Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2121 9.8 緊急
Network
ThemeMove UniCamp ThemeMoveのWordPress用UniCampにおけるPHP リモートファイルインクルージョンの脆弱性 CWE-98
PHP リモートファイルインクルージョン
CVE-2025-54701 2026-02-6 10:40 2025-08-14 Show GitHub Exploit DB Packet Storm
2122 5.3 警告
Network
Codeshare Codeshare Codeshareにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2025-60925 2026-02-6 10:40 2025-11-4 Show GitHub Exploit DB Packet Storm
2123 6.1 警告
Network
Zucchetti s.p.a. Infinity Zucchetti
ZMaintenance Infinity
Zucchetti s.p.a.のZMaintenance Infinity等の複数製品におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-61431 2026-02-6 10:40 2025-11-4 Show GitHub Exploit DB Packet Storm
2124 9.1 緊急
Network
Shopify remix-run/deno
@remix-run/node
@react-router/node
Shopifyの@react-router/node等の複数製品におけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2025-61686 2026-02-6 10:40 2026-01-10 Show GitHub Exploit DB Packet Storm
2125 9.8 緊急
Network
EUROLAB srl ELTS 100 Firmware EUROLAB srlのELTS 100 Firmwareにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2025-63225 2026-02-6 10:40 2025-11-18 Show GitHub Exploit DB Packet Storm
2126 3.5
Adjacent
Freebox Freebox One Firmware
Freebox v5 HD Firmware
Freebox v5 Crystal Firmware
Freebox v6 Revolution Firmware
Freebox Mini 4K&nbs…
FreeboxのFreebox Mini 4K Firmware等の複数製品における重要な情報の平文での送信に関する脆弱性 CWE-319
重要な情報の平文での送信
CVE-2025-63292 2026-02-6 10:40 2025-11-17 Show GitHub Exploit DB Packet Storm
2127 6.5 警告
Network
workdo HRM SaaS WorkDoのHRM SaaSにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2025-63294 2026-02-6 10:40 2025-11-4 Show GitHub Exploit DB Packet Storm
2128 7.5 重要
Network
kiloview E3 Firmware Kiloview Electronics Co., Ltd.のE3 Firmwareにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2025-63560 2026-02-6 10:40 2025-11-6 Show GitHub Exploit DB Packet Storm
2129 6.5 警告
Network
GuoMinJim PersonManage GuoMinJimのPersonManageにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2025-63686 2026-02-6 10:40 2025-11-7 Show GitHub Exploit DB Packet Storm
2130 5.4 警告
Network
Magento, Inc. E-Commerce Bhabishya-123のE-commerceにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-63883 2026-02-6 10:40 2025-11-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
348161 - symantec norton_antivirus
norton_internet_security
norton_system_works
The SmartScan feature in the Auto-Protect module for Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denia… NVD-CWE-Other
CVE-2005-0923 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
348162 - web-app.org webapp Unknown vulnerability in subs.pl for WebAPP 0.9.9 through 0.9.9.2 has unknown impact and attack vectors, probably involving shell metacharacters or .. sequences. NVD-CWE-Other
CVE-2005-0927 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
348163 - chatness chatness Cross-site scripting (XSS) vulnerability in message.php in Chatness 2.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the user field or (2) the message paramete… NVD-CWE-Other
CVE-2005-0930 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
348164 - jimmy the_includer PHP remote file inclusion vulnerability in The Includer 1.0 and 1.1 allows remote attackers to execute arbitrary PHP code. NVD-CWE-Other
CVE-2005-0931 2008-09-6 05:47 2005-03-29 Show GitHub Exploit DB Packet Storm
348165 - wackowiki wackowiki Multiple cross-site scripting (XSS) vulnerabilities in WackoWiki R4 allow remote attackers to inject arbitrary web script or HTML via unknown vectors. NVD-CWE-Other
CVE-2005-0934 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
348166 - yepyep mtftpd Buffer overflow in the mt_do_dir function in YepYep mtftpd 0.0.3 may allow attackers to execute arbitrary code via a long path. NVD-CWE-Other
CVE-2005-0959 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
348167 - openbsd openbsd Multiple vulnerabilities in the SACK functionality in (1) tcp_input.c and (2) tcp_usrreq.c OpenBSD 3.5 and 3.6 allow remote attackers to cause a denial of service (memory exhaustion or system crash). NVD-CWE-Other
CVE-2005-0960 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
348168 - horde application_framework Cross-site scripting (XSS) vulnerability in Horde 3.0.4 before 3.0.4-RC2 allows remote attackers to inject arbitrary web script or HTML via the parent frame title. NVD-CWE-Other
CVE-2005-0961 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
348169 - apple mac_os_x Heap-based buffer overflow in the syscall emulation functionality in Mac OS X before 10.3.9 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via craf… NVD-CWE-Other
CVE-2005-0969 2008-09-6 05:47 2005-05-12 Show GitHub Exploit DB Packet Storm
348170 - apple mac_os_x Stack-based buffer overflow in the semop system call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments. NVD-CWE-Other
CVE-2005-0971 2008-09-6 05:47 2005-05-12 Show GitHub Exploit DB Packet Storm