Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
246591 6.8 警告 awbs - AWBS における SQL インジェクションの脆弱性 - CVE-2007-4112 2012-06-26 15:54 2007-07-31 Show GitHub Exploit DB Packet Storm
246592 6.8 警告 codewidgets - Real Estate listing website アプリケーションテンプレートのログインスクリプトにおける SQL インジェクションの脆弱性 - CVE-2007-4111 2012-06-26 15:54 2007-07-31 Show GitHub Exploit DB Packet Storm
246593 7.5 危険 codewidgets - Message Board / Threaded Discussion Forum Application Template の sign_in.aspx における SQL インジェクションの脆弱性 - CVE-2007-4110 2012-06-26 15:54 2007-07-31 Show GitHub Exploit DB Packet Storm
246594 7.5 危険 codewidgets - Online Store Application Template の sign_in.aspx における SQL インジェクションの脆弱性 - CVE-2007-4109 2012-06-26 15:54 2007-07-31 Show GitHub Exploit DB Packet Storm
246595 7.5 危険 codewidgets - Online Event Registration Template の sign_in.aspx における SQL インジェクションの脆弱性 - CVE-2007-4108 2012-06-26 15:54 2007-07-31 Show GitHub Exploit DB Packet Storm
246596 6.8 警告 codewidgets - CodeWidgets Pay Roll - Time Sheet and Punch Card Application における SQL インジェクションの脆弱性 - CVE-2007-4106 2012-06-26 15:54 2007-07-31 Show GitHub Exploit DB Packet Storm
246597 9.3 危険 Baidu, Inc. - Baidu Soba Search Bar の BaiduBar.dll の特定の ActiveX コントロールにおける任意のコードを実行される脆弱性 - CVE-2007-4105 2012-06-26 15:54 2007-07-31 Show GitHub Exploit DB Packet Storm
246598 7.8 危険 Digium - Asterisk Open の IAX2 チャネルドライバ (chan_iax2) におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-4103 2012-06-26 15:54 2007-07-31 Show GitHub Exploit DB Packet Storm
246599 6.8 警告 global centre - Madoa Poll における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-4101 2012-06-26 15:54 2007-07-31 Show GitHub Exploit DB Packet Storm
246600 7.5 危険 bsm store - BSM Store Dependent Forums における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-4095 2012-06-26 15:54 2007-07-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 31, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
219741 7.0 HIGH
Local
lg lha.sys The LHA.sys driver before 1.1.1811.2101 in LG Device Manager exposes functionality that allows low-privileged users to read and write arbitrary physical memory via specially crafted IOCTL requests an… CWE-59
Link Following
CVE-2019-8372 2024-11-21 13:49 2019-02-19 Show GitHub Exploit DB Packet Storm
219742 5.4 MEDIUM
Network
txjia imcat imcat 4.5 has Stored XSS via the root/run/adm.php fm[instop][note] parameter. CWE-79
Cross-site Scripting
CVE-2019-8436 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
219743 4.8 MEDIUM
Network
phpmywind phpmywind admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header. CWE-79
Cross-site Scripting
CVE-2019-8435 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
219744 6.1 MEDIUM
Network
cmseasy cmseasy In CmsEasy 7.0, there is XSS via the ckplayer.php autoplay parameter. CWE-79
Cross-site Scripting
CVE-2019-8434 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
219745 7.5 HIGH
Network
jtbc jtbc_php JTBC(PHP) 3.0.1.8 allows Arbitrary File Upload via the console/#/console/file/manage.php?type=list URI, as demonstrated by a .php file. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2019-8433 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
219746 6.1 MEDIUM
Network
cmseasy cmseasy In CmsEasy 7.0, there is XSS via the ckplayer.php url parameter. CWE-79
Cross-site Scripting
CVE-2019-8432 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
219747 9.8 CRITICAL
Network
zoneminder zoneminder ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter. CWE-89
SQL Injection
CVE-2019-8429 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
219748 9.8 CRITICAL
Network
zoneminder zoneminder ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] value. CWE-89
SQL Injection
CVE-2019-8428 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
219749 9.8 CRITICAL
Network
zoneminder zoneminder daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters. CWE-78
OS Command 
CVE-2019-8427 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm
219750 6.1 MEDIUM
Network
zoneminder zoneminder skins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the newControl[MinTiltRange] parameter. CWE-79
Cross-site Scripting
CVE-2019-8426 2024-11-21 13:49 2019-02-18 Show GitHub Exploit DB Packet Storm