Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
201481 7.5 危険 bolinos - BolinOS の system/_b/contentFiles/gBHTMLEditor.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4851 2012-06-26 15:37 2006-09-18 Show GitHub Exploit DB Packet Storm
201482 5.1 警告 bolinos - BolinOS の system/_b/contentFiles/gBIndex.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4850 2012-06-26 15:37 2006-09-18 Show GitHub Exploit DB Packet Storm
201483 5.1 警告 シトリックス・システムズ - Citrix Access Gateway with AAC における認証を回避される脆弱性 - CVE-2006-4846 2012-06-26 15:37 2006-09-14 Show GitHub Exploit DB Packet Storm
201484 5.1 警告 george lewe - TeamCal Pro の includes/footer.html.inc.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4845 2012-06-26 15:37 2006-09-18 Show GitHub Exploit DB Packet Storm
201485 5.1 警告 Claroline Consortium
Dokeos
- Dokeos などの製品で使用される Claroline の inc/claro_init_local.inc.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-4844 2012-06-26 15:37 2006-09-18 Show GitHub Exploit DB Packet Storm
201486 4.3 警告 codeworx technologies - DCP-Portal SE におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-4838 2012-06-26 15:37 2006-09-15 Show GitHub Exploit DB Packet Storm
201487 7.5 危険 codeworx technologies - DCP-Portal SE における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4837 2012-06-26 15:37 2006-09-15 Show GitHub Exploit DB Packet Storm
201488 5.1 警告 codeworx technologies - DCP-Portal SE の login.php における SQL インジェクションの脆弱性 - CVE-2006-4836 2012-06-26 15:37 2006-09-15 Show GitHub Exploit DB Packet Storm
201489 5 警告 bluview - Bluview BMB における重要な情報を取得される脆弱性 - CVE-2006-4835 2012-06-26 15:37 2006-09-15 Show GitHub Exploit DB Packet Storm
201490 10 危険 blojsom - David Czarnecki Blojsom の EditBlogTemplatesPlugin.java におけるディレクトリトラバーサルの脆弱性 - CVE-2006-4830 2012-06-26 15:37 2006-09-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 26, 2025, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
266531 - phpmyadmin phpmyadmin phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection an… CWE-89
CWE-352
SQL Injection
 Origin Validation Error
CVE-2008-1149 2017-08-8 10:29 2008-03-5 Show GitHub Exploit DB Packet Storm
266532 - cisco emergency_responder
mobility_manager
unified_communications_manager
unified_presence
The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and 6.x, Unified Presence 1.x and 6.x, Emergency Resp… CWE-287
Improper Authentication
CVE-2008-1154 2017-08-8 10:29 2008-04-5 Show GitHub Exploit DB Packet Storm
266533 - cisco network_admission_control Cisco Network Admission Control (NAC) Appliance 3.5.x, 3.6.x before 3.6.4.4, 4.0.x before 4.0.6, and 4.1.x before 4.1.2 allows remote attackers to obtain the shared secret for the Clean Access Server… CWE-200
Information Exposure
CVE-2008-1155 2017-08-8 10:29 2008-04-17 Show GitHub Exploit DB Packet Storm
266534 - cisco ciscoworks_internetwork_performance_monitor Cisco CiscoWorks Internetwork Performance Monitor (IPM) 2.6 creates a process that executes a command shell and listens on a randomly chosen TCP port, which allows remote attackers to execute arbitra… CWE-20
 Improper Input Validation 
CVE-2008-1157 2017-08-8 10:29 2008-03-15 Show GitHub Exploit DB Packet Storm
266535 - cisco unified_presence
unified_presence_server
The Presence Engine (PE) service in Cisco Unified Presence before 6.0(1) allows remote attackers to cause a denial of service (core dump and service interruption) via malformed packets, aka Bug ID CS… CWE-20
 Improper Input Validation 
CVE-2008-1158 2017-08-8 10:29 2008-05-16 Show GitHub Exploit DB Packet Storm
266536 - flyspray flyspray Multiple cross-site scripting (XSS) vulnerabilities in Flyspray 0.9.9 through 0.9.9.4 allow remote attackers to inject arbitrary web script or HTML via (1) a forced SQL error message or (2) old_value… CWE-79
Cross-site Scripting
CVE-2008-1165 2017-08-8 10:29 2008-03-6 Show GitHub Exploit DB Packet Storm
266537 - sarg squid_analysis_report_generator Cross-site scripting (XSS) vulnerability in Squid Analysis Report Generator (Sarg) 2.2.3.1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent header, which is not prope… CWE-79
Cross-site Scripting
CVE-2008-1168 2017-08-8 10:29 2008-03-6 Show GitHub Exploit DB Packet Storm
266538 - simm-comm sci_photo_chat Directory traversal vulnerability in the embedded HTTP server in SCI Photo Chat Server 3.4.9 and earlier allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) or "../" (dot … CWE-22
Path Traversal
CVE-2008-1169 2017-08-8 10:29 2008-03-6 Show GitHub Exploit DB Packet Storm
266539 - centreon centreon Multiple cross-site scripting (XSS) vulnerabilities in include/common/javascript/color_picker.php in Centreon 1.4.2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the… CWE-79
Cross-site Scripting
CVE-2008-1179 2017-08-8 10:29 2008-03-6 Show GitHub Exploit DB Packet Storm
266540 - bsd_perimeter pfsense Cross-site scripting (XSS) vulnerability in BSD Perimeter pfSense before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2008-1182 2017-08-8 10:29 2008-03-6 Show GitHub Exploit DB Packet Storm