Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
193931 4.3 警告 idevSpot - IDevSpot iSupport におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-4884 2012-09-25 15:35 2006-09-19 Show GitHub Exploit DB Packet Storm
193932 4.3 警告 idevSpot - IDevSpot BizDirectory におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-4883 2012-09-25 15:35 2006-09-19 Show GitHub Exploit DB Packet Storm
193933 7.5 危険 jupiter cms - Jupiter CMS における SQL インジェクションの脆弱性 - CVE-2006-4876 2012-09-25 15:35 2006-09-19 Show GitHub Exploit DB Packet Storm
193934 5 警告 jupiter cms - Jupiter CMS におけるピクチャファイルをアップロードされる脆弱性 - CVE-2006-4875 2012-09-25 15:35 2006-09-19 Show GitHub Exploit DB Packet Storm
193935 4.3 警告 jupiter cms - Jupiter CMS におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-4874 2012-09-25 15:35 2006-09-19 Show GitHub Exploit DB Packet Storm
193936 5 警告 jupiter cms - Jupiter CMS における重要な情報を取得される脆弱性 - CVE-2006-4873 2012-09-25 15:35 2006-09-19 Show GitHub Exploit DB Packet Storm
193937 7.5 危険 keyvan1 - Keyvan1 ECardPro の search.asp における SQL インジェクションの脆弱性 - CVE-2006-4872 2012-09-25 15:35 2006-09-19 Show GitHub Exploit DB Packet Storm
193938 7.5 危険 keyvan1 - Keyvan1 EShoppingPro の search_run.asp における SQL インジェクションの脆弱性 - CVE-2006-4871 2012-09-25 15:35 2006-09-19 Show GitHub Exploit DB Packet Storm
193939 7.5 危険 perlunity - phpunity.postcard の phpunity-postcard.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-4869 2012-09-25 15:35 2006-09-19 Show GitHub Exploit DB Packet Storm
193940 7.5 危険 mohammed mehdi panjwani - Mohammed Mehdi Panjwani Complain Center の loginprocess.asp における SQL インジェクションの脆弱性 - CVE-2006-4861 2012-09-25 15:35 2006-09-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 5, 2025, 4:56 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
269731 - zanfi_solutions zanfi_cms_lite Zanfi CMS lite 1.1 allows remote attackers to obtain the full path of the web server via direct requests without required arguments to (1) adm_pages.php, (2) corr_pages.php, (3) del_block.php, (4) de… NVD-CWE-Other
CVE-2004-2196 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
269732 - kdocker kdocker kdocker.cpp in kdocker 0.1 through 0.8 does not properly check the ownership of files, which could allow local users to execute arbitrary programs. NVD-CWE-Other
CVE-2004-2197 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
269733 - duware duclassmate account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_recordId parameter on the "My Account" page. NVD-CWE-Other
CVE-2004-2198 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
269734 - duware duclassified Cross-site scripting (XSS) vulnerability in DUware DUclassified 4.0 allows remote attackers to inject arbitrary web script or HTML via the message text. NVD-CWE-Other
CVE-2004-2199 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
269735 - duware duforum Cross-site scripting (XSS) vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to inject arbitrary web script or HTML via via the message text. NVD-CWE-Other
CVE-2004-2200 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
269736 - duware duforum SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID parameter in messages.asp, (2) MSG_ID parameter in messageDetail… NVD-CWE-Other
CVE-2004-2201 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
269737 - duware duclassified Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute other commands on the server's underlying database via the (… NVD-CWE-Other
CVE-2004-2202 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
269738 - ansel ansel Ansel 1.2 through 2.0 uses insecure default permissions, which allows remote attackers to gain access to web readable directories. NVD-CWE-Other
CVE-2004-2203 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
269739 - macromedia coldfusion Macromedia ColdFusion MX 6.0 and 6.1 application server, when running with the CreateObject function or CFOBJECT tag enabled, allows local users to conduct unauthorized activities and obtain administ… NVD-CWE-Other
CVE-2004-2204 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
269740 - symantec_veritas cluster_server Unknown vulnerability in Veritas Cluster Server 1.0.1 through 4.0 allows local users to gain root access via unspecified vectors. NVD-CWE-Other
CVE-2004-2205 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm