Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227691 7.5 危険 phpecard - phpECard の functions.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4456 2012-12-20 18:02 2006-08-31 Show GitHub Exploit DB Packet Storm
227692 4.3 警告 PmWiki - PmWiki におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-4453 2012-12-20 18:02 2006-08-30 Show GitHub Exploit DB Packet Storm
227693 7.5 危険 web3king - Web3news の security/include/_class.security.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4452 2012-12-20 18:02 2006-08-30 Show GitHub Exploit DB Packet Storm
227694 5.1 警告 phpBB - PHPBB の usercp_avatar.php における Web のプロキシとしてサーバが使用される脆弱性 - CVE-2006-4450 2012-12-20 18:02 2006-08-29 Show GitHub Exploit DB Packet Storm
227695 7.2 危険 X.Org Foundation - libX11 などを含む X.Org および XFree86 における権限を取得される脆弱性 - CVE-2006-4447 2012-12-20 18:02 2006-08-29 Show GitHub Exploit DB Packet Storm
227696 7.5 危険 venture nine - Tagger LE における任意の PHP コードを実行される脆弱性 - CVE-2006-4437 2012-12-20 18:02 2006-09-14 Show GitHub Exploit DB Packet Storm
227697 7.5 危険 Zend Technologies Ltd. - Zend Platform におけるディレクトリトラバーサルの脆弱性 - CVE-2006-4432 2012-12-20 18:02 2006-08-28 Show GitHub Exploit DB Packet Storm
227698 7.5 危険 Zend Technologies Ltd. - Zend Platform の Session Clustering Daemon および mod_cluster モジュールにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2006-4431 2012-12-20 18:02 2006-08-28 Show GitHub Exploit DB Packet Storm
227699 4.3 警告 yapig - YaPIG の template/default/thanks_comment.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-4421 2012-12-20 18:02 2006-08-28 Show GitHub Exploit DB Packet Storm
227700 7.5 危険 promanager - ProManager の note.php における SQL インジェクションの脆弱性 - CVE-2006-4419 2012-12-20 18:02 2006-08-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 25, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211681 8.3 HIGH
Network
mybb mybb
merge_system
xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to bypass intended access restrictions via vectors related to… CWE-284
Improper Access Control
CVE-2015-8973 2024-11-21 11:39 2017-02-1 Show GitHub Exploit DB Packet Storm
211682 9.8 CRITICAL
Network
gnu chess Stack-based buffer overflow in the ValidateMove function in frontend/move.cc in GNU Chess (aka gnuchess) before 6.2.4 might allow context-dependent attackers to execute arbitrary code via a large inp… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2015-8972 2024-11-21 11:39 2017-01-24 Show GitHub Exploit DB Packet Storm
211683 7.8 HIGH
Local
debian
enlightenment
debian_linux
terminology
Terminology 0.7.0 allows remote attackers to execute arbitrary commands via escape sequences that modify the window title and then are written to the terminal, a similar issue to CVE-2003-0063. CWE-77
Command Injection
CVE-2015-8971 2024-11-21 11:39 2017-01-24 Show GitHub Exploit DB Packet Storm
211684 6.1 MEDIUM
Network
mustache.js_project mustache.js mustache package before 2.2.1 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted. CWE-79
Cross-site Scripting
CVE-2015-8862 2024-11-21 11:39 2017-01-24 Show GitHub Exploit DB Packet Storm
211685 6.1 MEDIUM
Network
handlebars.js_project handlebars.js The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted. CWE-79
Cross-site Scripting
CVE-2015-8861 2024-11-21 11:39 2017-01-24 Show GitHub Exploit DB Packet Storm
211686 7.5 HIGH
Network
nodejs node.js The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive. CWE-59
Link Following
CVE-2015-8860 2024-11-21 11:39 2017-01-24 Show GitHub Exploit DB Packet Storm
211687 5.3 MEDIUM
Network
send_project send The send package before 0.11.1 for Node.js allows attackers to obtain the root path via unspecified vectors. NVD-CWE-noinfo
CVE-2015-8859 2024-11-21 11:39 2017-01-24 Show GitHub Exploit DB Packet Storm
211688 7.5 HIGH
Network
uglifyjs_project uglifyjs The uglify-js package before 2.6.0 for Node.js allows attackers to cause a denial of service (CPU consumption) via crafted input in a parse call, aka a "regular expression denial of service (ReDoS)." CWE-399
 Resource Management Errors
CVE-2015-8858 2024-11-21 11:39 2017-01-24 Show GitHub Exploit DB Packet Storm
211689 9.8 CRITICAL
Network
uglifyjs_project uglifyjs The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which might allow attackers to bypass security mechanisms or possi… CWE-254
 7PK - Security Features
CVE-2015-8857 2024-11-21 11:39 2017-01-24 Show GitHub Exploit DB Packet Storm
211690 6.1 MEDIUM
Network
openjsf serve-index Cross-site scripting (XSS) vulnerability in the serve-index package before 1.6.3 for Node.js allows remote attackers to inject arbitrary web script or HTML via a crafted file or directory name. CWE-79
Cross-site Scripting
CVE-2015-8856 2024-11-21 11:39 2017-01-24 Show GitHub Exploit DB Packet Storm