NVD Vulnerability Information Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
In descending order of publication date
In descending order of update date
Number of items displayed

You can search the list of vulnerabilities managed by the NVD (National Vulnerability Database).
Since vulnerability information is often updated before JVN (Japan Vulnerability Note), vulnerabilities that are not listed in JVN may be updated.

If there is a vulnerability related to JVN (Japan Vulnerability Note), the information will be displayed on the detail page.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW

Update Date:June 24, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
342651 4.3 MEDIUM
bitdamaged geoblog Cross-site scripting (XSS) vulnerability in viewcat.php in geoBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via the cat parameter. NVD-CWE-Other
CVE-2006-2177 2018-10-19 01:38 2006-05-4 Show GitHub Exploit DB Packet Storm
342652 5.0 MEDIUM
zenphoto zenphoto zenphoto 1.0.1 beta and earlier allow remote attackers to obtain sensitive information via a direct request for the (1) /photos/themes/default/ and (2) /photos/themes/testing/ URIs, which reveals the… NVD-CWE-Other
CVE-2006-2186 2018-10-19 01:38 2006-05-4 Show GitHub Exploit DB Packet Storm
342653 6.8 MEDIUM
zenphoto zenphoto Multiple cross-site scripting (XSS) vulnerabilities in zenphoto 1.0.1 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) a parameter in i.php, and the (2) albu… NVD-CWE-Other
CVE-2006-2187 2018-10-19 01:38 2006-05-4 Show GitHub Exploit DB Packet Storm
342654 6.8 MEDIUM
zenphoto zenphoto This vulnerability is addressed in the following product release: zenphoto, zenphoto, 1.0.2 beta NVD-CWE-Other
CVE-2006-2187 2018-10-19 01:38 2006-05-4 Show GitHub Exploit DB Packet Storm
342655 6.8 MEDIUM
cmscout cmscout Multiple cross-site scripting (XSS) vulnerabilities in CMScout 1.10 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the Body field of a private message (PM), (2) BBC… NVD-CWE-Other
CVE-2006-2188 2018-10-19 01:38 2006-05-4 Show GitHub Exploit DB Packet Storm
342656 6.8 MEDIUM
cmscout cmscout This vulnerability is addressed in the following product release: CMScout, CMScout, 1.21 NVD-CWE-Other
CVE-2006-2188 2018-10-19 01:38 2006-05-4 Show GitHub Exploit DB Packet Storm
342657 10.0 HIGH
servous sblog SQL injection vulnerability in search.php in Servous sBLOG 0.7.2 allows remote attackers to execute arbitrary SQL commands via the keyword parameter. NOTE: this issue can be used to trigger path dis… NVD-CWE-Other
CVE-2006-2189 2018-10-19 01:38 2006-05-4 Show GitHub Exploit DB Packet Storm
342658 7.6 HIGH
openoffice
sun
openoffice
staroffice
OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to conduct unauthorized activities via an OpenOffice document with a malicious BASIC macro, whi… CWE-264
Permissions, Privileges, and Access Controls
CVE-2006-2198 2018-10-19 01:38 2006-07-1 Show GitHub Exploit DB Packet Storm
342659 7.6 HIGH
openoffice
sun
openoffice
staroffice
Unspecified vulnerability in Java Applets in OpenOffice.org 1.1.x (aka StarOffice) up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to escape the Java sandbox and conduct unauthorize… NVD-CWE-noinfo
CVE-2006-2199 2018-10-19 01:38 2006-07-1 Show GitHub Exploit DB Packet Storm
342660 6.4 MEDIUM
invision_power_services invision_gallery SQL injection vulnerability in post.php in Invision Gallery 2.0.6 allows remote attackers to execute arbitrary SQL commands via the album parameter. NVD-CWE-Other
CVE-2006-2202 2018-10-19 01:38 2006-05-5 Show GitHub Exploit DB Packet Storm
342661 5.5 MEDIUM
invision_power_services invision_power_board SQL injection vulnerability in the topic deletion functionality (post_delete function in func_mod.php) for Invision Power Board 2.1.5 allows remote authenticated moderators to execute arbitrary SQL c… NVD-CWE-Other
CVE-2006-2204 2018-10-19 01:38 2006-05-5 Show GitHub Exploit DB Packet Storm
342662 5.8 MEDIUM
321soft php-gallery Cross-site scripting (XSS) vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to inject arbitrary web script or HTML via the path parameter. NOTE: this issue might be resu… NVD-CWE-Other
CVE-2006-2210 2018-10-19 01:38 2006-05-5 Show GitHub Exploit DB Packet Storm
342663 5.0 MEDIUM
321soft php-gallery Absolute path traversal vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to browse arbitrary directories via the path parameter. NVD-CWE-Other
CVE-2006-2211 2018-10-19 01:38 2006-05-5 Show GitHub Exploit DB Packet Storm
342664 6.4 MEDIUM
karjasoft sami_ftp_server Buffer overflow in KarjaSoft Sami FTP Server 2.0.2 and earlier allows remote attackers to execute arbitrary code via a long (1) USER or (2) PASS command. NVD-CWE-Other
CVE-2006-2212 2018-10-19 01:38 2006-05-5 Show GitHub Exploit DB Packet Storm
342665 5.0 MEDIUM
devsyn open_bulletin_board Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to obtain the full path of the web server via an invalid pforums parameter to (1) misc.php and (2) member.php. NVD-CWE-Other
CVE-2006-2216 2018-10-19 01:38 2006-05-5 Show GitHub Exploit DB Packet Storm
342666 2.1 LOW
bitrock
process-one
install_builder
ejabberd
A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and earlier, generates an installer that allows local users to cau… NVD-CWE-Other
CVE-2006-2221 2018-10-19 01:38 2006-05-6 Show GitHub Exploit DB Packet Storm
342667 2.1 LOW
bitrock
process-one
install_builder
ejabberd
This vulnerability is addressed in the following product releases: Process-one, ejabberd, 1.1.1_2 BitRock, Install Builder, 3.7.0 NVD-CWE-Other
CVE-2006-2221 2018-10-19 01:38 2006-05-6 Show GitHub Exploit DB Packet Storm
342668 5.0 MEDIUM
norz zawhttpd Buffer overflow in zawhttpd 0.8.23, and possibly previous versions, allows remote attackers to cause a denial of service (daemon crash) via a request for a URI composed of several "\" (backslash) cha… NVD-CWE-Other
CVE-2006-2222 2018-10-19 01:38 2006-05-6 Show GitHub Exploit DB Packet Storm
342669 5.0 MEDIUM
quagga quagga RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain … CWE-20
 Improper Input Validation 
CVE-2006-2223 2018-10-19 01:38 2006-05-6 Show GitHub Exploit DB Packet Storm
342670 5.0 MEDIUM
quagga quagga_routing_software_suite RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets. CWE-287
Improper Authentication
CVE-2006-2224 2018-10-19 01:38 2006-05-6 Show GitHub Exploit DB Packet Storm
342671 7.5 HIGH
dxmsoft xm_easy_personal_ftp_server Buffer overflow in XM Easy Personal FTP Server 4.3 and earlier allows remote attackers to execute arbitrary code, probably via a USER command with a long username. NVD-CWE-Other
CVE-2006-2225 2018-10-19 01:38 2006-05-6 Show GitHub Exploit DB Packet Storm
342672 4.3 MEDIUM
punbb punbb Cross-site scripting (XSS) vulnerability in misc.php in PunBB 1.2.11 allows remote attackers to inject arbitrary web script or HTML via the req_message parameter, because the value of the redirect_ur… NVD-CWE-Other
CVE-2006-2227 2018-10-19 01:38 2006-05-6 Show GitHub Exploit DB Packet Storm
342673 4.3 MEDIUM
w-agora w-agora Cross-site scripting (XSS) vulnerability in w-Agora (aka Web-Agora) 4.2.0 allows remote attackers to inject arbitrary web script or HTML via a post with a BBCode tag that contains a JavaScript event … NVD-CWE-Other
CVE-2006-2228 2018-10-19 01:38 2006-05-6 Show GitHub Exploit DB Packet Storm
342674 5.0 MEDIUM
xine xine Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.4 might allow attackers to cause a denial of service via format string specifiers in an MP3 filename specified on the command… NVD-CWE-Other
CVE-2006-2230 2018-10-19 01:38 2006-05-6 Show GitHub Exploit DB Packet Storm
342675 4.3 MEDIUM
big_webmaster big_webmaster_guestbook_script Multiple cross-site scripting (XSS) vulnerabilities in addguest.cgi in Big Webmaster Guestbook Script 1.02 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mail, … NVD-CWE-Other
CVE-2006-2231 2018-10-19 01:38 2006-05-6 Show GitHub Exploit DB Packet Storm
342676 4.3 MEDIUM
scriptsez cute_guestbook Cross-site scripting (XSS) vulnerability in Scriptsez Cute Guestbook 20060211 allows remote attackers to inject arbitrary web script or HTML via the Comments field when signing the guestbook. NVD-CWE-Other
CVE-2006-2232 2018-10-19 01:38 2006-05-6 Show GitHub Exploit DB Packet Storm
342677 7.5 HIGH
banktown btcxctl20com_activex_control Buffer overflow in BankTown Client Control (aka BtCxCtl20Com) 1.4.2.51817, and possibly 1.5.2.50209, allows remote attackers to execute arbitrary code via a long string in the first argument to SetBa… NVD-CWE-Other
CVE-2006-2233 2018-10-19 01:38 2006-05-6 Show GitHub Exploit DB Packet Storm
342678 6.8 MEDIUM
tyrocms tyrocms Multiple cross-site scripting (XSS) vulnerabilities in TyroCMS beta 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) a javascript URI in an img BBCode tag, or a JavaScript ev… NVD-CWE-Other
CVE-2006-2234 2018-10-19 01:38 2006-05-6 Show GitHub Exploit DB Packet Storm
342679 7.6 HIGH
codemunkyx simple_poll CodeMunkyX (aka free-php.net) Simple Poll 1.0, when authentication is not required for the admin directory, allows remote attackers to gain administrative privileges by appending /admin/ to the top-l… NVD-CWE-Other
CVE-2006-2235 2018-10-19 01:38 2006-05-6 Show GitHub Exploit DB Packet Storm
342680 7.6 HIGH
codemunkyx simple_poll This vulnerability can only be exploited when authentication is not required for the admin directory. NVD-CWE-Other
CVE-2006-2235 2018-10-19 01:38 2006-05-6 Show GitHub Exploit DB Packet Storm
342681 7.6 HIGH
id_software quake_3_arena
quake_3_engine
return_to_castle_wolfenstein
wolfenstein_enemy_territory
Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote attackers to execute arbitrary commands via a long re… NVD-CWE-Other
CVE-2006-2236 2018-10-19 01:38 2006-05-9 Show GitHub Exploit DB Packet Storm
342682 6.4 MEDIUM
ftrainsoft fast_click PHP remote file inclusion vulnerability in show.php in Fast Click SQL Lite 1.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. NOTE: This is a di… NVD-CWE-Other
CVE-2006-2241 2018-10-19 01:38 2006-05-9 Show GitHub Exploit DB Packet Storm
342683 5.8 MEDIUM
uapplication ublog Cross-site scripting (XSS) vulnerability in UBlog 1.6 Access Edition allows remote attackers to inject arbitrary web script or HTML via text fields when adding a blog entry. NVD-CWE-Other
CVE-2006-2246 2018-10-19 01:38 2006-05-9 Show GitHub Exploit DB Packet Storm
342684 5.0 MEDIUM
webcalendar webcalendar WebCalendar 1.0.1 to 1.0.3 generates different error messages depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames. NVD-CWE-Other
CVE-2006-2247 2018-10-19 01:38 2006-05-9 Show GitHub Exploit DB Packet Storm
342685 4.3 MEDIUM
cutephp cutenews Multiple cross-site scripting (XSS) vulnerabilities in search.php in CuteNews 1.4.1 and earlier, and possibly 1.4.5, allow remote attackers to inject arbitrary web script or HTML via the (1) user, (2… NVD-CWE-Other
CVE-2006-2249 2018-10-19 01:38 2006-05-9 Show GitHub Exploit DB Packet Storm
342686 6.4 MEDIUM
cutephp cutenews CuteNews 1.4.1 allows remote attackers to obtain sensitive information via a direct request to (1) /inc/show.inc.php or (2) /inc/functions.inc.php, which reveal the path in an error message. NVD-CWE-Other
CVE-2006-2250 2018-10-19 01:38 2006-05-9 Show GitHub Exploit DB Packet Storm
342687 6.4 MEDIUM
openfaq openfaq Cross-site scripting vulnerability in submit.php in OpenFAQ 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter. NVD-CWE-Other
CVE-2006-2252 2018-10-19 01:38 2006-05-9 Show GitHub Exploit DB Packet Storm
342688 2.6 LOW
singapore singapore Cross-site scripting (XSS) vulnerability in index.php in singapore 0.9.7 allows remote attackers to inject arbitrary web script or HTML via the image parameter. NVD-CWE-Other
CVE-2006-2262 2018-10-19 01:38 2006-05-9 Show GitHub Exploit DB Packet Storm
342689 5.0 MEDIUM
kerio winroute_firewall Kerio WinRoute Firewall before 6.2.1 allows remote attackers to cause a denial of service (application crash) via unknown vectors in the "email protocol inspectors," possibly (1) SMTP and (2) POP3. NVD-CWE-Other
CVE-2006-2267 2018-10-19 01:38 2006-05-9 Show GitHub Exploit DB Packet Storm
342690 5.0 MEDIUM
kerio winroute_firewall This vulnerability is addressed in the following product release: Kerio, WinRoute Firewall, 6.2.1 NVD-CWE-Other
CVE-2006-2267 2018-10-19 01:38 2006-05-9 Show GitHub Exploit DB Packet Storm
342691 7.5 HIGH
flexcustomer flexcustomer SQL injection vulnerability in FlexCustomer 0.0.4 and earlier allows remote attackers to bypass authentication and execute arbitrary SQL commands via the admin and ordinary user interface, probably i… CWE-89
SQL Injection
CVE-2006-2268 2018-10-19 01:38 2006-05-9 Show GitHub Exploit DB Packet Storm
342692 4.3 MEDIUM
mywebland mybloggie Cross-site scripting (XSS) vulnerability in myWebland MyBloggie 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in a BBCode img tag. NVD-CWE-Other
CVE-2006-2269 2018-10-19 01:38 2006-05-9 Show GitHub Exploit DB Packet Storm
342693 7.5 HIGH
jetbox jetbox_cms PHP remote file inclusion vulnerability in includes/config.php in Jetbox CMS 2.1 allows remote attackers to execute arbitrary code via a URL in the relative_script_path parameter. NVD-CWE-Other
CVE-2006-2270 2018-10-19 01:38 2006-05-9 Show GitHub Exploit DB Packet Storm
342694 9.3 HIGH
verisign i-nav The InstallProduct routine in the Verisign VUpdater.Install (aka i-Nav) ActiveX control does not verify Microsoft Cabinet (.CAB) files, which allows remote attackers to run an arbitrary executable fi… NVD-CWE-Other
CVE-2006-2273 2018-10-19 01:38 2006-05-12 Show GitHub Exploit DB Packet Storm
342695 5.0 MEDIUM
apple mac_os_x Multiple Apple Mac OS X 10.4 applications might allow context-dependent attackers to cause a denial of service (application crash) via a crafted OpenEXR (.exr) image file, which triggers the crash wh… NVD-CWE-Other
CVE-2006-2277 2018-10-19 01:38 2006-05-10 Show GitHub Exploit DB Packet Storm
342696 5.0 MEDIUM
arabless saphplesson SaphpLesson 3.0 does not initialize array variables, which allows remote attackers to obtain the full path via an non-array (1) hrow parameter to (a) show.php or (b) index.php; the (2) Lsnrow paramet… NVD-CWE-Other
CVE-2006-2278 2018-10-19 01:38 2006-05-10 Show GitHub Exploit DB Packet Storm
342697 7.5 HIGH
arabless saphplesson Multiple SQL injection vulnerabilities in SaphpLesson 3.0 allow remote attackers to execute arbitrary SQL commands via (1) the Find parameter in (a) search.php, and the (2) LID and (3) Rate parameter… NVD-CWE-Other
CVE-2006-2279 2018-10-19 01:38 2006-05-10 Show GitHub Exploit DB Packet Storm
342698 5.0 MEDIUM
openengine openengine Directory traversal vulnerability in website.php in openEngine 1.8 Beta 2 and earlier allows remote attackers to list arbitrary directories and read arbitrary files via a .. (dot dot) in the template… NVD-CWE-Other
CVE-2006-2280 2018-10-19 01:38 2006-05-10 Show GitHub Exploit DB Packet Storm
342699 7.5 HIGH
x-scripts x-poll X-Scripts X-Poll (xpoll) 2.30 allows remote attackers to execute arbitrary PHP code by using admin/images/add.php to upload a PHP file, then access it. CWE-94
Code Injection
CVE-2006-2281 2018-10-19 01:38 2006-05-10 Show GitHub Exploit DB Packet Storm
342700 4.3 MEDIUM
x7_group x7_chat Cross-site scripting (XSS) vulnerability in X7 Chat 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the URL of an avatar, possibly related to … NVD-CWE-Other
CVE-2006-2282 2018-10-19 01:38 2006-05-10 Show GitHub Exploit DB Packet Storm