Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 21, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
246101 7.5 危険 bugmall - BugMall Shopping Cart におけるログインアクセス権を取得される脆弱性 - CVE-2007-3446 2012-06-26 15:46 2007-06-26 Show GitHub Exploit DB Packet Storm
246102 5 警告 aastra telecom - Aastra 9112i SIP Phone におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-3441 2012-06-26 15:46 2007-06-26 Show GitHub Exploit DB Packet Storm
246103 7.8 危険 マイクロソフト
AOL
- AIM におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-3437 2012-06-26 15:46 2007-06-26 Show GitHub Exploit DB Packet Storm
246104 6.8 警告 e107.org - e107 の signup.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-3429 2012-06-26 15:46 2007-06-26 Show GitHub Exploit DB Packet Storm
246105 4.3 警告 access2asp - access2asp におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3414 2012-06-26 15:46 2007-06-26 Show GitHub Exploit DB Packet Storm
246106 4.3 警告 bitego - bosDataGrid におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3413 2012-06-26 15:46 2007-06-26 Show GitHub Exploit DB Packet Storm
246107 4.3 警告 clicktech - ClickGallery Server の edit_image.asp におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3412 2012-06-26 15:46 2007-06-26 Show GitHub Exploit DB Packet Storm
246108 7.5 危険 dia - Dia における詳細不明な脆弱性 - CVE-2007-3408 2012-06-26 15:46 2007-06-26 Show GitHub Exploit DB Packet Storm
246109 7.5 危険 dreamlog - dreamLog の upload.php における uploads/images/ 配下の任意の PHP コードをアップロードされる脆弱性 - CVE-2007-3403 2012-06-26 15:46 2007-06-26 Show GitHub Exploit DB Packet Storm
246110 7.5 危険 b1g - B1G b1gBB の footer.inc.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-3401 2012-06-26 15:46 2007-06-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 21, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
219491 5.3 MEDIUM
Network
ibm guardium_data_encryption
guardium_for_cloud_key_management
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// l… CWE-311
Missing Encryption of Sensitive Data
CVE-2019-4686 2024-11-21 13:43 2020-08-27 Show GitHub Exploit DB Packet Storm
219492 4.3 MEDIUM
Network
ibm maximo_asset_management IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences … CWE-22
Path Traversal
CVE-2019-4582 2024-11-21 13:43 2020-08-13 Show GitHub Exploit DB Packet Storm
219493 4.3 MEDIUM
Network
ibm cognos_analytics IBM Cognos Analytics 11.0 and 11.1 is vulnerable to privlege escalation where the "My schedules and subscriptions" page is visible and accessible to a less privileged user. IBM X-Force ID: 167449. CWE-269
 Improper Privilege Management
CVE-2019-4589 2024-11-21 13:43 2020-08-3 Show GitHub Exploit DB Packet Storm
219494 5.3 MEDIUM
Network
ibm cognos_analytics IBM Cognos Analytics 11.0 and 11.1 is susceptible to an information disclosure vulnerability where an attacker could gain access to cached browser data. IBM X-Force ID: 161748. NVD-CWE-noinfo
CVE-2019-4366 2024-11-21 13:43 2020-08-3 Show GitHub Exploit DB Packet Storm
219495 5.4 MEDIUM
Network
hcltech marketing_campaign "HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for users in Dashboard, potentially giving an attacker ability to inject malicious … CWE-79
Cross-site Scripting
CVE-2019-4091 2024-11-21 13:43 2020-07-18 Show GitHub Exploit DB Packet Storm
219496 5.4 MEDIUM
Network
hcltech marketing_campaign "HCL Campaign is vulnerable to cross-site scripting when a user provides XSS scripts in Campaign Description field." CWE-79
Cross-site Scripting
CVE-2019-4090 2024-11-21 13:43 2020-07-18 Show GitHub Exploit DB Packet Storm
219497 7.8 HIGH
Local
ibm maximo_asset_management IBM Maximo Asset Management 7.6.0 and 7.6.1 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 167451. CWE-384
 Session Fixation
CVE-2019-4591 2024-11-21 13:43 2020-07-13 Show GitHub Exploit DB Packet Storm
219498 6.1 MEDIUM
Network
hcltech appscan "HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy." CWE-79
Cross-site Scripting
CVE-2019-4324 2024-11-21 13:43 2020-07-8 Show GitHub Exploit DB Packet Storm
219499 4.3 MEDIUM
Network
hcltech appscan "HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame." CWE-1021
 Improper Restriction of Rendered UI Layers or Frames
CVE-2019-4323 2024-11-21 13:43 2020-07-8 Show GitHub Exploit DB Packet Storm
219500 7.8 HIGH
Local
ibm security_identity_manager_virtual_appliance IBM Security Identity Manager Virtual Appliance 7.0.2 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 171512. CWE-312
 Cleartext Storage of Sensitive Information
CVE-2019-4676 2024-11-21 13:43 2020-07-2 Show GitHub Exploit DB Packet Storm