Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 1, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228431 8.3 危険 Wikka Development Team - WikkaWiki における任意の設定ファイルをアップロードされる脆弱性 - CVE-2007-2613 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
228432 7.5 危険 Wikka Development Team - WikkaWiki の libs/Wakka.class.php における SQL インジェクションの脆弱性 - CVE-2007-2612 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
228433 6.8 警告 wavelink media - TutorialCMS におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-2600 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
228434 7.5 危険 wavelink media - TutorialCMS における SQL インジェクションの脆弱性 - CVE-2007-2599 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
228435 10 危険 Simplenews Project - SimpleNews の print.php における SQL インジェクションの脆弱性 - CVE-2007-2598 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
228436 7.5 危険 telltargetcms - telltarget CMS における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2597 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
228437 6.5 警告 rscript - RSAuction におけるユーザ自身のアカウントステータスを Suspended から Active に変更される脆弱性 - CVE-2007-2595 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
228438 7.5 危険 phpmyportal - phpMyPortal の inc/articles.inc.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2594 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
228439 7.5 危険 vm watermark - Gallery 用の vm watermark における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-2575 2012-12-20 18:19 2007-05-9 Show GitHub Exploit DB Packet Storm
228440 7.5 危険 phptree - PHPtree の plugin/HP_DEV/cms2.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2573 2012-12-20 18:19 2007-05-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 1, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313151 - oscommerce oscommerce Directory traversal vulnerability in file_manager.php in osCommerce 2.2 allows remote attackers to view arbitrary files via a .. (dot dot) in the filename argument. NVD-CWE-Other
CVE-2004-2021 2024-02-14 10:17 2004-12-31 Show GitHub Exploit DB Packet Storm
313152 - allwebscripts mysqlguest Cross-site scripting (XSS) vulnerability in AWSguest.php in AllWebScripts MySQLGuest allows remote attackers to inject arbitrary HTML and PHP code via the (1) Name, (2) Email, (3) Homepage or (4) Com… NVD-CWE-Other
CVE-2004-2138 2024-02-14 10:17 2004-12-31 Show GitHub Exploit DB Packet Storm
313153 - phpx phpx PHPX 3.2.6 and earlier allows remote attackers to obtain the physical path of PHPX via a null or invalid value in the limit parameter, which leaks the pathname in a database error message, as demonst… NVD-CWE-Other
CVE-2004-2362 2024-02-14 10:17 2004-12-31 Show GitHub Exploit DB Packet Storm
313154 - phpx phpx Validate-Before-Canonicalize vulnerability in the checkURI function in functions.inc.php in PHPX 3.0 through 3.2.6 allows remote attackers to conduct cross-site scripting (XSS) attacks via hex-encode… NVD-CWE-Other
CVE-2004-2363 2024-02-14 10:17 2004-12-31 Show GitHub Exploit DB Packet Storm
313155 - phpx phpx Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary commands via URLs that are automatically executed on behalf of the administrator… NVD-CWE-Other
CVE-2004-2364 2024-02-14 10:17 2004-12-31 Show GitHub Exploit DB Packet Storm
313156 - - - PHP remote file inclusion vulnerability in header.php in Opt-X 0.7.2 allows remote attackers to execute arbitrary PHP code via the systempath parameter. NVD-CWE-Other
CVE-2004-2368 2024-02-14 10:17 2004-12-31 Show GitHub Exploit DB Packet Storm
313157 - whitsoft_development slimftpd Buffer overflow in SlimFTPd 3.15 and earlier allows local users to execute arbitrary code via a long command, such as (1) CWD, (2) STOR, (3) MKD, and (4) STAT. NVD-CWE-Other
CVE-2004-2418 2024-02-14 10:17 2004-12-31 Show GitHub Exploit DB Packet Storm
313158 - - - Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via (1) "..", (2) "\..\" (backslash dot dot), or (3) "/../" se… NVD-CWE-Other
CVE-2004-2487 2024-02-14 10:17 2004-12-31 Show GitHub Exploit DB Packet Storm
313159 - - - Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via "C:" sequences in the (1) RETR (get), (2) NLST (ls), (3) L… NVD-CWE-Other
CVE-2004-2488 2024-02-14 10:17 2004-12-31 Show GitHub Exploit DB Packet Storm
313160 - leigh_business_enterprises web_helpdesk SQL injection vulnerability in jobedit.asp in Leigh Business Enterprises (LBE) Web Helpdesk before 4.0.0.81 allows remote attackers to execute arbitrary SQL commands via the id parameter. NVD-CWE-Other
CVE-2004-2562 2024-02-14 10:17 2004-12-31 Show GitHub Exploit DB Packet Storm