Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 22, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
252461 7.5 危険 Michau Enterprises - SenseSites CommonSense CMS の article.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-5037 2011-12-9 13:41 2011-11-2 Show GitHub Exploit DB Packet Storm
252462 7.5 危険 Groone's World - Groone's Simple Contact Form における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2010-5038 2011-12-9 13:40 2011-11-2 Show GitHub Exploit DB Packet Storm
252463 7.5 危険 ScriptsFeed.com - ScriptsFeed Recipes Listing Portal における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-5039 2011-12-9 13:40 2011-11-2 Show GitHub Exploit DB Packet Storm
252464 6.8 警告 John Bradshaw - Nucleus 用 NP_Gallery プラグインにおける PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2010-5040 2011-12-9 13:39 2011-11-2 Show GitHub Exploit DB Packet Storm
252465 7.5 危険 John Bradshaw - Nucleus 用 NP_Gallery プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-5041 2011-12-9 13:38 2011-11-2 Show GitHub Exploit DB Packet Storm
252466 4.3 警告 Blue Constant Media Ltd - Joomla! 用 DJ-ArtGallery コンポーネントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-5042 2011-12-9 13:38 2011-11-2 Show GitHub Exploit DB Packet Storm
252467 6 警告 Blue Constant Media Ltd - Joomla! 用 DJ-ArtGallery コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-5043 2011-12-9 13:34 2011-11-2 Show GitHub Exploit DB Packet Storm
252468 6 警告 Kanich - Joomla! 用 Search Log コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-5044 2011-12-9 13:33 2011-11-2 Show GitHub Exploit DB Packet Storm
252469 4.3 警告 Sell@Site - Smart ASP Survey におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-5045 2011-12-9 13:32 2011-11-2 Show GitHub Exploit DB Packet Storm
252470 5.1 警告 FFFTPプロジェクト - FFFTP における実行ファイル読み込みに関する脆弱性 CWE-Other
その他
CVE-2011-4266 2011-12-9 12:02 2011-12-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 23, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
224781 5.4 MEDIUM
Network
solarwinds web_help_desk SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket. CWE-79
Cross-site Scripting
CVE-2019-16956 2024-11-21 13:31 2021-01-4 Show GitHub Exploit DB Packet Storm
224782 7.5 HIGH
Network
matrixssl matrixssl In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and a daemon crash) via a crafted incoming network message, a different vulnerabili… CWE-787
 Out-of-bounds Write
CVE-2019-16747 2024-11-21 13:31 2020-12-31 Show GitHub Exploit DB Packet Storm
224783 6.5 MEDIUM
Network
solarwinds webhelpdesk SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket. CWE-1236
 Improper Neutralization of Formula Elements in a CSV File
CVE-2019-16959 2024-11-21 13:31 2020-12-22 Show GitHub Exploit DB Packet Storm
224784 5.4 MEDIUM
Network
solarwinds webhelpdesk SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account. CWE-79
Cross-site Scripting
CVE-2019-16957 2024-11-21 13:31 2020-12-18 Show GitHub Exploit DB Packet Storm
224785 5.4 MEDIUM
Network
solarwinds webhelpdesk SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request. CWE-79
Cross-site Scripting
CVE-2019-16955 2024-11-21 13:31 2020-12-18 Show GitHub Exploit DB Packet Storm
224786 5.4 MEDIUM
Network
solarwinds help_desk Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name. CWE-79
Cross-site Scripting
CVE-2019-16958 2024-11-21 13:31 2020-12-2 Show GitHub Exploit DB Packet Storm
224787 7.5 HIGH
Network
mozilla
siemens
network_security_services
ruggedcom_rox_mx5000_firmware
ruggedcom_rox_rx1400_firmware
ruggedcom_rox_rx1500_firmware
ruggedcom_rox_rx1501_firmware
ruggedcom_rox_rx1510_firmware
rugge…
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service. CWE-295
Improper Certificate Validation 
CVE-2019-17007 2024-11-21 13:31 2020-10-23 Show GitHub Exploit DB Packet Storm
224788 9.8 CRITICAL
Network
siemens
mozilla
netapp
ruggedcom_rox_mx5000_firmware
ruggedcom_rox_rx1400_firmware
ruggedcom_rox_rx1500_firmware
ruggedcom_rox_rx1501_firmware
ruggedcom_rox_rx1510_firmware
ruggedcom_rox_rx1511_firmware
r…
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the in… CWE-119
CWE-20
Incorrect Access of Indexable Resource ('Range Error') 
 Improper Input Validation 
CVE-2019-17006 2024-11-21 13:31 2020-10-23 Show GitHub Exploit DB Packet Storm
224789 6.5 MEDIUM
Adjacent
august august_home
connect_wi-fi_bridge_firmware
Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacker to decrypt an intercepted payload containing the Wi-Fi network authentication… CWE-798
 Use of Hard-coded Credentials
CVE-2019-17098 2024-11-21 13:31 2020-09-30 Show GitHub Exploit DB Packet Storm
224790 7.8 HIGH
Local
ivanti workspace_control In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registries. This is possible because pwrgrid.exe first checks the Current User registry… CWE-269
 Improper Privilege Management
CVE-2019-17066 2024-11-21 13:31 2020-05-19 Show GitHub Exploit DB Packet Storm