Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 13, 2026, 12:06 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230011 7.5 危険 ttcms - ttCMS の lib/db/ez_sql.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-1708 2012-12-20 18:19 2007-03-26 Show GitHub Exploit DB Packet Storm
230012 7.8 危険 yet another telephony engine - Yate の SIP チャネルモジュールにおけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-1693 2012-12-20 18:19 2007-05-17 Show GitHub Exploit DB Packet Storm
230013 6.8 警告 second sight software - Second Sight Software ActiveGS ActiveX コントロール におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-1691 2012-12-20 18:19 2007-04-19 Show GitHub Exploit DB Packet Storm
230014 6.8 警告 second sight software - Second Sight Software ActiveGS ActiveX コントロール におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-1690 2012-12-20 18:19 2007-04-19 Show GitHub Exploit DB Packet Storm
230015 10 危険 シマンテック - Norton Personal Firewall および Internet Security 用の ISAlertDataCOM ActiveX コントロールにおけるバッファオーバーフローの脆弱性 - CVE-2007-1689 2012-12-20 18:19 2007-05-16 Show GitHub Exploit DB Packet Storm
230016 9.3 危険 solidworks - sldimdownload.dll の SolidWorks sldimdownload ActiveX コントロールにおける任意のコマンドを実行される脆弱性 - CVE-2007-1684 2012-12-20 18:19 2007-04-5 Show GitHub Exploit DB Packet Storm
230017 9.3 危険 Yahoo! - Yahoo! Messenger の AudioConf ActiveX コントロールにおけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-1680 2012-12-20 18:19 2007-04-5 Show GitHub Exploit DB Packet Storm
230018 7.5 危険 Python Software Foundation - Python の Modules/zlib におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-1657 2012-12-20 18:19 2007-03-23 Show GitHub Exploit DB Packet Storm
230019 10 危険 tinymux - TinyMUX の funmath.cpp におけるバッファオーバーフローの脆弱性 - CVE-2007-1655 2012-12-20 18:19 2007-03-23 Show GitHub Exploit DB Packet Storm
230020 4.3 警告 subhub - SubHub におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-1646 2012-12-20 18:19 2007-03-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313041 7.5 HIGH
Network
rust-bitcoin miniscript The Miniscript (aka rust-miniscript) library before 12.2.0 for Rust allows stack consumption because it does not properly track tree depth. CWE-787
 Out-of-bounds Write
CVE-2024-44073 2024-09-7 02:35 2024-08-19 Show GitHub Exploit DB Packet Storm
313042 - - - The News Element Elementor Blog Magazine WordPress plugin before 1.0.6 is vulnerable to Local File Inclusion via the template parameter. This makes it possible for unauthenticated attacker to include… - CVE-2024-6459 2024-09-7 02:35 2024-08-17 Show GitHub Exploit DB Packet Storm
313043 9.8 CRITICAL
Network
totolink lr350_firmware Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-… NVD-CWE-noinfo
CVE-2024-42967 2024-09-7 02:35 2024-08-16 Show GitHub Exploit DB Packet Storm
313044 9.8 CRITICAL
Network
tenda fh1201_firmware An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary commands via a crafted HTTP request. NVD-CWE-noinfo
CVE-2024-42947 2024-09-7 02:35 2024-08-16 Show GitHub Exploit DB Packet Storm
313045 7.8 HIGH
Local
cysoft168 super_easy_enterprise_management_system SQL Injection vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script to the/ajax/Login.ashx component. CWE-89
SQL Injection
CVE-2024-42679 2024-09-7 02:35 2024-08-15 Show GitHub Exploit DB Packet Storm
313046 4.8 MEDIUM
Network
micro.company collect.chat The Chatbot for WordPress by Collect.chat ?? WordPress plugin before 2.4.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Sit… CWE-79
Cross-site Scripting
CVE-2024-6498 2024-09-7 02:35 2024-08-5 Show GitHub Exploit DB Packet Storm
313047 8.6 HIGH
Network
rocket.chat rocket.chat A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1. CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2024-39713 2024-09-7 02:35 2024-08-5 Show GitHub Exploit DB Packet Storm
313048 - - - The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers to download them and retrieve sensitive informati… - CVE-2024-6477 2024-09-7 02:35 2024-08-3 Show GitHub Exploit DB Packet Storm
313049 7.2 HIGH
Network
teamt5 threatsonar_anti-ransomware ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, w… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2024-7694 2024-09-7 02:24 2024-08-12 Show GitHub Exploit DB Packet Storm
313050 5.4 MEDIUM
Network
wpextended wp_extended The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.0.8 via the duplicate_post function due… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2024-8123 2024-09-7 02:20 2024-09-4 Show GitHub Exploit DB Packet Storm