Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 2:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
246071 7.5 危険 ajax - Ajax File Browser の in _includes/settings.inc.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-4921 2012-06-26 15:54 2007-09-17 Show GitHub Exploit DB Packet Storm
246072 7.5 危険 gelatocms - Gelato の classes/gelato.class.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-4918 2012-06-26 15:54 2007-09-17 Show GitHub Exploit DB Packet Storm
246073 10 危険 Boa - Boa 用の Intersil 拡張機能におけるメモリに格納された管理者パスワードを変更される脆弱性 CWE-20
不適切な入力確認
CVE-2007-4915 2012-06-26 15:54 2007-09-17 Show GitHub Exploit DB Packet Storm
246074 5 警告 JetAudio - JetCast Server の JSMP3OGGWt.dll におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2007-4911 2012-06-26 15:54 2007-09-17 Show GitHub Exploit DB Packet Storm
246075 7.5 危険 AuraCMS - AuraCMS の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-4908 2012-06-26 15:54 2007-09-17 Show GitHub Exploit DB Packet Storm
246076 7.5 危険 AuraCMS - AuraCMS の mod/contak.php における任意の PHP コードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2007-4905 2012-06-26 15:54 2007-09-17 Show GitHub Exploit DB Packet Storm
246077 5.8 警告 AOL - Internet Explorer サーバコントロールにおける任意のコードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2007-4901 2012-06-26 15:54 2007-09-14 Show GitHub Exploit DB Packet Storm
246078 4.3 警告 University of California - Boinc Forum におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-4899 2012-06-26 15:54 2007-09-14 Show GitHub Exploit DB Packet Storm
246079 6.8 警告 AuraCMS - AuraCMS の index.php における任意の PHP コードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2007-4886 2012-06-26 15:54 2007-09-13 Show GitHub Exploit DB Packet Storm
246080 4.3 警告 avnex - Avnex AV MP3 Player におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2007-4885 2012-06-26 15:54 2007-09-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
218841 9.8 CRITICAL
Network
zoneminder zoneminder ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] value. CWE-89
SQL Injection
CVE-2019-8428 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
218842 9.8 CRITICAL
Network
zoneminder zoneminder daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters. CWE-78
OS Command 
CVE-2019-8427 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
218843 6.1 MEDIUM
Network
zoneminder zoneminder skins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the newControl[MinTiltRange] parameter. CWE-79
Cross-site Scripting
CVE-2019-8426 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
218844 6.1 MEDIUM
Network
zoneminder zoneminder includes/database.php in ZoneMinder before 1.32.3 has XSS in the construction of SQL-ERR messages. CWE-79
Cross-site Scripting
CVE-2019-8425 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
218845 9.8 CRITICAL
Network
zoneminder zoneminder ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter. CWE-89
SQL Injection
CVE-2019-8424 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
218846 9.8 CRITICAL
Network
zoneminder zoneminder ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter. CWE-89
SQL Injection
CVE-2019-8423 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
218847 7.2 HIGH
Network
pbootcms pbootcms A SQL Injection vulnerability exists in PbootCMS v1.3.2 via the description parameter in apps\admin\controller\content\ContentController.php. CWE-89
SQL Injection
CVE-2019-8422 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
218848 7.2 HIGH
Network
bagesoft bagecms upload/protected/modules/admini/views/post/index.php in BageCMS through 3.1.4 allows SQL Injection via the title or titleAlias parameter. CWE-89
SQL Injection
CVE-2019-8421 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
218849 6.1 MEDIUM
Network
vnote_project vnote VNote 2.2 has XSS via a new text note. CWE-79
Cross-site Scripting
CVE-2019-8419 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
218850 8.8 HIGH
Network
seacms seacms SeaCMS 7.2 mishandles member.php?mod=repsw4 requests. NVD-CWE-noinfo
CVE-2019-8418 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm