Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 25, 2026, 2:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230081 7.5 危険 virtual design studios - Virtual Design Studio vlbook の include/global.inc.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-2073 2012-12-20 18:52 2008-05-5 Show GitHub Exploit DB Packet Storm
230082 4.3 警告 virtual design studios - Virtual Design Studio vlbook の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2072 2012-12-20 18:52 2008-05-5 Show GitHub Exploit DB Packet Storm
230083 4.3 警告 WordPress.org - WordPress におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2068 2012-12-20 18:52 2008-04-25 Show GitHub Exploit DB Packet Storm
230084 7.5 危険 YourFreeWorld.com - YourFreeWorld Jokes Site Script の jokes.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2065 2012-12-20 18:52 2008-05-2 Show GitHub Exploit DB Packet Storm
230085 10 危険 phpgedview - PhpGedView における脆弱性 CWE-noinfo
情報不足
CVE-2008-2064 2012-12-20 18:52 2008-05-2 Show GitHub Exploit DB Packet Storm
230086 4.3 警告 softpedia - Softpedia SiteXS CMS の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2046 2012-12-20 18:52 2008-05-1 Show GitHub Exploit DB Packet Storm
230087 5 警告 SugarCRM - SugarCRM Sugar Community Edition における絶対パストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-2045 2012-12-20 18:52 2008-04-10 Show GitHub Exploit DB Packet Storm
230088 6.5 警告 turnkey solutions - Turnkey Web Tools SunShop Shopping Cart の admin/adminindex.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2038 2012-12-20 18:52 2008-04-30 Show GitHub Exploit DB Packet Storm
230089 7.5 危険 Mike Jolley - WordPress 用の Download Monitor プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2034 2012-12-20 18:52 2008-04-30 Show GitHub Exploit DB Packet Storm
230090 7.5 危険 WordPress.org - WordPress 用の Spreadsheet プラグインの ss_load.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1982 2012-12-20 18:52 2008-04-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 25, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
223751 9.8 CRITICAL
Network
gitlab gitlab Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal. CWE-22
Path Traversal
CVE-2019-19088 2024-11-21 13:34 2020-01-4 Show GitHub Exploit DB Packet Storm
223752 4.3 MEDIUM
Network
gitlab gitlab Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 2 of 2). CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2019-19087 2024-11-21 13:34 2020-01-4 Show GitHub Exploit DB Packet Storm
223753 4.3 MEDIUM
Network
gitlab gitlab Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 1 of 2). CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2019-19086 2024-11-21 13:34 2020-01-4 Show GitHub Exploit DB Packet Storm
223754 6.5 MEDIUM
Adjacent
huawei p30_firmware HUAWEI P30 smart phones with versions earlier than 10.0.0.166(C00E66R1P11) have an information leak vulnerability. An attacker could send specific command in the local area network (LAN) to exploit t… NVD-CWE-noinfo
CVE-2019-19441 2024-11-21 13:34 2020-01-4 Show GitHub Exploit DB Packet Storm
223755 8.1 HIGH
Network
xmlblueprint xmlblueprint XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is: Arbitrary File Read when an XML File is validated. The component is: XML Validate function. The attack vect… CWE-611
XXE
CVE-2019-19032 2024-11-21 13:34 2019-12-31 Show GitHub Exploit DB Packet Storm
223756 8.1 HIGH
Network
edit-xml easy_xml_editor Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is: Arbitrary File Read and DoS by consuming resources. The component is: XML Parsing. The attack vector is: S… CWE-611
XXE
CVE-2019-19031 2024-11-21 13:34 2019-12-31 Show GitHub Exploit DB Packet Storm
223757 7.8 HIGH
Local
tinywall tinywall Unsafe usage of .NET deserialization in Named Pipe message processing allows privilege escalation to NT AUTHORITY\SYSTEM for a local attacker. Affected product is TinyWall, all versions up to and inc… CWE-502
 Deserialization of Untrusted Data
CVE-2019-19470 2024-11-21 13:34 2019-12-31 Show GitHub Exploit DB Packet Storm
223758 5.4 MEDIUM
Network
jetbrains ktor JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting. CWE-74
Injection
CVE-2019-19389 2024-11-21 13:34 2019-12-27 Show GitHub Exploit DB Packet Storm
223759 9.8 CRITICAL
Network
huawei m5_lite_10_firmware M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability. Due to the input validation logic is incorrect, an attacker can exploit this vulnerability to modify th… CWE-20
 Improper Input Validation 
CVE-2019-19398 2024-11-21 13:34 2019-12-27 Show GitHub Exploit DB Packet Storm
223760 5.4 MEDIUM
Network
cridio listingpro The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Good For field on the new listing submit page. CWE-79
Cross-site Scripting
CVE-2019-19542 2024-11-21 13:34 2019-12-27 Show GitHub Exploit DB Packet Storm