Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
187361 5.8 警告 EmoryM - Android 用 Android_Pusher ライブラリにおける SSL サーバを偽装される脆弱性 CWE-20
不適切な入力確認
CVE-2012-5813 2012-11-7 17:38 2012-11-4 Show GitHub Exploit DB Packet Storm
187362 5.8 警告 ACRA - Android 用 ACRA ライブラリにおける SSL サーバを偽装される脆弱性 CWE-20
不適切な入力確認
CVE-2012-5812 2012-11-7 17:38 2012-11-4 Show GitHub Exploit DB Packet Storm
187363 5.8 警告 Zen Cart
First Data
- Zen Cart の LinkPoint モジュールにおける SSL サーバを偽装される脆弱性 CWE-20
不適切な入力確認
CVE-2012-5808 2012-11-7 16:40 2012-11-4 Show GitHub Exploit DB Packet Storm
187364 5.8 警告 Zen Cart
Authorize.Net
- Zen Cart の Authorize.Net eCheck モジュールにおける SSL サーバを偽装される脆弱性 CWE-20
不適切な入力確認
CVE-2012-5807 2012-11-7 16:39 2012-11-4 Show GitHub Exploit DB Packet Storm
187365 5.8 警告 Zen Cart
PayPal
- Zen Cart の PayPal Payments Pro モジュールにおける SSL サーバを偽装される脆弱性 CWE-20
不適切な入力確認
CVE-2012-5806 2012-11-7 16:37 2012-11-4 Show GitHub Exploit DB Packet Storm
187366 5.8 警告 Zen Cart
PayPal
- Zen Cart の PayPal IPN 機能における SSL サーバを偽装される脆弱性 CWE-20
不適切な入力確認
CVE-2012-5805 2012-11-7 16:36 2012-11-4 Show GitHub Exploit DB Packet Storm
187367 5.8 警告 CyberSource Corporation
Ubercart
- Ubercart の CyberSource モジュールにおける SSL サーバを偽装される脆弱性 CWE-20
不適切な入力確認
CVE-2012-5804 2012-11-7 16:35 2012-11-4 Show GitHub Exploit DB Packet Storm
187368 5.8 警告 Hassan Consulting
Ubercart
- Ubercart の Authorize.Net モジュールにおける SSL サーバを偽装される脆弱性 CWE-20
不適切な入力確認
CVE-2012-5803 2012-11-7 16:34 2012-11-4 Show GitHub Exploit DB Packet Storm
187369 5.8 警告 Ubercart - Ubercart の PayPal モジュールにおける SSL サーバを偽装される脆弱性 CWE-20
不適切な入力確認
CVE-2012-5802 2012-11-7 16:34 2012-11-4 Show GitHub Exploit DB Packet Storm
187370 5.8 警告 PrestaShop - PrestaShop の PayPal モジュールにおける SSL サーバを偽装される脆弱性 CWE-20
不適切な入力確認
CVE-2012-5801 2012-11-7 16:33 2012-11-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 10, 2025, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
278421 - pmachine pmachine_pro Cross-site scripting (XSS) vulnerability in pm/language/spanish/preferences.php in PMachine Pro 2.4.1 allows remote attackers to inject arbitrary web script or HTML via the L_PREF_NAME[855] parameter. CWE-79
Cross-site Scripting
CVE-2008-0334 2008-09-6 06:34 2008-01-18 Show GitHub Exploit DB Packet Storm
278422 - mahara mahara Unspecified vulnerability in Mahara before 0.9.1 has unknown impact and remote attack vectors, probably related to cross-site scripting (XSS) in uploaded files. CWE-79
Cross-site Scripting
CVE-2008-0381 2008-09-6 06:34 2008-01-23 Show GitHub Exploit DB Packet Storm
278423 - bcoos event_calendar Cross-site scripting (XSS) vulnerability in modules/ecal/display.php in the Event Calendar in bcoos 1.0.10 allows remote attackers to inject arbitrary web script or HTML via the month parameter. NOT… CWE-79
Cross-site Scripting
CVE-2007-6365 2008-09-6 06:33 2007-12-15 Show GitHub Exploit DB Packet Storm
278424 - e-xoops e-xoops Multiple SQL injection vulnerabilities in e-Xoops (exoops) 1.08, and 1.05 Rev 1 through 3, allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to (a) mylinks/ratelink.p… CWE-89
SQL Injection
CVE-2007-6380 2008-09-6 06:33 2007-12-15 Show GitHub Exploit DB Packet Storm
278425 - serendipity serendipity Cross-site request forgery (CSRF) vulnerability in the mycalendar plugin before 0.13 for Serendipity allows remote attackers to perform actions as blog administrators, which can be leveraged to condu… CWE-352
 Origin Validation Error
CVE-2007-6390 2008-09-6 06:33 2007-12-18 Show GitHub Exploit DB Packet Storm
278426 - debian debian_linux scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute arbitrary code by invoking scp, as implemented by OpenSSH, with the -F and -o options. CWE-94
Code Injection
CVE-2007-6415 2008-09-6 06:33 2008-01-25 Show GitHub Exploit DB Packet Storm
278427 - anon_proxy_server anon_proxy_server Multiple cross-site scripting (XSS) vulnerabilities in Anon Proxy Server before 0.101 allow remote attackers to inject arbitrary web script or HTML via the URI, which is later displayed by (1) log.ph… CWE-79
Cross-site Scripting
CVE-2007-6460 2008-09-6 06:33 2007-12-20 Show GitHub Exploit DB Packet Storm
278428 - phprpg phprpg SQL injection vulnerability in index.php in phpRPG 0.8, when magic_qutoes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these d… CWE-89
SQL Injection
CVE-2007-6469 2008-09-6 06:33 2007-12-20 Show GitHub Exploit DB Packet Storm
278429 - phprpg phprpg phpRPG 0.8 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read session ID values in files under tmp/, and then hijack sessions via … CWE-264
Permissions, Privileges, and Access Controls
CVE-2007-6470 2008-09-6 06:33 2007-12-20 Show GitHub Exploit DB Packet Storm
278430 - phprpg phprpg SQL injection vulnerability in index.php in phpRPG 0.8 allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: the provenance of this information is unknown; the … CWE-89
SQL Injection
CVE-2007-6484 2008-09-6 06:33 2007-12-21 Show GitHub Exploit DB Packet Storm