Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
251461 5.8 警告 Tencent - Android 用 Tencent QQPhoto における連絡先情報およびパスワードハッシュを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-4867 2012-01-27 15:18 2012-01-25 Show GitHub Exploit DB Packet Storm
251462 6.4 警告 Kaixin001 - Android 用 Kaixin001 における連絡先情報および平文パスワードを読まれる脆弱性 CWE-200
情報漏えい
CVE-2011-4866 2012-01-27 15:18 2012-01-25 Show GitHub Exploit DB Packet Storm
251463 5.8 警告 Tencent - Android 用 Tencent WBlog および MicroBlogPad におけるドラフトメッセージおよび検索キーワードを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-4865 2012-01-27 15:12 2012-01-25 Show GitHub Exploit DB Packet Storm
251464 5.8 警告 Tencent - Android 用 Tencent MobileQQ におけるメッセージおよびフレンドリストを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-4864 2012-01-27 15:10 2012-01-25 Show GitHub Exploit DB Packet Storm
251465 5.8 警告 Tencent - Android 用 Tencent QQPimSecure における SMS/MMS メッセージおよび連絡先リストを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-4863 2012-01-27 15:08 2012-01-25 Show GitHub Exploit DB Packet Storm
251466 5.8 警告 AnGuanJia - Android 用 AnGuanJia における SMS/MMS メッセージおよび連絡先リストを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-4773 2012-01-27 15:07 2012-01-25 Show GitHub Exploit DB Packet Storm
251467 5.8 警告 Qihoo 360 Technology - Android 用 360 KouXin における SMS メッセージおよび連絡先リストを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-4772 2012-01-27 15:06 2012-01-25 Show GitHub Exploit DB Packet Storm
251468 5.8 警告 Lucion Technologies - Android 用 Scan to PDF Free におけるスキャンされたファイルおよび Google アカウントを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-4771 2012-01-27 15:05 2012-01-25 Show GitHub Exploit DB Packet Storm
251469 5.8 警告 QIWI Wallet - Android 用 QIWI Wallet における金銭に関する情報を読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-4770 2012-01-27 15:03 2012-01-25 Show GitHub Exploit DB Packet Storm
251470 5.8 警告 Qihoo 360 Technology - Android 用 360 MobileSafe における SMS メッセージおよび連絡先リストを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-4769 2012-01-27 14:56 2012-01-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 20, 2026, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
223421 7.5 HIGH
Network
oniguruma_project
php
fedoraproject
canonical
debian
oniguruma
php
fedora
ubuntu_linux
debian_linux
Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c. CWE-125
Out-of-bounds Read
CVE-2019-19246 2024-11-21 13:34 2019-11-26 Show GitHub Exploit DB Packet Storm
223422 5.3 MEDIUM
Network
embedthis goahead Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect uses a static host buffer that has a limited length and can overflow. This can ca… CWE-787
CWE-908
 Out-of-bounds Write
 Use of Uninitialized Resource
CVE-2019-19240 2024-11-21 13:34 2019-11-23 Show GitHub Exploit DB Packet Storm
223423 5.5 MEDIUM
Local
linux linux_kernel In the AppleTalk subsystem in the Linux kernel before 5.1, there is a potential NULL pointer dereference because register_snap_client may return NULL. This will lead to denial of service in net/apple… CWE-476
 NULL Pointer Dereference
CVE-2019-19227 2024-11-21 13:34 2019-11-22 Show GitHub Exploit DB Packet Storm
223424 5.5 MEDIUM
Local
libarchive
debian
fedoraproject
canonical
libarchive
debian_linux
fedora
ubuntu_linux
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive. CWE-125
Out-of-bounds Read
CVE-2019-19221 2024-11-21 13:34 2019-11-22 Show GitHub Exploit DB Packet Storm
223425 8.8 HIGH
Network
rconfig rconfig rConfig 3.9.2 allows devices.php?searchColumn= SQL injection. CWE-89
SQL Injection
CVE-2019-19207 2024-11-21 13:34 2019-11-22 Show GitHub Exploit DB Packet Storm
223426 7.5 HIGH
Network
oniguruma_project
debian
fedoraproject
oniguruma
debian_linux
fedora
An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. … CWE-125
Out-of-bounds Read
CVE-2019-19204 2024-11-21 13:34 2019-11-22 Show GitHub Exploit DB Packet Storm
223427 7.5 HIGH
Network
oniguruma_project
fedoraproject
oniguruma
fedora
An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced without checking if it passed the end of the matched … CWE-125
Out-of-bounds Read
CVE-2019-19203 2024-11-21 13:34 2019-11-22 Show GitHub Exploit DB Packet Storm
223428 8.8 HIGH
Network
vtiger vtiger_crm In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding roleid=H2 to a POST request. CWE-276
Incorrect Default Permissions 
CVE-2019-19202 2024-11-21 13:34 2019-11-22 Show GitHub Exploit DB Packet Storm
223429 7.8 HIGH
Local
kyrolsecuritylabs kyrol_internet_security IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an attacker to achieve privilege escalation, denial-of-service, and code execution via usermode because 0x9C402401 usi… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2019-19197 2024-11-21 13:34 2019-11-22 Show GitHub Exploit DB Packet Storm
223430 7.8 HIGH
Local
shibboleth service_provider Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the shibd account) after installation. This allows the u… CWE-59
Link Following
CVE-2019-19191 2024-11-21 13:34 2019-11-22 Show GitHub Exploit DB Packet Storm