Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
193071 7.5 危険 noname media - Noname Media Photo Galerie Standard の view.php における SQL インジェクションの脆弱性 - CVE-2007-0786 2012-09-25 16:47 2007-02-6 Show GitHub Exploit DB Packet Storm
193072 7.8 危険 Linux - Linux kernel におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2007-0772 2012-09-25 16:47 2007-02-20 Show GitHub Exploit DB Packet Storm
193073 6.8 警告 Phorum - Phorum の core におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-0767 2012-09-25 16:47 2007-01-26 Show GitHub Exploit DB Packet Storm
193074 7.5 危険 miguel nunes - MiGCMS における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-0757 2012-09-25 16:47 2007-02-5 Show GitHub Exploit DB Packet Storm
193075 6.8 警告 mentiss acgv - ACGVannu における SQL インジェクションの脆弱性 - CVE-2007-0698 2012-09-25 16:47 2007-02-3 Show GitHub Exploit DB Packet Storm
193076 6.4 警告 mentiss acgv - ACGVannu の index2.php におけるパスワードなどを変更される脆弱性 - CVE-2007-0697 2012-09-25 16:47 2007-02-3 Show GitHub Exploit DB Packet Storm
193077 5 警告 myevent - myEvent における重要な情報を取得される脆弱性 - CVE-2007-0690 2012-09-25 16:47 2007-05-30 Show GitHub Exploit DB Packet Storm
193078 5 警告 MyBB Group - MyBB における重要な情報を取得される脆弱性 - CVE-2007-0689 2012-09-25 16:47 2007-05-14 Show GitHub Exploit DB Packet Storm
193079 7.5 危険 hunkaray duyuru - Hunkaray Duyuru Scripti における SQL インジェクションの脆弱性 - CVE-2007-0688 2012-09-25 16:47 2007-02-2 Show GitHub Exploit DB Packet Storm
193080 6.5 警告 michelle - Michelle's L2J Dropcalc の i-search.php における SQL インジェクションの脆弱性 - CVE-2007-0687 2012-09-25 16:47 2007-02-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 13, 2025, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
266881 - newsphp newsphp Cross-site scripting (XSS) vulnerability in index.php in NewsPHP allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter. NOTE: this issue might overlap vector 3 in C… CWE-79
Cross-site Scripting
CVE-2004-2688 2017-07-29 10:29 2004-12-31 Show GitHub Exploit DB Packet Storm
266882 - newsphp newsphp NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the "autorized=admin; root=admin" value. CWE-264
Permissions, Privileges, and Access Controls
CVE-2004-2689 2017-07-29 10:29 2004-12-31 Show GitHub Exploit DB Packet Storm
266883 - newsphp newsphp Unrestricted file upload vulnerability in the Administration Panel for NewsPHP allows remote authenticated administrators to upload and execute arbitrary code instead of video files. NVD-CWE-Other
CVE-2004-2690 2017-07-29 10:29 2004-12-31 Show GitHub Exploit DB Packet Storm
266884 - 3com 3c17205-us
3c17210-us
superstack_3_switch
Unspecified vulnerability in 3Com SuperStack 3 4400 switches with firmware version before 3.31 allows remote attackers to cause a denial of service (device reset) via a crafted request to the web man… NVD-CWE-Other
CVE-2004-2691 2017-07-29 10:29 2004-12-31 Show GitHub Exploit DB Packet Storm
266885 - kyberdigi_labs php-exec-dir The exec_dir PHP patch (php-exec-dir) 4.3.2 through 4.3.7 with safe mode disabled allows remote attackers to bypass restrictions and execute arbitrary commands via a backtick operator, which is not h… CWE-16
CWE-264
Configuration
Permissions, Privileges, and Access Controls
CVE-2004-2692 2017-07-29 10:29 2004-12-31 Show GitHub Exploit DB Packet Storm
266886 - bea weblogic_server BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, when using Remote Method Invocation (RMI) over Internet Inter-ORB Protocol (IIOP), does not properly handle when multiple logins for differ… CWE-255
Credentials Management
CVE-2004-2696 2017-07-29 10:29 2004-12-31 Show GitHub Exploit DB Packet Storm
266887 - ibm aix The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack on a command line argument (log file). NOTE: this might be r… CWE-362
Race Condition
CVE-2004-2697 2017-07-29 10:29 2004-12-31 Show GitHub Exploit DB Packet Storm
266888 - imwheel imwheel Race condition in IMWheel 1.0.0pre11 and earlier, when running with the -k option, allows local users to cause a denial of service (IMWheel crash) and possibly modify arbitrary files via a symlink at… CWE-362
Race Condition
CVE-2004-2698 2017-07-29 10:29 2004-12-31 Show GitHub Exploit DB Packet Storm
266889 - aspdotnetstorefront aspdotnetstorefront deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified ProductID parameter. CWE-264
Permissions, Privileges, and Access Controls
CVE-2004-2699 2017-07-29 10:29 2004-12-31 Show GitHub Exploit DB Packet Storm
266890 - aspdotnetstorefront aspdotnetstorefront Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter. CWE-79
Cross-site Scripting
CVE-2004-2701 2017-07-29 10:29 2004-12-31 Show GitHub Exploit DB Packet Storm