Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 14, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229941 6.5 警告 phpBB - phpBB 用の IP-Tracking Mod における SQL インジェクションの脆弱性 - CVE-2007-2858 2012-12-20 18:19 2007-05-24 Show GitHub Exploit DB Packet Storm
229942 7.5 危険 zakkis technology corporation - ABC Excel Parser の sample/xls2mysql における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2857 2012-12-20 18:19 2007-05-24 Show GitHub Exploit DB Packet Storm
229943 10 危険 sky software - Sky Software Shell MegaPack ActiveX の shComboBox ActiveX コントロールにおけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-2848 2012-12-20 18:19 2007-05-24 Show GitHub Exploit DB Packet Storm
229944 6.8 警告 unicon-imc2 - unicon-imc2 の ImmModules/cce/ におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-2835 2012-12-20 18:19 2007-07-1 Show GitHub Exploit DB Packet Storm
229945 9.3 危険 wavelink media - TutorialCMS における認証を回避される脆弱性 - CVE-2007-2822 2012-12-20 18:19 2007-05-22 Show GitHub Exploit DB Packet Storm
229946 7.5 危険 WordPress.org - WordPress の wp-admin/admin-ajax.php における SQL インジェクションの脆弱性 - CVE-2007-2821 2012-12-20 18:19 2007-05-22 Show GitHub Exploit DB Packet Storm
229947 4.3 警告 track+ - Track+ の reportItem.do におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-2819 2012-12-20 18:19 2007-05-22 Show GitHub Exploit DB Packet Storm
229948 7.5 危険 vizayn urun - Vizayn Urun Tanitim Sitesi の default.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-2803 2012-12-20 18:19 2007-05-22 Show GitHub Exploit DB Packet Storm
229949 4.3 警告 rm - RM EasyMail Plus の cp/ps/Main/login/Login におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-2802 2012-12-20 18:19 2007-05-22 Show GitHub Exploit DB Packet Storm
229950 6.8 警告 vpasp - VP-ASP Shopping Cart の shopcontent.asp におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-2790 2012-12-20 18:19 2007-05-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 14, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
312771 - - - An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 through 7.0.3 change password endpoint may allow an authent… CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2024-45327 2024-09-12 01:26 2024-09-11 Show GitHub Exploit DB Packet Storm
312772 - - - A vulnerability was found in Mercury MNVR816 up to 2.0.1.0.5. It has been classified as problematic. This affects an unknown part of the file /web-static/. The manipulation leads to files or director… CWE-552
 Files or Directories Accessible to External Parties
CVE-2024-8655 2024-09-12 01:26 2024-09-11 Show GitHub Exploit DB Packet Storm
312773 - - - SpiderControl SCADA Web Server has a vulnerability that could allow an attacker to upload specially crafted malicious files without authentication. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2024-8232 2024-09-12 01:26 2024-09-11 Show GitHub Exploit DB Packet Storm
312774 - - - Directus is a real-time API and App dashboard for managing SQL database content. An unauthenticated user can access credentials of last authenticated user via OpenID or OAuth2 where the authenticatio… CWE-524
 Use of Cache Containing Sensitive Information
CVE-2024-45596 2024-09-12 01:26 2024-09-11 Show GitHub Exploit DB Packet Storm
312775 - - - cross-site scripting (XSS) vulnerability in Gibbon Core v26.0.00 allows an attacker to execute arbitrary code via the imageLink parameter in the library_manage_catalog_editProcess.php component. - CVE-2024-34831 2024-09-12 01:26 2024-09-11 Show GitHub Exploit DB Packet Storm
312776 6.5 MEDIUM
Network
mozilla thunderbird When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 128.2. CWE-416
 Use After Free
CVE-2024-8394 2024-09-12 01:25 2024-09-7 Show GitHub Exploit DB Packet Storm
312777 8.8 HIGH
Network
draytek vigor3900_firmware DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the value parameter in the filter_string function. CWE-78
OS Command 
CVE-2024-44845 2024-09-12 01:24 2024-09-7 Show GitHub Exploit DB Packet Storm
312778 8.8 HIGH
Network
draytek vigor3900_firmware DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the name parameter in the run_command function. CWE-78
OS Command 
CVE-2024-44844 2024-09-12 01:24 2024-09-7 Show GitHub Exploit DB Packet Storm
312779 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: gsmi: fix null-deref in gsmi_get_variable We can get EFI variables without fetching the attribute, so we must allow for that in g… CWE-476
 NULL Pointer Dereference
CVE-2023-52893 2024-09-12 01:24 2024-08-21 Show GitHub Exploit DB Packet Storm
312780 4.3 MEDIUM
Network
ngothang wp_multitasking The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack CWE-352
 Origin Validation Error
CVE-2024-6852 2024-09-12 01:23 2024-09-8 Show GitHub Exploit DB Packet Storm