Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 31, 2025, 4:03 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
193561 7.5 危険 photo organizer - Photo Organizer における SQL インジェクションの脆弱性 - CVE-2006-6245 2012-09-25 15:36 2006-12-4 Show GitHub Exploit DB Packet Storm
193562 7.5 危険 MailEnable - MailEnbale NetWebAdmin の Webadmin における空のパスワードを認証される脆弱性 CWE-255
証明書・パスワード管理
CVE-2006-6239 2012-09-25 15:36 2006-12-3 Show GitHub Exploit DB Packet Storm
193563 5 警告 neoengine - NeoEngine 用などの neonet/core.cpp におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2006-6227 2012-09-25 15:36 2006-06-27 Show GitHub Exploit DB Packet Storm
193564 7.5 危険 neoengine - NeoEngine などにおけるフォーマットストリングの脆弱性 - CVE-2006-6226 2012-09-25 15:36 2006-06-27 Show GitHub Exploit DB Packet Storm
193565 7.5 危険 nivisec - Nivisec Hacks List の admin_hacks_list.php における SQL インジェクションの脆弱性 - CVE-2006-6216 2012-09-25 15:36 2006-11-30 Show GitHub Exploit DB Packet Storm
193566 7.5 危険 pegames - PEGames の index.php における PHP リモートファイルインクルージョン攻撃を実行される脆弱性 - CVE-2006-6213 2012-09-25 15:36 2006-11-30 Show GitHub Exploit DB Packet Storm
193567 7.5 危険 iisworks - ASP ListPics の listpics.asp における SQL インジェクションの脆弱性 - CVE-2006-6210 2012-09-25 15:36 2006-11-30 Show GitHub Exploit DB Packet Storm
193568 7.5 危険 midicart software - MidiCart ASP Shopping Cart などにおける SQL インジェクションの脆弱性 - CVE-2006-6209 2012-09-25 15:36 2006-11-30 Show GitHub Exploit DB Packet Storm
193569 5 警告 krishan - Mambo の flyspray コンポーネントにおけるディレクトリトラバーサルの脆弱性 - CVE-2006-6203 2012-09-25 15:36 2006-11-30 Show GitHub Exploit DB Packet Storm
193570 7.5 危険 nukeai - NukeAI モジュールの modules/NukeAI/util.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-6202 2012-09-25 15:36 2006-11-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 31, 2025, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
269751 - mozilla bugzilla Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to view the password in the web server log files. NVD-CWE-Other
CVE-2004-0706 2017-07-11 10:30 2004-07-27 Show GitHub Exploit DB Packet Storm
269752 - mozilla bugzilla SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allows remote attackers with privileges to grant membership to any group to execute arbitrary S… NVD-CWE-Other
CVE-2004-0707 2017-07-11 10:30 2004-07-27 Show GitHub Exploit DB Packet Storm
269753 - moinmoin moinmoin MoinMoin 1.2.1 and earlier allows remote attackers to gain privileges by creating a user with the same name as an existing group that has higher privileges. NVD-CWE-Other
CVE-2004-0708 2017-07-11 10:30 2004-07-27 Show GitHub Exploit DB Packet Storm
269754 - hp openview_select_access HP OpenView Select Access 5.0 through 6.0 does not correctly decode UTF-8 encoded unicode characters in a URL, which could allow remote attackers to bypass access restrictions. NVD-CWE-Other
CVE-2004-0709 2017-07-11 10:30 2004-07-27 Show GitHub Exploit DB Packet Storm
269755 - bea weblogic_server The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in "*" as wildcards as if they were the legal "/*" pattern, which could cause WebLogic 7.x to allow remote … NVD-CWE-Other
CVE-2004-0711 2017-07-11 10:30 2004-07-27 Show GitHub Exploit DB Packet Storm
269756 - bea weblogic_server The configuration tools (1) config.sh in Unix or (2) config.cmd in Windows for BEA WebLogic Server 8.1 through SP2 create a log file that contains the administrative username and password in cleartex… NVD-CWE-Other
CVE-2004-0712 2017-07-11 10:30 2004-07-27 Show GitHub Exploit DB Packet Storm
269757 - bea weblogic_server The remove method in a stateful Enterprise JavaBean (EJB) in BEA WebLogic Server and WebLogic Express version 8.1 through SP2, 7.0 through SP4, and 6.1 through SP6, does not properly check EJB permis… NVD-CWE-Other
CVE-2004-0713 2017-07-11 10:30 2004-07-27 Show GitHub Exploit DB Packet Storm
269758 - bea weblogic_server The WebLogic Authentication provider for BEA WebLogic Server and WebLogic Express 8.1 through SP2 and 7.0 through SP4 does not properly clear member relationships when a group is deleted, which can c… NVD-CWE-Other
CVE-2004-0715 2017-07-11 10:30 2004-07-27 Show GitHub Exploit DB Packet Storm
269759 - apple safari Safari 1.2.2 does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame i… NVD-CWE-Other
CVE-2004-0720 2017-07-11 10:30 2004-07-27 Show GitHub Exploit DB Packet Storm
269760 - microsoft java_virtual_machine Microsoft Java virtual machine (VM) 5.0.0.3810 allows remote attackers to bypass sandbox restrictions to read or write certain data between applets from different domains via the "GET/Key" and "PUT/K… NVD-CWE-Other
CVE-2004-0723 2017-07-11 10:30 2004-07-27 Show GitHub Exploit DB Packet Storm