Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 24, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228161 5 警告 WordPress.org - WordPress および WordPress MU における有効なユーザ名を列挙される脆弱性 CWE-16
環境設定
CVE-2009-2335 2012-12-20 19:10 2009-07-10 Show GitHub Exploit DB Packet Storm
228162 4.9 警告 WordPress.org - WordPress および WordPress MU の wp-admin/admin.php における重要な情報を取得される脆弱性 CWE-287
不適切な認証
CVE-2009-2334 2012-12-20 19:10 2009-07-9 Show GitHub Exploit DB Packet Storm
228163 2.1 注意 サン・マイクロシステムズ - Solaris 上の Sun Lightweight Availability Collection Tool における任意のファイルを上書きされる脆弱性 CWE-362
競合状態
CVE-2009-2314 2012-12-20 19:10 2009-07-2 Show GitHub Exploit DB Packet Storm
228164 7.5 危険 selbstzweck - WBB3 用の rGallery プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2311 2012-12-20 19:10 2009-07-2 Show GitHub Exploit DB Packet Storm
228165 7.5 危険 punres - PunBB 用の Affiliation モジュールの affiliates.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2308 2012-12-20 19:10 2009-07-2 Show GitHub Exploit DB Packet Storm
228166 7.5 危険 tutorial-share - Optimum Web Design Tutorial Share における認証を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-2293 2012-12-20 19:10 2009-07-1 Show GitHub Exploit DB Packet Storm
228167 4.3 警告 The phpMyAdmin Project - phpMyAdmin におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2284 2012-12-20 19:10 2009-06-30 Show GitHub Exploit DB Packet Storm
228168 10 危険 UMN - MapServer の mapserv におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-2281 2012-12-20 19:10 2009-10-22 Show GitHub Exploit DB Packet Storm
228169 2.6 注意 サン・マイクロシステムズ - Sun Java System Access Manager の CDC servlet におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2268 2012-12-20 19:10 2009-06-29 Show GitHub Exploit DB Packet Storm
228170 5 警告 stardict - stardict における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2009-2260 2012-12-20 19:10 2009-06-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 24, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
318041 7.5 HIGH
Network
dlink dsl-504t_firmware D-Link DSL-504T stores usernames and passwords in cleartext in the router configuration file, which allows remote attackers to obtain sensitive information. CWE-312
 Cleartext Storage of Sensitive Information
CVE-2005-1828 2024-02-14 01:17 2005-05-26 Show GitHub Exploit DB Packet Storm
318042 7.5 HIGH
Network
broadcom bluecoat_security_gateway The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which all… CWE-312
 Cleartext Storage of Sensitive Information
CVE-2004-2397 2024-02-14 01:17 2004-12-31 Show GitHub Exploit DB Packet Storm
318043 - myupb ultimate_php_board Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing the code in the User-Agent header, which is execute… CWE-94
Code Injection
CVE-2003-0395 2024-02-14 01:14 2003-07-2 Show GitHub Exploit DB Packet Storm
318044 5.5 MEDIUM
Local
capturix scanshare Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext in capturixss_cfg.ini, which is readable by local users. CWE-312
 Cleartext Storage of Sensitive Information
CVE-2005-2209 2024-02-14 01:09 2005-07-11 Show GitHub Exploit DB Packet Storm
318045 - - - Rejected reason: **REJECT** Not a valid vulnerability. - CVE-2024-0707 2024-02-13 23:15 2024-02-13 Show GitHub Exploit DB Packet Storm
318046 - - - Rejected reason: **REJECT** This is a duplicate of CVE-2024-1049. Please use CVE-2024-1049 instead. - CVE-2024-1420 2024-02-13 00:15 2024-02-13 Show GitHub Exploit DB Packet Storm
318047 7.5 HIGH
Network
phprank phprank phpRank 1.8 stores the administrative password in plaintext on the server and in the "ap" cookie, which allows remote attackers to retrieve the administrative password. CWE-312
 Cleartext Storage of Sensitive Information
CVE-2002-1800 2024-02-10 12:06 2002-12-31 Show GitHub Exploit DB Packet Storm
318048 7.5 HIGH
Network
audiogalaxy audiogalaxy Autogalaxy stores usernames and passwords in cleartext in cookies, which makes it easier for remote attackers to obtain authentication information and gain unauthorized access via sniffing or a cross… CWE-312
 Cleartext Storage of Sensitive Information
CVE-2001-1536 2024-02-10 12:04 2001-12-31 Show GitHub Exploit DB Packet Storm
318049 - - - Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. All references and descriptions in this record have been removed to prevent accidental usage. - CVE-2023-6716 2024-02-9 18:15 2024-02-9 Show GitHub Exploit DB Packet Storm
318050 - georgecurrums open_guestbook Cross-site scripting (XSS) vulnerability in header.php in Open Guestbook 0.5 allows remote attackers to inject arbitrary web script or HTML via the title parameter. CWE-79
Cross-site Scripting
CVE-2006-3295 2024-02-9 12:26 2006-06-29 Show GitHub Exploit DB Packet Storm