Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227911 6.8 警告 Joomla! - Joomla! 用の com_performs における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-3774 2012-12-20 18:02 2006-07-24 Show GitHub Exploit DB Packet Storm
227912 6.8 警告 Mambo Foundation - Joomla! および Mambo 用の Bridge コンポーネントにおける PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-3773 2012-12-20 18:02 2006-07-10 Show GitHub Exploit DB Packet Storm
227913 5.1 警告 php-post - PHP-Post における管理者権限を取得される脆弱性 - CVE-2006-3772 2012-12-20 18:02 2006-07-24 Show GitHub Exploit DB Packet Storm
227914 7.5 危険 imaginex-resource - iManage CMS の component.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-3771 2012-12-20 18:02 2006-07-24 Show GitHub Exploit DB Packet Storm
227915 7.5 危険 phpfaber - phpFaber TopSites の index.php における SQL インジェクションの脆弱性 - CVE-2006-3770 2012-12-20 18:02 2006-07-24 Show GitHub Exploit DB Packet Storm
227916 2.6 注意 top xl - Top XL におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-3769 2012-12-20 18:02 2006-07-24 Show GitHub Exploit DB Packet Storm
227917 6.4 警告 intervations - FileCOPA FTP Server の filecpnt.exe における整数アンダーフローの脆弱性 - CVE-2006-3768 2012-12-20 18:02 2006-07-28 Show GitHub Exploit DB Packet Storm
227918 6.8 警告 darrens 5-dollar script archive - Darren's $5 Script Archive osDate の showprofile.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-3767 2012-12-20 18:02 2006-07-21 Show GitHub Exploit DB Packet Storm
227919 5 警告 darrens 5-dollar script archive - Darren's $5 Script Archive osDate における本人のレートを格上げできる脆弱性 - CVE-2006-3766 2012-12-20 18:02 2006-07-21 Show GitHub Exploit DB Packet Storm
227920 4.3 警告 huttenlocher webdesign - Huttenlocher Webdesign hwdeGUEST におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-3765 2012-12-20 18:02 2006-07-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 21, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
212041 6.1 MEDIUM
Network
edx edx-platform edx-platform before 2015-09-17 allows XSS via a team name. CWE-79
Cross-site Scripting
CVE-2015-6960 2024-11-21 11:35 2019-07-30 Show GitHub Exploit DB Packet Storm
212042 8.8 HIGH
Network
moxa softcms Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to address the vulnerability. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2015-6458 2024-11-21 11:35 2019-03-22 Show GitHub Exploit DB Packet Storm
212043 8.8 HIGH
Network
moxa softcms Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to address the vulnerability. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2015-6457 2024-11-21 11:35 2019-03-22 Show GitHub Exploit DB Packet Storm
212044 5.4 MEDIUM
Network
schneider-electric bmxnoc0401_firmware
bmxnoe0100_firmware
bmxnoe0110_firmware
bmxnoe0110h_firmware
bmxnor0200h_firmware
modicon_m340_bmxp342020_firmware
modicon_m340_bmxp342020h_firmware
modicon_m…
Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, B… CWE-79
Cross-site Scripting
CVE-2015-6462 2024-11-21 11:35 2019-03-22 Show GitHub Exploit DB Packet Storm
212045 5.4 MEDIUM
Network
schneider-electric bmxnoc0401_firmware
bmxnoe0100_firmware
bmxnoe0110_firmware
bmxnoe0110h_firmware
bmxnor0200h_firmware
modicon_m340_bmxp342020_firmware
modicon_m340_bmxp342020h_firmware
modicon_m…
Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP… CWE-20
 Improper Input Validation 
CVE-2015-6461 2024-11-21 11:35 2019-03-22 Show GitHub Exploit DB Packet Storm
212046 5.9 MEDIUM
Network
atlassian floodlight Race condition in the LoadBalancer module in the Atlassian Floodlight Controller before 1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and thread crash) via a stat… CWE-362
CWE-476
Race Condition
 NULL Pointer Dereference
CVE-2015-6569 2024-11-21 11:35 2018-02-22 Show GitHub Exploit DB Packet Storm
212047 6.1 MEDIUM
Network
combodo itop Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows remote attackers to inject arbitrary web script or HTML via a dashboard title. CWE-79
Cross-site Scripting
CVE-2015-6544 2024-11-21 11:35 2018-02-21 Show GitHub Exploit DB Packet Storm
212048 7.5 HIGH
Network
oxid-esales eshop The OpenID Single Sign-On authentication functionality in OXID eShop before 4.5.0 allows remote attackers to impersonate users via the email address in a crafted authentication token. CWE-287
Improper Authentication
CVE-2015-6926 2024-11-21 11:35 2018-01-20 Show GitHub Exploit DB Packet Storm
212049 6.1 MEDIUM
Network
puppet puppet_enterprise Cross-site scripting (XSS) vulnerability in the console in Puppet Enterprise before 2015.2.1 allows remote attackers to inject arbitrary web script or HTML via the string parameter, related to Login … CWE-79
Cross-site Scripting
CVE-2015-6502 2024-11-21 11:35 2017-12-12 Show GitHub Exploit DB Packet Storm
212050 4.6 MEDIUM
Physics
grupo_msa vot.ar The parse function in MSA vot.Ar 3.1 does not check whether a candidate receives more than one vote, which allows physically proximate attackers to cast multiple votes for a candidate via a crafted R… CWE-20
 Improper Input Validation 
CVE-2015-6839 2024-11-21 11:35 2017-10-24 Show GitHub Exploit DB Packet Storm