Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 19, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230771 7.8 危険 リアルネットワークス - RealNetworks RealPlayer におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2497 2012-12-20 18:19 2007-05-3 Show GitHub Exploit DB Packet Storm
230772 7.5 危険 postnuke software foundation - PostNuke 用の v4bJournal モジュールにおける SQL インジェクションの脆弱性 - CVE-2007-2492 2012-12-20 18:19 2007-05-3 Show GitHub Exploit DB Packet Storm
230773 7.2 危険 VMware - EMC VMware Workstation などの PIIX4 電源管理サブシステムにおける任意のメモリ領域に書き込まれる脆弱性 - CVE-2007-2491 2012-12-20 18:19 2007-05-3 Show GitHub Exploit DB Packet Storm
230774 7.5 危険 ruben boelinger - WordPress 用の myflash プラグインにおける PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2485 2012-12-20 18:19 2007-05-3 Show GitHub Exploit DB Packet Storm
230775 6.8 警告 ruben boelinger - WordPress 用の wp-Table プラグインにおける PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2484 2012-12-20 18:19 2007-05-3 Show GitHub Exploit DB Packet Storm
230776 6.8 警告 ruben boelinger - WordPress 用の wp-Table プラグインにおけるディレクトリトラバーサルの脆弱性 - CVE-2007-2483 2012-12-20 18:19 2007-05-3 Show GitHub Exploit DB Packet Storm
230777 6.8 警告 ruben boelinger - WordPress 用の wordTube プラグインにおけるディレクトリトラバーサルの脆弱性 - CVE-2007-2482 2012-12-20 18:19 2007-05-3 Show GitHub Exploit DB Packet Storm
230778 6.8 警告 ruben boelinger - WordPress 用の wordTube プラグインの wordtube-button.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2481 2012-12-20 18:19 2007-05-3 Show GitHub Exploit DB Packet Storm
230779 7.5 危険 turnkey web tools - Turnkey Web Tools SunShop Shopping Cart における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2474 2012-12-20 18:19 2007-05-2 Show GitHub Exploit DB Packet Storm
230780 4.3 警告 sendcard - Sendcard の sendcard.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-2472 2012-12-20 18:19 2007-05-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 19, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313421 7.8 HIGH
Local
google android In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no additional execution privi… CWE-787
 Out-of-bounds Write
CVE-2024-44094 2024-09-18 22:37 2024-09-14 Show GitHub Exploit DB Packet Storm
313422 7.5 HIGH
Network
gitlab gitlab ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allows denial of s… CWE-1333
 Inefficient Regular Expression Complexity
CVE-2024-2800 2024-09-18 21:42 2024-08-8 Show GitHub Exploit DB Packet Storm
313423 5.4 MEDIUM
Network
gitlab gitlab A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 prior 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2. When view… CWE-79
Cross-site Scripting
CVE-2024-4207 2024-09-18 21:41 2024-08-8 Show GitHub Exploit DB Packet Storm
313424 8.8 HIGH
Network
google
microsoft
chrome
edge_chromium
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CWE-787
 Out-of-bounds Write
CVE-2024-7965 2024-09-18 21:40 2024-08-22 Show GitHub Exploit DB Packet Storm
313425 8.8 HIGH
Network
redhat openshift_data_science
openshift_ai
A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models within the same namespace. When deploying AI models, the UI provides the option … NVD-CWE-Other
CVE-2024-7557 2024-09-18 16:15 2024-08-12 Show GitHub Exploit DB Packet Storm
313426 6.7 MEDIUM
Local
microsoft windows_10_1507
windows_10_1809
windows_server_2019
windows_server_2022
windows_11_21h2
windows_10_21h2
windows_11_22h2
windows_10_22h2
windows_11_23h2
windows_server_2022_…
Summary: Microsoft was notified that an elevation of privilege vulnerability exists in Windows based systems supporting Virtualization Based Security (VBS), including a subset of Azure Virtual Machin… NVD-CWE-Other
CVE-2024-21302 2024-09-18 09:15 2024-08-8 Show GitHub Exploit DB Packet Storm
313427 7.5 HIGH
Network
containers aardvark-dns A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open… NVD-CWE-noinfo
CVE-2024-8418 2024-09-18 05:15 2024-09-5 Show GitHub Exploit DB Packet Storm
313428 4.3 MEDIUM
Network
imagerecycle imagerecycle_pdf_\&_image_compression The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.14. This is due to missing or incorrect nonce valid… CWE-352
 Origin Validation Error
CVE-2024-8120 2024-09-18 05:07 2024-08-24 Show GitHub Exploit DB Packet Storm
313429 4.8 MEDIUM
Network
cleversoft clever_addons_for_elementor Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CleverSoft Clever Addons for Elementor allows Stored XSS.This issue affects Clever Addons … CWE-79
Cross-site Scripting
CVE-2024-43324 2024-09-18 05:04 2024-08-18 Show GitHub Exploit DB Packet Storm
313430 6.1 MEDIUM
Network
orbisius child_theme_creator Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Svetoslav Marinov (Slavi) Child Theme Creator allows Reflected XSS.This issue affects Chil… CWE-79
Cross-site Scripting
CVE-2024-43276 2024-09-18 05:00 2024-08-18 Show GitHub Exploit DB Packet Storm