Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
244041 7.5 危険 aj square - AJ Matrix DNA の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2779 2012-06-26 16:10 2009-08-17 Show GitHub Exploit DB Packet Storm
244042 4.3 警告 garagesalesjunkie - GarageSales Script の visitor/view.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2778 2012-06-26 16:10 2009-08-14 Show GitHub Exploit DB Packet Storm
244043 7.5 危険 desiscripts - Desi Short URL Script の index.php における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2009-2642 2012-06-26 16:10 2009-07-28 Show GitHub Exploit DB Packet Storm
244044 9.3 危険 日本エイサー - acerctrl.ocx の Acer LunchApp ActiveX コントロールにおける任意のコマンドを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2009-2627 2012-06-26 16:10 2009-08-19 Show GitHub Exploit DB Packet Storm
244045 5 警告 Firebird Project - Firebird SQL の fbserver.exe の src/remote/server.cpp におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2009-2620 2012-06-26 16:10 2009-07-29 Show GitHub Exploit DB Packet Storm
244046 7.5 危険 datachecknh - DataCheck Solutions V-SpacePal の login.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2619 2012-06-26 16:10 2009-07-27 Show GitHub Exploit DB Packet Storm
244047 9.3 危険 baofeng - BaoFeng Storm の medialib.dll におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-2617 2012-06-26 16:10 2009-07-27 Show GitHub Exploit DB Packet Storm
244048 7.5 危険 datachecknh - DataCheck Solutions SitePal の z_admin_login.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2616 2012-06-26 16:10 2009-07-27 Show GitHub Exploit DB Packet Storm
244049 4.3 警告 datachecknh - DataCheck Solutions SitePal におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2615 2012-06-26 16:10 2009-07-27 Show GitHub Exploit DB Packet Storm
244050 7.5 危険 datachecknh - DataCheck Solutions LinkPal の z_admin_login.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2614 2012-06-26 16:10 2009-07-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 4, 2026, 4:17 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
219571 8.8 HIGH
Network
twinkletoessoftware booked phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary Web/custom-favicon.php PHP code, because Presenters/Admin/ManageThemePresent… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2019-9581 2024-11-21 13:51 2019-03-6 Show GitHub Exploit DB Packet Storm
219572 7.5 HIGH
Network
yubico libu2f-host In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back to the device. CWE-908
 Use of Uninitialized Resource
CVE-2019-9578 2024-11-21 13:51 2019-03-6 Show GitHub Exploit DB Packet Storm
219573 5.3 MEDIUM
Network
sagemcom f\@st_5260_firmware Sagemcom F@st 5260 routers using firmware version 0.4.39, in WPA mode, default to using a PSK that is generated from a 2-part wordlist of known values and a nonce with insufficient entropy. The numbe… CWE-331
 Insufficient Entropy
CVE-2019-9555 2024-11-21 13:51 2019-03-6 Show GitHub Exploit DB Packet Storm
219574 5.5 MEDIUM
Local
linux
debian
redhat
opensuse
canonical
linux_kernel
debian_linux
enterprise_linux
leap
ubuntu_linux
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers to exploit kernel NULL pointer dereferences on non-SM… CWE-476
 NULL Pointer Dereference
CVE-2019-9213 2024-11-21 13:51 2019-03-6 Show GitHub Exploit DB Packet Storm
219575 6.1 MEDIUM
Network
adenion blog2social The Blog2Social plugin before 5.0.3 for WordPress allows wp-admin/admin.php?page=blog2social-ship XSS. CWE-79
Cross-site Scripting
CVE-2019-9576 2024-11-21 13:51 2019-03-6 Show GitHub Exploit DB Packet Storm
219576 6.1 MEDIUM
Network
quizandsurveymaster quiz_and_survey_master The Quiz And Survey Master plugin 6.0.4 for WordPress allows wp-admin/admin.php?page=mlw_quiz_results quiz_id XSS. CWE-79
Cross-site Scripting
CVE-2019-9575 2024-11-21 13:51 2019-03-6 Show GitHub Exploit DB Packet Storm
219577 7.5 HIGH
Network
mishubd wp_human_resource_management The WP Human Resource Management plugin before 2.2.6 for WordPress does not ensure that a leave modification occurs in the context of the Administrator or HR Manager role. CWE-862
 Missing Authorization
CVE-2019-9574 2024-11-21 13:51 2019-03-6 Show GitHub Exploit DB Packet Storm
219578 7.5 HIGH
Network
mishubd wp_human_resource_management The WP Human Resource Management plugin before 2.2.6 for WordPress mishandles leave applications. CWE-19
 Data Processing Errors
CVE-2019-9573 2024-11-21 13:51 2019-03-6 Show GitHub Exploit DB Packet Storm
219579 7.2 HIGH
Network
schoolcms schoolcms SchoolCMS version 2.3.1 allows file upload via the theme upload feature at admin.php?m=admin&c=theme&a=upload by using the .zip extension along with the _Static substring, changing the Content-Type t… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2019-9572 2024-11-21 13:51 2019-03-5 Show GitHub Exploit DB Packet Storm
219580 4.8 MEDIUM
Network
yzmcms yzmcms An issue was discovered in YzmCMS 5.2.0. It has XSS via the bottom text field to the admin/system_manage/save.html URI, related to the site_code parameter. CWE-79
Cross-site Scripting
CVE-2019-9570 2024-11-21 13:51 2019-03-5 Show GitHub Exploit DB Packet Storm