Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
193381 7.5 危険 open newsletter - Open Newsletter の settings.php などのスクリプトにおける不正な管理者の操作を実行される脆弱性 - CVE-2006-6785 2012-09-25 15:36 2006-12-27 Show GitHub Exploit DB Packet Storm
193382 7.5 危険 netbula - Netbula Anyboard における SQL インジェクションの脆弱性 - CVE-2006-6784 2012-09-25 15:36 2006-12-27 Show GitHub Exploit DB Packet Storm
193383 7.5 危険 logahead - logahead UNU における任意のファイルをアップロードされる脆弱性 CWE-287
不適切な認証
CVE-2006-6783 2012-09-25 15:36 2006-12-27 Show GitHub Exploit DB Packet Storm
193384 5 警告 hlstats - HLstats における重要な情報を取得される脆弱性 - CVE-2006-6781 2012-09-25 15:36 2006-12-27 Show GitHub Exploit DB Packet Storm
193385 9.4 危険 oftpd - oftpd におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2006-6767 2012-09-25 15:36 2007-01-16 Show GitHub Exploit DB Packet Storm
193386 7.5 危険 hlstats - HLstats のログインフォームにおける SQL インジェクションの脆弱性 - CVE-2006-6780 2012-09-25 15:36 2006-12-27 Show GitHub Exploit DB Packet Storm
193387 6.8 警告 vBulletin Solutions, Inc. - Jelsoft vBulletin におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6779 2012-09-25 15:36 2006-12-27 Show GitHub Exploit DB Packet Storm
193388 6.8 警告 irokez - Irokez CMS における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-6771 2012-09-25 15:36 2006-12-27 Show GitHub Exploit DB Packet Storm
193389 6.8 警告 jinzora - Jinzora Media Jukebox における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-6770 2012-09-25 15:36 2006-12-27 Show GitHub Exploit DB Packet Storm
193390 6.8 警告 php live - PHP Live! におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6769 2012-09-25 15:36 2006-12-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 8, 2025, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
267111 - the_address_book
the_address_book_reloaded
the_address_book
the_address_book_reloaded
Multiple SQL injection vulnerabilities in the authentication process in katzlbt (a) The Address Book 1.04e and earlier and (b) The Address Book Reloaded before 2.0-rc4 allow remote attackers to execu… NVD-CWE-Other
CVE-2006-4056 2017-07-20 10:32 2006-08-10 Show GitHub Exploit DB Packet Storm
267112 - cakefoundation cakephp Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in a 4… CWE-79
Cross-site Scripting
CVE-2006-4067 2017-07-20 10:32 2006-08-10 Show GitHub Exploit DB Packet Storm
267113 - mywebland myevent PHP remote file inclusion vulnerability in viewevent.php in myWebland myEvent 1.x allows remote attackers to execute arbitrary PHP code via a URL in the myevent_path parameter, a different vector tha… NVD-CWE-Other
CVE-2006-4083 2017-07-20 10:32 2006-08-11 Show GitHub Exploit DB Packet Storm
267114 - olaf_noehring the_search_engine_project PHP remote file inclusion vulnerability in Olaf Noehring The Search Engine Project (TSEP) 0.942 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tsep_config[absPath]… NVD-CWE-Other
CVE-2006-4085 2017-07-20 10:32 2006-08-11 Show GitHub Exploit DB Packet Storm
267115 - mojoscripts mojogallery Cross-site scripting (XSS) vulnerability in admin.cgi in mojoscripts.com mojoGallery allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: the provenance o… NVD-CWE-Other
CVE-2006-4087 2017-07-20 10:32 2006-08-11 Show GitHub Exploit DB Packet Storm
267116 - cisco secure_access_control_server Stack-based buffer overflow in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary … NVD-CWE-Other
CVE-2006-4098 2017-07-20 10:32 2006-12-31 Show GitHub Exploit DB Packet Storm
267117 - businessobjects crystal_enterprise Business Objects Crystal Enterprise 9 and 10 generates predictable session identifiers, which allows remote attackers to hijack sessions of other users via WCSID cookie values. NVD-CWE-Other
CVE-2006-4099 2017-07-20 10:32 2006-11-30 Show GitHub Exploit DB Packet Storm
267118 - mojoscripts mojogallery Cross-site scripting (XSS) vulnerability in admin.cgi in mojoscripts.com mojoGallery allows remote attackers to inject arbitrary web script or HTML via "password input." NVD-CWE-Other
CVE-2006-4104 2017-07-20 10:32 2006-08-15 Show GitHub Exploit DB Packet Storm
267119 - drupal job_search SQL injection vulnerability in the Job Search module (job.module) 4.6 before revision 1.3.2.1 in Drupal allows remote attackers to execute arbitrary SQL commands via a job or resume search. NVD-CWE-Other
CVE-2006-4107 2017-07-20 10:32 2006-08-15 Show GitHub Exploit DB Packet Storm
267120 - drupal bibliography_module SQL injection vulnerability in Bibliography (biblio.module) 4.6 before revision 1.1.1.1.4.11 and 4.7 before revision 1.13.2.5 for Drupal allows remote attackers to execute arbitrary SQL commands via … NVD-CWE-Other
CVE-2006-4108 2017-07-20 10:32 2006-08-15 Show GitHub Exploit DB Packet Storm