Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227901 7.5 危険 ufo2000 - UFO2000 の multiplay.cpp におけるバッファオーバーフローの脆弱性 - CVE-2006-3788 2012-12-20 18:02 2006-07-24 Show GitHub Exploit DB Packet Storm
227902 2.1 注意 Kerio Technologies - Sunbelt Kerio Personal Firewall の kpf4ss.exe におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2006-3787 2012-12-20 18:02 2006-07-24 Show GitHub Exploit DB Packet Storm
227903 3.6 注意 シマンテック - Symantec pcAnywhere におけるカスタム .cif ファイルを生成される脆弱性 - CVE-2006-3786 2012-12-20 18:02 2006-07-24 Show GitHub Exploit DB Packet Storm
227904 2.1 注意 シマンテック - Symantec pcAnywhere におけるパスワードを取得される脆弱性 - CVE-2006-3785 2012-12-20 18:02 2006-07-24 Show GitHub Exploit DB Packet Storm
227905 7.2 危険 シマンテック - Symantec pcAnywhere における権限を取得される脆弱性 - CVE-2006-3784 2012-12-20 18:02 2006-07-24 Show GitHub Exploit DB Packet Storm
227906 5 警告 keyifweb - Keyifweb Keyif Portal におけるデータベースをダウンロードされる脆弱性 - CVE-2006-3780 2012-12-20 18:02 2006-07-24 Show GitHub Exploit DB Packet Storm
227907 6.5 警告 シトリックス・システムズ - Citrix MetaFrame における権限を取得される脆弱性 - CVE-2006-3779 2012-12-20 18:02 2006-07-24 Show GitHub Exploit DB Packet Storm
227908 7.5 危険 idevSpot - IDevSpot PhpLinkExchange の index.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-3777 2012-12-20 18:02 2006-07-24 Show GitHub Exploit DB Packet Storm
227909 7.5 危険 idevSpot - IDevSpot PhpHostBot および AutoHost の order/index.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-3776 2012-12-20 18:02 2006-07-24 Show GitHub Exploit DB Packet Storm
227910 7.5 危険 mybulletinboard - MyBB の class_session.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2006-3775 2012-12-20 18:02 2006-07-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 25, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
199701 4.9 MEDIUM
Network
cmsmadesimple cms_made_simple In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a FileManager action to admin/moduleinterface.php. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2017-11404 2024-11-21 12:07 2017-07-18 Show GitHub Exploit DB Packet Storm
199702 8.8 HIGH
Network
graphicsmagick graphicsmagick The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 has an out-of-order CloseBlob call, resulting in a use-after-free via a crafted file. CWE-416
 Use After Free
CVE-2017-11403 2024-11-21 12:07 2017-07-18 Show GitHub Exploit DB Packet Storm
199703 7.8 HIGH
Local
ffmpeg ffmpeg Integer overflow in the ape_decode_frame function in libavcodec/apedec.c in FFmpeg 2.4 through 3.3.2 allows remote attackers to cause a denial of service (out-of-array access and application crash) o… CWE-125
Out-of-bounds Read
CVE-2017-11399 2024-11-21 12:07 2017-07-18 Show GitHub Exploit DB Packet Storm
199704 5.4 MEDIUM
Network
bolt bolt_cms Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry. CWE-79
Cross-site Scripting
CVE-2017-11128 2024-11-21 12:07 2017-07-18 Show GitHub Exploit DB Packet Storm
199705 5.4 MEDIUM
Network
bolt bolt_cms Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a "Content-Type: image/svg+xml" header. CWE-79
Cross-site Scripting
CVE-2017-11127 2024-11-21 12:07 2017-07-18 Show GitHub Exploit DB Packet Storm
199706 8.8 HIGH
Network
intenogroup inteno_router_firmware Inteno routers have a JUCI ACL misconfiguration that allows the "user" account to read files, write to files, and add root SSH keys via JSON commands to ubus. (Exploitation is sometimes easy because … CWE-269
 Improper Privilege Management
CVE-2017-11361 2024-11-21 12:07 2017-07-18 Show GitHub Exploit DB Packet Storm
199707 7.5 HIGH
Network
shoco_project shoco The shoco_decompress function in the API in shoco through 2017-07-17 allows remote attackers to cause a denial of service (buffer over-read and application crash) via malformed compressed data. CWE-125
Out-of-bounds Read
CVE-2017-11367 2024-11-21 12:07 2017-07-18 Show GitHub Exploit DB Packet Storm
199708 9.8 CRITICAL
Network
php php In PHP 7.x before 7.0.21 and 7.1.x before 7.1.7, ext/intl/msgformat/msgformat_parse.c does not restrict the locale length, which allows remote attackers to cause a denial of service (stack-based buff… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2017-11362 2024-11-21 12:07 2017-07-17 Show GitHub Exploit DB Packet Storm
199709 6.5 MEDIUM
Network
imagemagick imagemagick The ReadRLEImage function in coders\rle.c in ImageMagick 7.0.6-1 has a large loop vulnerability via a crafted rle file that triggers a huge number_pixels value. CWE-834
 Excessive Iteration
CVE-2017-11360 2024-11-21 12:07 2017-07-17 Show GitHub Exploit DB Packet Storm
199710 9.8 CRITICAL
Network
fiyo fiyo_cms Fiyo CMS v2.0.7 has an SQL injection vulnerability in dapur/apps/app_article/sys_article.php via the name parameter in editing or adding a tag name. CWE-89
SQL Injection
CVE-2017-11354 2024-11-21 12:07 2017-07-17 Show GitHub Exploit DB Packet Storm