Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Oct. 2, 2024, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
191471 7.5 危険 eazy cart - Eazy Cart における管理アクセス権を取得される脆弱性 - CVE-2006-5245 2012-06-26 15:37 2006-10-11 Show GitHub Exploit DB Packet Storm
191472 7.5 危険 Etomite Project - Etomite CMS における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2006-5242 2012-06-26 15:37 2006-10-11 Show GitHub Exploit DB Packet Storm
191473 5.1 警告 docmint - Docmint の engine/require.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5240 2012-06-26 15:37 2006-10-11 Show GitHub Exploit DB Packet Storm
191474 4.3 警告 expblog - eXpBlog におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2006-5239 2012-06-26 15:37 2006-10-11 Show GitHub Exploit DB Packet Storm
191475 10 危険 blue smiley organizer - Blue Smiley Organizer のファイルアップロードモジュールにおける詳細不明な脆弱性 - CVE-2006-5238 2012-06-26 15:37 2006-10-11 Show GitHub Exploit DB Packet Storm
191476 7.5 危険 blue smiley organizer - Blue Smiley Organizer における SQL インジェクションの脆弱性 - CVE-2006-5237 2012-06-26 15:37 2006-10-11 Show GitHub Exploit DB Packet Storm
191477 7.5 危険 4homepages - 4images の search.php における SQL インジェクションの脆弱性 - CVE-2006-5236 2012-06-26 15:37 2006-10-10 Show GitHub Exploit DB Packet Storm
191478 7.5 危険 dimension of phpbb - phpBB の Dimension の includes/functions_kb.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5235 2012-06-26 15:37 2006-10-10 Show GitHub Exploit DB Packet Storm
191479 7.8 危険 Grandstream Networks - Grandstream GXP-2000 VoIP Desktop Phone におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2006-5231 2012-06-26 15:37 2006-10-10 Show GitHub Exploit DB Packet Storm
191480 7.5 危険 freeforum - FreeForum の forum.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5230 2012-06-26 15:37 2006-10-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Oct. 3, 2024, 5:55 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2341 - - - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escaping of Output, CWE - 83 Improper Neutralization of Script in Attributes in a Web… CWE-79
CWE-116
Cross-site Scripting
 Improper Encoding or Escaping of Output
CVE-2024-7873 2024-09-20 21:30 2024-09-17 Show GitHub Exploit DB Packet Storm
2342 - - - FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_directory - CVE-2024-46362 2024-09-20 21:30 2024-09-17 Show GitHub Exploit DB Packet Storm
2343 - - - FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/rename - CVE-2024-46085 2024-09-20 21:30 2024-09-17 Show GitHub Exploit DB Packet Storm
2344 - - - On Windows systems, the Arc configuration files resulted to be world-readable. This can lead to information disclosure by local attackers, via exfiltration of sensitive data from configuration fil… - CVE-2023-5937 2024-09-20 21:15 2024-05-16 Show GitHub Exploit DB Packet Storm
2345 - - - Audit records for OpenAPI requests may include sensitive information. This could lead to unauthorized accesses and privilege escalation. - CVE-2023-6916 2024-09-20 21:15 2024-04-11 Show GitHub Exploit DB Packet Storm
2346 7.5 HIGH
Network
nozominetworks cmc
guardian
A missing authentication check in the WebSocket channel used for the Check Point IoT integration in Nozomi Networks Guardian and CMC, may allow an unauthenticated attacker to obtain assets data witho… CWE-306
Missing Authentication for Critical Function
CVE-2023-5253 2024-09-20 21:15 2024-01-15 Show GitHub Exploit DB Packet Storm
2347 4.3 MEDIUM
Network
nozominetworks cmc
guardian
A partial DoS vulnerability has been detected in the Reports section, exploitable by a malicious authenticated user forcing a report to be saved with its name set as null. The reports section will b… NVD-CWE-noinfo
CVE-2023-24015 2024-09-20 21:15 2023-08-9 Show GitHub Exploit DB Packet Storm
2348 4.9 MEDIUM
Network
nozominetworks cmc
guardian
An authenticated administrator can upload a SAML configuration file with the wrong format, with the application not checking the correct file format. Every subsequent application request will return … NVD-CWE-noinfo
CVE-2023-23903 2024-09-20 21:15 2023-08-9 Show GitHub Exploit DB Packet Storm
2349 4.8 MEDIUM
Network
nozominetworks cmc
guardian
An authenticated attacker with administrative access to the web management interface can inject malicious JavaScript code inside the definition of a Threat Intelligence rule, that will be stored and … CWE-79
Cross-site Scripting
CVE-2023-22843 2024-09-20 21:15 2023-08-9 Show GitHub Exploit DB Packet Storm
2350 6.5 MEDIUM
Network
nozominetworks cmc
guardian
A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the sorting parameter, allows an authenticated attacker to execute arbitrary SQL statement… CWE-89
SQL Injection
CVE-2023-22378 2024-09-20 21:15 2023-08-9 Show GitHub Exploit DB Packet Storm