-Protection HTTP response header is not set in responses from the web server. For older web browser not supporting Content Security Policy, this might in… CWE-79
Cross-site Scripting
CVE-2019-19002 2024-11-21 13:33 2020-04-3 Show GitHub Exploit DB Packet Storm
223202 6.5 MEDIUM
Network
hitachienergy esoms For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an attacker can frame parts of the applicat… CWE-1021
 Improper Restriction of Rendered UI Layers or Frames
CVE-2019-19001 2024-11-21 13:33 2020-04-3 Show GitHub Exploit DB Packet Storm
223203 6.5 MEDIUM
Network
hitachienergy esoms For ABB eSOMS 4.0 to 6.0.3, the Cache-Control and Pragma HTTP header(s) have not been properly configured within the application response. This can potentially allow browsers and proxies to cache sen… CWE-200
Information Exposure
CVE-2019-19000 2024-11-21 13:33 2020-04-3 Show GitHub Exploit DB Packet Storm
223204 4.3 MEDIUM
Network
harriscomputer ormed_mis Harris Ormed Self Service before 2019.1.4 allows an authenticated user to view W-2 forms belonging to other users via an arbitrary empNo value to the ORMEDMIS/Data/PY/T4W2Service.svc/RetrieveW2Entrie… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2019-18626 2024-11-21 13:33 2020-03-26 Show GitHub Exploit DB Packet Storm
223205 7.5 HIGH
Network
bloq univalue UniValue::read() in UniValue before 1.0.5 allow attackers to cause a denial of service (the class internal data reaches an inconsistent state) via input data that triggers an error. CWE-674
 Uncontrolled Recursion
CVE-2019-18936 2024-11-21 13:33 2020-03-21 Show GitHub Exploit DB Packet Storm
223206 6.1 MEDIUM
Network
squid-cache
debian
canonical
opensuse
squid
debian_linux
ubuntu_linux
leap
Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi. CWE-74
Injection
CVE-2019-18860 2024-11-21 13:33 2020-03-21 Show GitHub Exploit DB Packet Storm
223207 9.8 CRITICAL
Network
sparkdevnetwork rock_rms Rock RMS before 1.8.6 mishandles vCard access control within the People/GetVCard/REST controller. NVD-CWE-noinfo
CVE-2019-18641 2024-11-21 13:33 2020-03-21 Show GitHub Exploit DB Packet Storm
223208 7.5 HIGH
Network
suitecrm suitecrm SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 mishandles API access tokens and credentials. CWE-522
 Insufficiently Protected Credentials
CVE-2019-18785 2024-11-21 13:33 2020-03-20 Show GitHub Exploit DB Packet Storm
223209 5.3 MEDIUM
Network
salesagility suitecrm SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 does not correctly implement the .htaccess protection mechanism. NVD-CWE-Other
CVE-2019-18782 2024-11-21 13:33 2020-03-20 Show GitHub Exploit DB Packet Storm
223210 7.8 HIGH
Local
claranova adaware_antivirus Adaware antivirus 12.6.1005.11662 and 12.7.1055.0 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junction to restore a malicious DLL from quarantine into … NVD-CWE-noinfo
CVE-2019-18979 2024-11-21 13:33 2020-03-19 Show GitHub Exploit DB Packet Storm