Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 19, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
244961 7.5 危険 Exiv2 project - exiv2 library の exif.cpp における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2007-6353 2012-06-26 15:54 2007-12-19 Show GitHub Exploit DB Packet Storm
244962 7.5 危険 aurora - aurora framework における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6345 2012-06-26 15:54 2007-12-13 Show GitHub Exploit DB Packet Storm
244963 7.5 危険 david castro - Apache HTTP Server の David Castro AuthCAS.pm における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6342 2012-06-26 15:54 2007-12-13 Show GitHub Exploit DB Packet Storm
244964 7.5 危険 avs media - Online Media Technologies AVSMJPEGFILE.DLL の特定の ActiveX コントロールにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-6327 2012-06-26 15:54 2007-12-13 Show GitHub Exploit DB Packet Storm
244965 6.8 警告 fastpublish - Fastpublish CMS の adminbereich/designconfig.php における PHP リモートファイルインクルージョンの脆弱性 CWE-20
CWE-94
CVE-2007-6325 2012-06-26 15:54 2007-12-13 Show GitHub Exploit DB Packet Storm
244966 6.8 警告 city writer - CityWriter の head.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-6324 2012-06-26 15:54 2007-12-13 Show GitHub Exploit DB Packet Storm
244967 4.3 警告 Drupal - Drupal の Feature モジュールにおけるクロスサイトリクエストフォージェリ攻撃を誘発する脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2007-6320 2012-06-26 15:54 2007-12-5 Show GitHub Exploit DB Packet Storm
244968 7.5 危険 falt4 cms - Falt4Extreme RC4 の index.php および admin/index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6311 2012-06-26 15:54 2007-12-11 Show GitHub Exploit DB Packet Storm
244969 4.3 警告 falt4 cms - Falt4Extreme RC4 におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6310 2012-06-26 15:54 2007-12-11 Show GitHub Exploit DB Packet Storm
244970 5 警告 fusion news - Fusion News におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2007-6300 2012-06-26 15:54 2007-12-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 20, 2026, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
220021 5.6 MEDIUM
Local
linux
fedoraproject
canonical
redhat
linux_kernel
fedora
ubuntu_linux
enterprise_linux
enterprise_linux_eus
enterprise_linux_server_tus
enterprise_linux_server_aus
enterprise_linux_for_real_time
enterprise_linux_…
A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1 guest could access L0's APIC register values via … - CVE-2019-3887 2024-11-21 13:42 2019-04-10 Show GitHub Exploit DB Packet Storm
220022 6.1 MEDIUM
Local
samba
fedoraproject
synology
samba
fedora
diskstation_manager
directory_server
router_manager
skynas_firmware
vs960hd_firmware
A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the insta… CWE-276
Incorrect Default Permissions 
CVE-2019-3870 2024-11-21 13:42 2019-04-10 Show GitHub Exploit DB Packet Storm
220023 5.3 MEDIUM
Network
vmware
debian
spring_security
debian_linux
Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a … CWE-330
 Use of Insufficiently Random Values
CVE-2019-3795 2024-11-21 13:42 2019-04-10 Show GitHub Exploit DB Packet Storm
220024 5.4 MEDIUM
Adjacent
redhat
opensuse
fedoraproject
libvirt
leap
fedora
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing u… - CVE-2019-3886 2024-11-21 13:42 2019-04-5 Show GitHub Exploit DB Packet Storm
220025 7.5 HIGH
Network
pivotal_software concourse Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can carry a SQL injection payload to the Concourse serv… CWE-89
SQL Injection
CVE-2019-3792 2024-11-21 13:42 2019-04-2 Show GitHub Exploit DB Packet Storm
220026 7.5 HIGH
Network
microfocus content_manager An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Manager 9.1, 9.2, and 9.3 when configured to use the ADFS authentication method. Th… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2019-3489 2024-11-21 13:42 2019-04-2 Show GitHub Exploit DB Packet Storm
220027 6.3 MEDIUM
Network
redhat openshift_container_platform A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X-Frame-Options and CSRF protections. If not otherw… - CVE-2019-3876 2024-11-21 13:42 2019-04-2 Show GitHub Exploit DB Packet Storm
220028 7.5 HIGH
Network
gnu
fedoraproject
opensuse
gnutls
fedora
leap
It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages. CWE-824
 Access of Uninitialized Pointer
CVE-2019-3836 2024-11-21 13:42 2019-04-2 Show GitHub Exploit DB Packet Storm
220029 8.1 HIGH
Network
dell emc_networking_os10 Dell EMC Networking OS10 versions prior to 10.4.3 contain a cryptographic key vulnerability due to an underlying application using undocumented, pre-installed X.509v3 key/certificate pairs. An unauth… CWE-798
 Use of Hard-coded Credentials
CVE-2019-3710 2024-11-21 13:42 2019-03-29 Show GitHub Exploit DB Packet Storm
220030 7.2 HIGH
Network
redhat ansible_tower When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks co… CWE-200
Information Exposure
CVE-2019-3869 2024-11-21 13:42 2019-03-28 Show GitHub Exploit DB Packet Storm