Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
244031 4.3 警告 Achievo - Achievo におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2733 2012-06-26 16:10 2009-10-11 Show GitHub Exploit DB Packet Storm
244032 7.8 危険 Digium - 複数の Asterisk 製品における SIP チャネルドライバにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2009-2726 2012-06-26 16:10 2009-08-12 Show GitHub Exploit DB Packet Storm
244033 5 警告 Django Software Foundation - Django の core/servers/basehttp.py の Admin メディアハンドラにおける任意のファイルを読まれる脆弱性 CWE-22
パス・トラバーサル
CVE-2009-2659 2012-06-26 16:10 2009-08-4 Show GitHub Exploit DB Packet Storm
244034 5 警告 Digium - Asterisk Open Source の main/rtp.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2009-2651 2012-06-26 16:10 2009-07-27 Show GitHub Exploit DB Packet Storm
244035 4.7 警告 FreeBSD - FreeBSD の IATA (ata) ドライバにおけるサービス運用妨害 (DoS) の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-2649 2012-06-26 16:10 2009-07-30 Show GitHub Exploit DB Packet Storm
244036 5 警告 flashden - FlashDen Guestbook における設定情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-2648 2012-06-26 16:10 2009-07-30 Show GitHub Exploit DB Packet Storm
244037 10 危険 DELL EMC (旧 EMC Corporation) - ISM Portmapper サービスの librpc.dll の認証機能における整数符号化エラーの脆弱性 CWE-189
数値処理の問題
CVE-2009-2754 2012-06-26 16:10 2010-03-5 Show GitHub Exploit DB Packet Storm
244038 9.3 危険 ditcms - dit.cms におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-2784 2012-06-26 16:10 2009-08-17 Show GitHub Exploit DB Packet Storm
244039 6 警告 Arab Portal - Arab Portal の forum.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2781 2012-06-26 16:10 2009-08-17 Show GitHub Exploit DB Packet Storm
244040 4.3 警告 68classifieds - 68 Classifieds におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2780 2012-06-26 16:10 2009-08-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 4, 2026, 4:17 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
219541 9.8 CRITICAL
Network
phpshe phpshe PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php. CWE-89
SQL Injection
CVE-2019-9626 2024-11-21 13:51 2019-03-8 Show GitHub Exploit DB Packet Storm
219542 8.8 HIGH
Network
directadmin directadmin JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account. CWE-352
 Origin Validation Error
CVE-2019-9625 2024-11-21 13:51 2019-03-8 Show GitHub Exploit DB Packet Storm
219543 7.8 HIGH
Local
webmin webmin Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to upload a crafted .cgi file via the /updown/upload.cgi URI. CWE-269
 Improper Privilege Management
CVE-2019-9624 2024-11-21 13:51 2019-03-7 Show GitHub Exploit DB Packet Storm
219544 9.8 CRITICAL
Network
fengoffice feng_office Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2019-9623 2024-11-21 13:51 2019-03-7 Show GitHub Exploit DB Packet Storm
219545 4.3 MEDIUM
Network
ebrigade ebrigade eBrigade through 4.5 allows Arbitrary File Download via ../ directory traversal in the showfile.php file parameter, as demonstrated by reading the user-data/save/backup.sql file. CWE-22
Path Traversal
CVE-2019-9622 2024-11-21 13:51 2019-03-7 Show GitHub Exploit DB Packet Storm
219546 8.8 HIGH
Network
ofcms_project ofcms An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/uedito… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2019-9617 2024-11-21 13:51 2019-03-7 Show GitHub Exploit DB Packet Storm
219547 7.2 HIGH
Network
ofcms_project ofcms An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/uedito… CWE-706
 Use of Incorrectly-Resolved Name or Reference
CVE-2019-9616 2024-11-21 13:51 2019-03-7 Show GitHub Exploit DB Packet Storm
219548 7.2 HIGH
Network
ofcms_project ofcms An issue was discovered in OFCMS before 1.1.3. It allows admin/system/generate/create?sql= SQL injection, related to SystemGenerateController.java. CWE-89
SQL Injection
CVE-2019-9615 2024-11-21 13:51 2019-03-7 Show GitHub Exploit DB Packet Storm
219549 8.8 HIGH
Network
ofcms_project ofcms An issue was discovered in OFCMS before 1.1.3. A command execution vulnerability exists via a template file with '<#assign ex="freemarker.template.utility.Execute"?new()> ${ ex("' followed by the com… CWE-74
Injection
CVE-2019-9614 2024-11-21 13:51 2019-03-7 Show GitHub Exploit DB Packet Storm
219550 7.2 HIGH
Network
ofcms_project ofcms An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/uedito… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2019-9613 2024-11-21 13:51 2019-03-7 Show GitHub Exploit DB Packet Storm