Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 16, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230831 7.5 危険 phpbp - phpBP の index.php における upload/banners/ ファイルに任意の PHP コードを挿入される脆弱性 - CVE-2007-0370 2012-12-20 18:19 2007-01-19 Show GitHub Exploit DB Packet Storm
230832 7.5 危険 phpbp - phpBP における SQL インジェクションの脆弱性 - CVE-2007-0369 2012-12-20 18:19 2007-01-19 Show GitHub Exploit DB Packet Storm
230833 7.5 危険 uberghey - Uberghey CMS の frontpage.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-0359 2012-12-20 18:19 2007-01-18 Show GitHub Exploit DB Packet Storm
230834 6.2 警告 zonelabs - Microsoft Windows XP および Windows Server 2003 における権限を取得される脆弱性 - CVE-2007-0351 2012-12-20 18:19 2007-01-18 Show GitHub Exploit DB Packet Storm
230835 7.5 危険 sme - SmE FileMailer の index.php および dl.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-0350 2012-12-20 18:19 2007-01-18 Show GitHub Exploit DB Packet Storm
230836 7.5 危険 sme - SmE FileMailer の index.php における SQL インジェクションの脆弱性 - CVE-2007-0346 2012-12-20 18:19 2007-01-17 Show GitHub Exploit DB Packet Storm
230837 6.8 警告 The phpMyAdmin Project - phpMyAdmin におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-0341 2012-12-20 18:19 2007-01-17 Show GitHub Exploit DB Packet Storm
230838 7.5 危険 thwboard - ThWboard の inc/header.inc.php における SQL インジェクションの脆弱性 - CVE-2007-0340 2012-12-20 18:19 2007-01-17 Show GitHub Exploit DB Packet Storm
230839 7.5 危険 scriptme - Scriptme SMe FileMailer の index.php における SQL インジェクションの脆弱性 - CVE-2007-0339 2012-12-20 18:19 2007-01-17 Show GitHub Exploit DB Packet Storm
230840 4.4 警告 rixstep - Rixstep Undercover の Undercover.app/Contents/Resources/uc における任意のファイルを上書きされる脆弱性 - CVE-2007-0336 2012-12-20 18:19 2007-01-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 16, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
317001 - - - Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. - CVE-2023-45921 2024-01-29 18:15 2024-01-29 Show GitHub Exploit DB Packet Storm
317002 - - - Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. - CVE-2023-45916 2024-01-29 18:15 2024-01-29 Show GitHub Exploit DB Packet Storm
317003 - - - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. - CVE-2023-6470 2024-01-27 06:15 2024-01-27 Show GitHub Exploit DB Packet Storm
317004 - noguska nola The document management module in NOLA 1.1.1 and 1.1.2 does not restrict the types of files that are uploaded, which allows remote attackers to upload and execute arbitrary PHP files with extensions … CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2002-1841 2024-01-27 05:01 2002-12-31 Show GitHub Exploit DB Packet Storm
317005 - apache http_server Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat)… CWE-78
OS Command 
CVE-2002-0061 2024-01-27 05:01 2002-03-21 Show GitHub Exploit DB Packet Storm
317006 - hypermail_development hypermail Hypermail allows remote attackers to execute arbitrary commands on a server supporting SSI via an attachment with a .shtml extension, which is archived on the server and can then be executed by reque… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2001-0901 2024-01-27 05:01 2001-11-19 Show GitHub Exploit DB Packet Storm
317007 - apache
ncsa
http_server
ncsa_httpd
phf CGI program allows remote command execution through shell metacharacters. CWE-78
OS Command 
CVE-1999-0067 2024-01-27 05:00 1996-03-20 Show GitHub Exploit DB Packet Storm
317008 - e107 e107 ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to imag… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2004-2262 2024-01-27 04:10 2004-12-31 Show GitHub Exploit DB Packet Storm
317009 - yvesglodt i-man I-Man 0.9, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code by uploading a file attachment with a .php extension. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2005-1868 2024-01-27 04:07 2005-06-9 Show GitHub Exploit DB Packet Storm
317010 - yapig yapig upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which allows remote attackers to upload arbitrary files and execute arbitrary PHP co… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2005-1881 2024-01-27 04:07 2005-06-6 Show GitHub Exploit DB Packet Storm