Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
245331 8.5 危険 アップル - Apple Mac OS X 用 DS Plug-In の認証機能における root パスワードを変更される脆弱性 - CVE-2007-0723 2012-06-26 15:46 2007-03-13 Show GitHub Exploit DB Packet Storm
245332 6.8 警告 アップル - Apple Mac OS X における整数オーバーフローの脆弱性 - CVE-2007-0722 2012-06-26 15:46 2007-03-13 Show GitHub Exploit DB Packet Storm
245333 6.8 警告 アップル - Apple Mac OS X の diskimages-helper における任意のコードを実行される脆弱性 - CVE-2007-0721 2012-06-26 15:46 2007-03-13 Show GitHub Exploit DB Packet Storm
245334 7.2 危険 Comodo - Comodo Firewall Pro および Comodo Personal Firewall の cmdmon.sys におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-0709 2012-06-26 15:46 2007-02-3 Show GitHub Exploit DB Packet Storm
245335 7.2 危険 Comodo - Comodo Firewall Pro の cmdmon.sys におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-0708 2012-06-26 15:46 2007-02-3 Show GitHub Exploit DB Packet Storm
245336 6.8 警告 Gretech - GOM Player におけるスタックベースのバッファーオーバーフローの脆弱性 - CVE-2007-0707 2012-06-26 15:46 2007-02-3 Show GitHub Exploit DB Packet Storm
245337 7.5 危険 epistemon - Epistemon の inc/common.inc.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-0701 2012-06-26 15:46 2007-02-3 Show GitHub Exploit DB Packet Storm
245338 6.8 警告 free lan intra internet portal - FLIP におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-0696 2012-06-26 15:46 2007-02-3 Show GitHub Exploit DB Packet Storm
245339 7.5 危険 free lan intra internet portal - FLIP における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-0695 2012-06-26 15:46 2007-02-3 Show GitHub Exploit DB Packet Storm
245340 4.3 警告 diangemilang - DGNews の footer.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-0694 2012-06-26 15:46 2007-05-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
219201 5.3 MEDIUM
Network
rubyonrails active_record_session_store The activerecord-session_store (aka Active Record Session Store) component through 1.1.3 for Ruby on Rails does not use a constant-time approach when delivering information about whether a guessed se… NVD-CWE-Other
CVE-2019-25025 2024-11-21 13:39 2021-03-5 Show GitHub Exploit DB Packet Storm
219202 6.5 MEDIUM
Network
scytl secure_vote An issue was discovered in Scytl sVote 2.1. Because the IP address from an X-Forwarded-For header (which can be manipulated client-side) is used for the internal application logs, an attacker can inj… CWE-290
 Authentication Bypass by Spoofing
CVE-2019-25023 2024-11-21 13:39 2021-02-27 Show GitHub Exploit DB Packet Storm
219203 9.8 CRITICAL
Network
scytl secure_vote An issue was discovered in Scytl sVote 2.1. An attacker can inject code that gets executed by creating an election-event and injecting a payload over an event alias, because the application calls Run… CWE-78
OS Command 
CVE-2019-25022 2024-11-21 13:39 2021-02-27 Show GitHub Exploit DB Packet Storm
219204 7.5 HIGH
Network
scytl secure_vote An issue was discovered in Scytl sVote 2.1. Due to the implementation of the database manager, an attacker can access the OrientDB by providing admin as the admin password. A different password canno… CWE-798
 Use of Hard-coded Credentials
CVE-2019-25021 2024-11-21 13:39 2021-02-27 Show GitHub Exploit DB Packet Storm
219205 7.5 HIGH
Network
scytl secure_vote An issue was discovered in Scytl sVote 2.1. Because the sdm-ws-rest API does not require authentication, an attacker can retrieve the administrative configuration by sending a POST request to the /sd… CWE-306
Missing Authentication for Critical Function
CVE-2019-25020 2024-11-21 13:39 2021-02-27 Show GitHub Exploit DB Packet Storm
219206 9.8 CRITICAL
Network
alleghenycreative openrepeater OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service parameter. CWE-78
OS Command 
CVE-2019-25024 2024-11-21 13:39 2021-02-19 Show GitHub Exploit DB Packet Storm
219207 9.8 CRITICAL
Network
limesurvey limesurvey LimeSurvey before 4.0.0-RC4 allows SQL injection via the participant model. CWE-89
SQL Injection
CVE-2019-25019 2024-11-21 13:39 2021-02-14 Show GitHub Exploit DB Packet Storm
219208 7.5 HIGH
Network
mit krb5-appl In the rcp client in MIT krb5-appl through 1.0.3, malicious servers could bypass intended access restrictions via the filename of . or an empty filename, similar to CVE-2018-20685 and CVE-2019-7282. … NVD-CWE-noinfo
CVE-2019-25018 2024-11-21 13:39 2021-02-3 Show GitHub Exploit DB Packet Storm
219209 5.9 MEDIUM
Network
mit krb5-appl An issue was discovered in rcp in MIT krb5-appl through 1.0.3. Due to the rcp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, t… CWE-863
 Incorrect Authorization
CVE-2019-25017 2024-11-21 13:39 2021-02-3 Show GitHub Exploit DB Packet Storm
219210 6.5 MEDIUM
Network
istio
redhat
istio
openshift_service_mesh
A NULL pointer dereference was found in pkg/proxy/envoy/v2/debug.go getResourceVersion in Istio pilot before 1.5.0-alpha.0. If a particular HTTP GET request is made to the pilot API endpoint, it is p… CWE-476
 NULL Pointer Dereference
CVE-2019-25014 2024-11-21 13:39 2021-01-29 Show GitHub Exploit DB Packet Storm