Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
231471 7.5 危険 phpMyFAQ - phpMyFAQ における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2006-6912 2012-12-20 18:02 2006-12-15 Show GitHub Exploit DB Packet Storm
231472 10 危険 東芝 - Toshiba Bluetooth スタックにおける管理者アクセス権限を取得される脆弱性 - CVE-2006-6903 2012-12-20 18:02 2006-12-31 Show GitHub Exploit DB Packet Storm
231473 5.4 警告 widcomm - Widcomm BTW におけるディレクトリトラバーサルの脆弱性 - CVE-2006-6897 2012-12-20 18:02 2006-12-31 Show GitHub Exploit DB Packet Storm
231474 5.4 警告 plantronic - Plantronic Headset の Bluetooth スタックにおける許可されていない組み合わせ操作を実行される脆弱性 - CVE-2006-6896 2012-12-20 18:02 2006-12-31 Show GitHub Exploit DB Packet Storm
231475 2.9 注意 sony ericsson - Sony Ericsson T60 の Bluetooth スタックにおける許可されていない問い合わせ応答へのアクセス権を取得される脆弱性 - CVE-2006-6895 2012-12-20 18:02 2006-12-31 Show GitHub Exploit DB Packet Storm
231476 10 危険 spine - SPINE における脆弱性 - CVE-2006-6894 2012-12-20 18:02 2006-12-31 Show GitHub Exploit DB Packet Storm
231477 5 警告 The Tor Project - Tor における非表示サービスの IP アドレスを特定される脆弱性 - CVE-2006-6893 2012-12-20 18:02 2006-12-31 Show GitHub Exploit DB Packet Storm
231478 5 警告 vz forum - Adp Forum における管理者アカウント名などを取得される脆弱性 - CVE-2006-6891 2012-12-20 18:02 2006-12-31 Show GitHub Exploit DB Packet Storm
231479 7.5 危険 voc-project - Voodoo chat におけるパスワードをダウンロードされる脆弱性 - CVE-2006-6890 2012-12-20 18:02 2006-12-31 Show GitHub Exploit DB Packet Storm
231480 5 警告 p-news - P-News における管理者アカウント名などを取得される脆弱性 - CVE-2006-6888 2012-12-20 18:02 2006-12-31 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
314651 4.8 MEDIUM
Network
concretecms concrete_cms Concrete CMS versions 9.0.0 to 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in RSS Displayer when user input is stored and later embedded into responses. A rogue administrator could inject mal… CWE-79
Cross-site Scripting
CVE-2024-4350 2024-08-31 03:18 2024-08-12 Show GitHub Exploit DB Packet Storm
314652 5.4 MEDIUM
Network
zohocorp manageengine_servicedesk_plus_msp
manageengine_servicedesk_plus
manageengine_supportcenter_plus
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configurations.This issue affects Endpoint Central: before 11.3.2416.04 and before 11.… CWE-79
Cross-site Scripting
CVE-2024-38869 2024-08-31 03:15 2024-08-24 Show GitHub Exploit DB Packet Storm
314653 9.8 CRITICAL
Network
pimax play
pitool
Multiple Pimax products accept WebSocket connections from unintended endpoints. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker. NVD-CWE-Other
CVE-2024-41889 2024-08-31 02:53 2024-08-5 Show GitHub Exploit DB Packet Storm
314654 8.0 HIGH
Adjacent
zexelon zwx-2000csw2-hn_firmware Incorrect permission assignment for critical resource issue exists in ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15, which may allow a network-adjacent authenticated attacker to alter the con… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2024-41720 2024-08-31 02:49 2024-08-5 Show GitHub Exploit DB Packet Storm
314655 8.8 HIGH
Adjacent
zexelon zwx-2000csw2-hn_firmware ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15 uses hard-coded credentials, which may allow a network-adjacent attacker with an administrative privilege to alter the configuration of the devic… CWE-798
 Use of Hard-coded Credentials
CVE-2024-39838 2024-08-31 02:49 2024-08-5 Show GitHub Exploit DB Packet Storm
314656 9.1 CRITICAL
Network
hamastar meetinghub_paperless_meetings A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to … CWE-522
 Insufficiently Protected Credentials
CVE-2024-6118 2024-08-31 02:44 2024-08-5 Show GitHub Exploit DB Packet Storm
314657 8.8 HIGH
Network
hamastar meetinghub_paperless_meetings A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform arbitrary sy… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2024-6117 2024-08-31 02:41 2024-08-5 Show GitHub Exploit DB Packet Storm
314658 5.3 MEDIUM
Network
in2code powermail An issue was discovered in powermail extension through 12.3.5 for TYPO3. It fails to validate the mail parameter of the confirmationAction, resulting in Insecure Direct Object Reference (IDOR). An un… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2024-45232 2024-08-31 01:34 2024-08-29 Show GitHub Exploit DB Packet Storm
314659 8.8 HIGH
Network
google chrome Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CWE-843
Type Confusion
CVE-2024-8194 2024-08-31 01:34 2024-08-29 Show GitHub Exploit DB Packet Storm
314660 9.8 CRITICAL
Network
in2code powermail An issue was discovered in powermail extension through 12.3.5 for TYPO3. Several actions in the OutputController can directly be called, due to missing or insufficiently implemented access checks, re… NVD-CWE-Other
CVE-2024-45233 2024-08-31 01:33 2024-08-29 Show GitHub Exploit DB Packet Storm