Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 23, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
251431 4.3 警告 Zimbra - Zimbra Web Client の zimbra/h/calendar におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-1213 2012-02-27 16:48 2012-02-24 Show GitHub Exploit DB Packet Storm
251432 4.3 警告 SMW+ - Semantic Enterprise Wiki の smwfOnSfSetTargetName 関数におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-1212 2012-02-27 16:47 2012-02-24 Show GitHub Exploit DB Packet Storm
251433 7.5 危険 Powie - Powie pFile の pfile/file.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-1210 2012-02-27 15:51 2012-02-24 Show GitHub Exploit DB Packet Storm
251434 4.3 警告 Fork CMS - Fork CMS の backend/core/engine/base.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-1209 2012-02-27 15:48 2012-02-24 Show GitHub Exploit DB Packet Storm
251435 4.3 警告 Fork CMS - Fork CMS の backend/core/engine/base.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-1208 2012-02-27 15:48 2012-02-24 Show GitHub Exploit DB Packet Storm
251436 5 警告 Fork CMS - Fork CMS の frontend/core/engine/javascript.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2012-1207 2012-02-27 15:41 2012-02-24 Show GitHub Exploit DB Packet Storm
251437 9.3 危険 Hancom Inc. - Hancom Office 2010 SE における整数オーバフローの脆弱性 CWE-189
数値処理の問題
CVE-2012-1206 2012-02-27 15:38 2012-02-24 Show GitHub Exploit DB Packet Storm
251438 7.5 危険 alanft - WordPress 用 Relocate Upload プラグインにおける PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2012-1205 2012-02-27 15:35 2012-02-24 Show GitHub Exploit DB Packet Storm
251439 4.3 警告 LEPTON Project - LEPTON におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-1000 2012-02-27 15:25 2012-02-24 Show GitHub Exploit DB Packet Storm
251440 7.5 危険 LEPTON Project - LEPTON の modules/news/rss.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-0999 2012-02-27 15:24 2012-02-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 23, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
223741 4.3 MEDIUM
Network
gitlab gitlab Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 1 of 2). CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2019-19086 2024-11-21 13:34 2020-01-4 Show GitHub Exploit DB Packet Storm
223742 6.5 MEDIUM
Adjacent
huawei p30_firmware HUAWEI P30 smart phones with versions earlier than 10.0.0.166(C00E66R1P11) have an information leak vulnerability. An attacker could send specific command in the local area network (LAN) to exploit t… NVD-CWE-noinfo
CVE-2019-19441 2024-11-21 13:34 2020-01-4 Show GitHub Exploit DB Packet Storm
223743 8.1 HIGH
Network
xmlblueprint xmlblueprint XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is: Arbitrary File Read when an XML File is validated. The component is: XML Validate function. The attack vect… CWE-611
XXE
CVE-2019-19032 2024-11-21 13:34 2019-12-31 Show GitHub Exploit DB Packet Storm
223744 8.1 HIGH
Network
edit-xml easy_xml_editor Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is: Arbitrary File Read and DoS by consuming resources. The component is: XML Parsing. The attack vector is: S… CWE-611
XXE
CVE-2019-19031 2024-11-21 13:34 2019-12-31 Show GitHub Exploit DB Packet Storm
223745 7.8 HIGH
Local
tinywall tinywall Unsafe usage of .NET deserialization in Named Pipe message processing allows privilege escalation to NT AUTHORITY\SYSTEM for a local attacker. Affected product is TinyWall, all versions up to and inc… CWE-502
 Deserialization of Untrusted Data
CVE-2019-19470 2024-11-21 13:34 2019-12-31 Show GitHub Exploit DB Packet Storm
223746 5.4 MEDIUM
Network
jetbrains ktor JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting. CWE-74
Injection
CVE-2019-19389 2024-11-21 13:34 2019-12-27 Show GitHub Exploit DB Packet Storm
223747 9.8 CRITICAL
Network
huawei m5_lite_10_firmware M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability. Due to the input validation logic is incorrect, an attacker can exploit this vulnerability to modify th… CWE-20
 Improper Input Validation 
CVE-2019-19398 2024-11-21 13:34 2019-12-27 Show GitHub Exploit DB Packet Storm
223748 5.4 MEDIUM
Network
cridio listingpro The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Good For field on the new listing submit page. CWE-79
Cross-site Scripting
CVE-2019-19542 2024-11-21 13:34 2019-12-27 Show GitHub Exploit DB Packet Storm
223749 5.4 MEDIUM
Network
cridio listingpro The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Best Day/Night field on the new listing submit page. CWE-79
Cross-site Scripting
CVE-2019-19541 2024-11-21 13:34 2019-12-27 Show GitHub Exploit DB Packet Storm
223750 6.1 MEDIUM
Network
cridio listingpro The ListingPro theme before v2.0.14.2 for WordPress has Reflected XSS via the What field on the homepage. CWE-79
Cross-site Scripting
CVE-2019-19540 2024-11-21 13:34 2019-12-27 Show GitHub Exploit DB Packet Storm