Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 23, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230151 4.3 警告 SmarterTools Inc. - SmarterTools SmarterMail Enterprise におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0872 2012-12-20 18:34 2008-02-21 Show GitHub Exploit DB Packet Storm
230152 7.5 危険 woltlab - WoltLab Burning Board の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0857 2012-12-20 18:34 2008-02-20 Show GitHub Exploit DB Packet Storm
230153 7.5 危険 WordPress.org - WordPress 用の Dean Logan WP-People プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0845 2012-12-20 18:34 2008-02-20 Show GitHub Exploit DB Packet Storm
230154 6.4 警告 statcountex - StatCounteX における重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-0843 2012-12-20 18:34 2008-02-20 Show GitHub Exploit DB Packet Storm
230155 4.4 警告 publicwarehouse - Public Warehouse LightBlog の view_member.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0840 2012-12-20 18:34 2008-02-20 Show GitHub Exploit DB Packet Storm
230156 4.3 警告 ソフォス - Sophos ES1000 および ES4000 Email Security Appliance の Web の管理インターフェースにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0838 2012-12-20 18:34 2008-02-20 Show GitHub Exploit DB Packet Storm
230157 7.5 危険 simple cms - Simple CMS の indexen.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0835 2012-12-20 18:34 2008-02-20 Show GitHub Exploit DB Packet Storm
230158 7.5 危険 PHPNUKE - PHP-Nuke の Books モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0827 2012-12-20 18:34 2008-02-19 Show GitHub Exploit DB Packet Storm
230159 3.6 注意 scribe - Scribe の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0822 2012-12-20 18:34 2008-02-19 Show GitHub Exploit DB Packet Storm
230160 3.6 注意 plutostatus - PlutoStatus Locator の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0819 2012-12-20 18:34 2008-02-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 23, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
223301 5.3 MEDIUM
Network
icegram email_subscribers_\&_newsletters The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure. CWE-862
 Missing Authorization
CVE-2019-19985 2024-11-21 13:35 2019-12-26 Show GitHub Exploit DB Packet Storm
223302 6.3 MEDIUM
Network
icegram email_subscribers_\&_newsletters The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns. CWE-863
 Incorrect Authorization
CVE-2019-19984 2024-11-21 13:35 2019-12-26 Show GitHub Exploit DB Packet Storm
223303 4.3 MEDIUM
Network
fastvelocity minify In the WordPress plugin, Fast Velocity Minify before 2.7.7, the full web root path to the running WordPress application can be discovered. In order to exploit this vulnerability, FVM Debug Mode needs… CWE-200
Information Exposure
CVE-2019-19983 2024-11-21 13:35 2019-12-26 Show GitHub Exploit DB Packet Storm
223304 5.3 MEDIUM
Network
icegram email_subscribers_\&_newsletters The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send… CWE-287
Improper Authentication
CVE-2019-19982 2024-11-21 13:35 2019-12-26 Show GitHub Exploit DB Packet Storm
223305 5.4 MEDIUM
Network
icegram email_subscribers_\&_newsletters The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings. CWE-352
 Origin Validation Error
CVE-2019-19981 2024-11-21 13:35 2019-12-26 Show GitHub Exploit DB Packet Storm
223306 4.3 MEDIUM
Network
icegram email_subscribers_\&_newsletters The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administra… NVD-CWE-noinfo
CVE-2019-19980 2024-11-21 13:35 2019-12-26 Show GitHub Exploit DB Packet Storm
223307 8.8 HIGH
Network
wp_maintenance_project wp_maintenance A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance mode and inject malicious code affecting site visitors. There was CSRF with re… CWE-352
CWE-79
 Origin Validation Error
Cross-site Scripting
CVE-2019-19979 2024-11-21 13:35 2019-12-26 Show GitHub Exploit DB Packet Storm
223308 9.8 CRITICAL
Network
libesmtp_project libesmtp libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read. CWE-125
Out-of-bounds Read
CVE-2019-19977 2024-11-21 13:35 2019-12-26 Show GitHub Exploit DB Packet Storm
223309 7.5 HIGH
Network
upc connect_box_eurodocsis_firmware The Administration page on Connect Box EuroDOCSIS 3.0 Voice Gateway CH7465LG-NCIP-6.12.18.25-2p6-NOSH devices accepts a cleartext password in a POST request on port 80, as demonstrated by the Passwor… CWE-319
Cleartext Transmission of Sensitive Information
CVE-2019-19967 2024-11-21 13:35 2019-12-26 Show GitHub Exploit DB Packet Storm
223310 5.3 MEDIUM
Network
wolfssl wolfssl An issue was discovered in wolfSSL before 4.3.0 in a non-default configuration where DSA is enabled. DSA signing uses the BEEA algorithm during modular inversion of the nonce, leading to a side-chann… NVD-CWE-Other
CVE-2019-19963 2024-11-21 13:35 2019-12-25 Show GitHub Exploit DB Packet Storm