Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 24, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
252301 5 警告 phpAlbum - phpAlbum の main.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2011-4807 2011-12-16 15:23 2011-12-14 Show GitHub Exploit DB Packet Storm
252302 4.3 警告 phpAlbum - phpAlbum の main.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4806 2011-12-16 15:20 2011-12-14 Show GitHub Exploit DB Packet Storm
252303 4.3 警告 SAP - SAP Crystal Report Server の pubDBLogon.jsp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4805 2011-12-16 15:18 2011-12-14 Show GitHub Exploit DB Packet Storm
252304 7.5 危険 Authenex - ASAS Server 上の Authenex Web Management Control における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2011-4801 2011-12-16 15:16 2011-09-16 Show GitHub Exploit DB Packet Storm
252305 9 危険 Rhino Software - Serv-U FTP サーバにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2011-4800 2011-12-16 15:15 2011-12-14 Show GitHub Exploit DB Packet Storm
252306 4.3 警告 マイクロソフト - Microsoft Internet Explorer におけるコンテンツを読まれる脆弱性 CWE-200
情報漏えい
CVE-2011-3404 2011-12-16 11:52 2011-12-13 Show GitHub Exploit DB Packet Storm
252307 9.3 危険 マイクロソフト - Windows 2008 および Windows 7 上で稼働する Microsoft Internet Explorer 9 における権限昇格の脆弱性 CWE-Other
その他
CVE-2011-2019 2011-12-16 11:50 2011-12-13 Show GitHub Exploit DB Packet Storm
252308 7.2 危険 マイクロソフト - 複数の Microsoft Windows のカーネルにおける権限昇格の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-2018 2011-12-16 11:49 2011-12-13 Show GitHub Exploit DB Packet Storm
252309 4.3 警告 マイクロソフト - Microsoft Internet Explorer 8 の XSS フィルタにおけるコンテンツを読まれる脆弱性 CWE-200
情報漏えい
CVE-2011-1992 2011-12-16 11:48 2011-12-13 Show GitHub Exploit DB Packet Storm
252310 9.3 危険 マイクロソフト - Microsoft Excel および Office における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2011-3403 2011-12-16 11:40 2011-12-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 24, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
224861 6.6 MEDIUM
Network
open-xchange open-xchange_appsuite OX App Suite through 7.10.2 has Incorrect Access Control. CWE-276
Incorrect Default Permissions 
CVE-2019-16716 2024-11-21 13:31 2020-01-7 Show GitHub Exploit DB Packet Storm
224862 8.8 HIGH
Network
tiny_file_manager_project tiny_file_manager In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2019-16790 2024-11-21 13:31 2019-12-31 Show GitHub Exploit DB Packet Storm
224863 7.8 HIGH
Local
k7computing k7_ultimate_security In K7 Ultimate Security 16.0.0117, the module K7BKCExt.dll (aka the backup module) improperly validates the administrative privileges of the user, allowing an arbitrary file write via a symbolic link… CWE-59
Link Following
CVE-2019-16896 2024-11-21 13:31 2019-12-28 Show GitHub Exploit DB Packet Storm
224864 5.4 MEDIUM
Network
wordpress
debian
wordpress
debian_linux
In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admi… CWE-79
Cross-site Scripting
CVE-2019-16781 2024-11-21 13:31 2019-12-27 Show GitHub Exploit DB Packet Storm
224865 8.2 HIGH
Network
agendaless
oracle
debian
fedoraproject
redhat
waitress
communications_cloud_native_core_network_function_cloud_native_environment
debian_linux
fedora
openstack
In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress lead… CWE-444
HTTP Request Smuggling
CVE-2019-16789 2024-11-21 13:31 2019-12-27 Show GitHub Exploit DB Packet Storm
224866 5.4 MEDIUM
Network
wordpress
debian
wordpress
debian_linux
WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an a… CWE-79
Cross-site Scripting
CVE-2019-16780 2024-11-21 13:31 2019-12-27 Show GitHub Exploit DB Packet Storm
224867 7.5 HIGH
Network
agendaless
oracle
debian
fedoraproject
redhat
waitress
communications_cloud_native_core_network_function_cloud_native_environment
debian_linux
fedora
openstack
Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Content-Length header … CWE-444
HTTP Request Smuggling
CVE-2019-16786 2024-11-21 13:31 2019-12-21 Show GitHub Exploit DB Packet Storm
224868 7.5 HIGH
Network
agendaless
oracle
debian
fedoraproject
redhat
waitress
communications_cloud_native_core_network_function_cloud_native_environment
debian_linux
fedora
openstack
Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fields is the sequence CRLF, a recipient MAY recognize… CWE-444
HTTP Request Smuggling
CVE-2019-16785 2024-11-21 13:31 2019-12-21 Show GitHub Exploit DB Packet Storm
224869 9.8 CRITICAL
Network
beckhoff twincat Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote Code Execution (as SYSTEM) via the Beckhoff ADS protocol. CWE-290
 Authentication Bypass by Spoofing
CVE-2019-16871 2024-11-21 13:31 2019-12-20 Show GitHub Exploit DB Packet Storm
224870 5.9 MEDIUM
Network
rack_project
fedoraproject
opensuse
rack
fedora
leap
There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack session… CWE-203
 Information Exposure Through Discrepancy
CVE-2019-16782 2024-11-21 13:31 2019-12-19 Show GitHub Exploit DB Packet Storm