Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
245091 6 警告 flatnuke3 - Flatnuke 3 の download モジュールにおける description.it.php ファイルへ PHP コードを挿入される脆弱性 CWE-94
コード・インジェクション
CVE-2007-5772 2012-06-26 15:54 2007-11-1 Show GitHub Exploit DB Packet Storm
245092 7.5 危険 flatnuke3 - Flatnuke 3 における管理者のアクセス権を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-5771 2012-06-26 15:54 2007-11-1 Show GitHub Exploit DB Packet Storm
245093 5 警告 globe7 - Globe7 ソフト電話クライアントにおける重要な情報を取得される脆弱性 CWE-310
暗号の問題
CVE-2007-5768 2012-06-26 15:54 2007-10-31 Show GitHub Exploit DB Packet Storm
245094 9.3 危険 AOL - AOL Radio の AmpX.dll の AOL AmpX ActiveX コントロールにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-5755 2012-06-26 15:54 2007-11-13 Show GitHub Exploit DB Packet Storm
245095 7.5 危険 agtc websolutions - PHP-AGTC Membership System の adduser.php におけるアカウントを作成される脆弱性 CWE-287
不適切な認証
CVE-2007-5752 2012-06-26 15:54 2007-10-31 Show GitHub Exploit DB Packet Storm
245096 5 警告 ghlab - Korean GHBoard の FlashUpload コンポーネントにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-5739 2012-06-26 15:54 2007-10-30 Show GitHub Exploit DB Packet Storm
245097 6.8 警告 ghlab - Korean GHBoard の FlashUpload コンポーネントにおける任意のファイルをアップロードされる脆弱性 CWE-20
不適切な入力確認
CVE-2007-5738 2012-06-26 15:54 2007-10-30 Show GitHub Exploit DB Packet Storm
245098 7.5 危険 ghlab - Korean GHBoard の component/upload.jsp における任意のファイルをアップロードされる脆弱性 CWE-20
CWE-94
CVE-2007-5737 2012-06-26 15:54 2007-10-30 Show GitHub Exploit DB Packet Storm
245099 5 警告 efileman - eFileMan における不特定のユーザ情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-5735 2012-06-26 15:54 2007-10-30 Show GitHub Exploit DB Packet Storm
245100 6.4 警告 efileman - eFileMan における任意のファイルをアップロードされる脆弱性 CWE-20
不適切な入力確認
CVE-2007-5734 2012-06-26 15:54 2007-10-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 19, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
218951 5.4 MEDIUM
Network
min-http-server_project min-http-server Cross-site scripting (XSS) vulnerability in min-http-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser. CWE-79
Cross-site Scripting
CVE-2019-5457 2024-11-21 13:44 2019-07-31 Show GitHub Exploit DB Packet Storm
218952 8.1 HIGH
Network
ui unifi_controller SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP server to record their SMTP credentials for malicious use l… CWE-255
Credentials Management
CVE-2019-5456 2024-11-21 13:44 2019-07-31 Show GitHub Exploit DB Packet Storm
218953 6.8 MEDIUM
Physics
nextcloud nextcloud Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process. CWE-287
Improper Authentication
CVE-2019-5455 2024-11-21 13:44 2019-07-31 Show GitHub Exploit DB Packet Storm
218954 9.8 CRITICAL
Network
nextcloud nextcloud SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring to resetup the account. CWE-89
SQL Injection
CVE-2019-5454 2024-11-21 13:44 2019-07-31 Show GitHub Exploit DB Packet Storm
218955 6.1 MEDIUM
Physics
nextcloud nextcloud Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider. CWE-287
Improper Authentication
CVE-2019-5453 2024-11-21 13:44 2019-07-31 Show GitHub Exploit DB Packet Storm
218956 2.4 LOW
Physics
nextcloud nextcloud Bypass lock protection in the Nextcloud Android app prior to version 3.6.2 causes leaking of thumbnails when requesting the Android content provider although the lock protection was not solved. NVD-CWE-Other
CVE-2019-5452 2024-11-21 13:44 2019-07-31 Show GitHub Exploit DB Packet Storm
218957 4.6 MEDIUM
Physics
nextcloud nextcloud_server Bypass lock protection in the Nextcloud Android app prior to version 3.6.1 allows accessing the files when repeatedly opening and closing the app in a very short time. CWE-306
Missing Authentication for Critical Function
CVE-2019-5451 2024-11-21 13:44 2019-07-31 Show GitHub Exploit DB Packet Storm
218958 6.8 MEDIUM
Physics
nextcloud nextcloud Improper sanitization of HTML in directory names in the Nextcloud Android app prior to version 3.7.0 allowed to style the directory name in the header bar when using basic HTML. CWE-79
Cross-site Scripting
CVE-2019-5450 2024-11-21 13:44 2019-07-31 Show GitHub Exploit DB Packet Storm
218959 4.3 MEDIUM
Network
nextcloud nextcloud_server A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events. CWE-862
 Missing Authorization
CVE-2019-5449 2024-11-21 13:44 2019-07-31 Show GitHub Exploit DB Packet Storm
218960 8.1 HIGH
Network
yarnpkg yarn Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network. CWE-319
Cleartext Transmission of Sensitive Information
CVE-2019-5448 2024-11-21 13:44 2019-07-31 Show GitHub Exploit DB Packet Storm