Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Nov. 17, 2024, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
191771 7.5 危険 discountedscripts - ACG-PTP の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3944 2012-06-26 16:02 2008-09-5 Show GitHub Exploit DB Packet Storm
191772 7.5 危険 ezonescripts - eZoneScripts Living Local の listtest.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3943 2012-06-26 16:02 2008-09-5 Show GitHub Exploit DB Packet Storm
191773 4.3 警告 bizdirectory - BizDirectory におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3941 2012-06-26 16:02 2008-09-5 Show GitHub Exploit DB Packet Storm
191774 5 警告 AVTECH - AVTECH PageR Enterprise の Web インターフェースにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-3939 2012-06-26 16:02 2008-09-5 Show GitHub Exploit DB Packet Storm
191775 7.8 危険 DreamBox - Dreambox DM500C の Web インターフェースにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2008-3936 2012-06-26 16:02 2008-09-5 Show GitHub Exploit DB Packet Storm
191776 9.3 危険 EZB Systems - UltraISO におけるフォーマットストリングの脆弱性 CWE-134
書式文字列の問題
CVE-2008-3871 2012-06-26 16:02 2009-04-1 Show GitHub Exploit DB Packet Storm
191777 6.9 警告 Debian - Citadel Server の migrate_aliases.sh における任意のファイルを上書きされる脆弱性 CWE-59
リンク解釈の問題
CVE-2008-3930 2012-06-26 16:02 2008-08-24 Show GitHub Exploit DB Packet Storm
191778 7.2 危険 Ampache.org - Ampache の gather-messages.sh における任意のファイルを上書きされる脆弱性 CWE-59
リンク解釈の問題
CVE-2008-3929 2012-06-26 16:02 2008-09-4 Show GitHub Exploit DB Packet Storm
191779 6.9 警告 Debian - Honeyd の test.sh における任意のファイルを上書きされる脆弱性 CWE-59
リンク解釈の問題
CVE-2008-3928 2012-06-26 16:02 2008-08-24 Show GitHub Exploit DB Packet Storm
191780 7.5 危険 bitlbee - BitlBee における既存のアカウントを "再作成" される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-3920 2012-06-26 16:02 2008-09-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Nov. 17, 2024, 12:17 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
259191 - hp color_laserjet_3000
color_laserjet_3800
color_laserjet_4700
color_laserjet_4730_mfp
color_laserjet_5550
color_laserjet_9500_mfp
color_laserjet_cm6030_mfp
color_laserjet_cm6040_mf…
Directory traversal vulnerability in the PostScript Interpreter, as used on the HP LaserJet 4xxx, 5200, 90xx, M30xx, M4345, M50xx, M90xx, P3005, and P4xxx; LaserJet Enterprise P3015; Color LaserJet 3… NVD-CWE-noinfo
CVE-2012-5221 2013-12-31 13:19 2013-04-30 Show GitHub Exploit DB Packet Storm
259192 - wordpress wordpress Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows remote attackers to hijack the authentication of a… CWE-352
 Origin Validation Error
CVE-2013-7233 2013-12-31 10:42 2013-12-30 Show GitHub Exploit DB Packet Storm
259193 - adtran aos
netvanta_7060
netvanta_7100
Cross-site scripting (XSS) vulnerability in the GUI login page in ADTRAN AOS before R10.8.1 on the NetVanta 7100 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2013-5210 2013-12-31 10:34 2013-12-30 Show GitHub Exploit DB Packet Storm
259194 - hot hotbox_router_firmware
hotbox_router
goform/login on the HOT HOTBOX router with software 2.1.11 allows remote attackers to cause a denial of service (device crash) via crafted HTTP POST data. CWE-20
 Improper Input Validation 
CVE-2013-5220 2013-12-31 04:29 2013-12-30 Show GitHub Exploit DB Packet Storm
259195 - hot hotbox_router_firmware
hotbox_router
Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject arbitrary web script or HTML via a crafted DHCP Host Name option, which is not… CWE-79
Cross-site Scripting
CVE-2013-5218 2013-12-31 04:27 2013-12-30 Show GitHub Exploit DB Packet Storm
259196 - hot hotbox_router_firmware
hotbox_router
Directory traversal vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in a URI, as demonstrated by a request for /etc/pass… CWE-22
Path Traversal
CVE-2013-5219 2013-12-31 04:26 2013-12-30 Show GitHub Exploit DB Packet Storm
259197 - hot hotbox_router_firmware
hotbox_router
Cross-site request forgery (CSRF) vulnerability in goform/wlanBasicSecurity on the HOT HOTBOX router with software 2.1.11 allows remote attackers to hijack the authentication of administrators for re… CWE-352
 Origin Validation Error
CVE-2013-5039 2013-12-31 04:25 2013-12-30 Show GitHub Exploit DB Packet Storm
259198 - hot hotbox_router_firmware
hotbox_router
The HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP address that had previously been used for an authenticated session. CWE-287
Improper Authentication
CVE-2013-5038 2013-12-31 04:14 2013-12-30 Show GitHub Exploit DB Packet Storm
259199 - hot hotbox_router_firmware
hotbox_router
The HOT HOTBOX router with software 2.1.11 has a default WPS PIN of 12345670, which makes it easier for remote attackers to obtain the WPA or WPA2 pre-shared key via EAP messages. CWE-255
Credentials Management
CVE-2013-5037 2013-12-31 04:12 2013-12-30 Show GitHub Exploit DB Packet Storm
259200 - microsoft windows_movie_maker Microsoft Windows Movie Maker 2.1.4026.0 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) via a crafted .wav file, as demonstrated by movieMaker.wav. CWE-20
 Improper Input Validation 
CVE-2013-4858 2013-12-31 03:50 2013-12-30 Show GitHub Exploit DB Packet Storm