Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 6, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
232321 7.5 危険 turnkey web tools - TurnkeyWebTools SunShop Shopping Cart の index.php における SQL インジェクションの脆弱性 - CVE-2007-2549 2012-12-20 18:19 2007-05-9 Show GitHub Exploit DB Packet Storm
232322 6.4 警告 turnkey web tools - TurnkeyWebTools SunShop Shopping Cart の index.php における脆弱性 - CVE-2007-2548 2012-12-20 18:19 2007-05-9 Show GitHub Exploit DB Packet Storm
232323 4.3 警告 turnkey web tools - TurnkeyWebTools SunShop Shopping Cart の index.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-2547 2012-12-20 18:19 2007-05-9 Show GitHub Exploit DB Packet Storm
232324 6.8 警告 Simple Machines - SMF におけるセッションをハイジャックされる脆弱性 CWE-287
不適切な認証
CVE-2007-2546 2012-12-20 18:19 2007-05-9 Show GitHub Exploit DB Packet Storm
232325 7.5 危険 XOOPS - XOOPS 用の Flashgames モジュールにおける SQL インジェクションの脆弱性 - CVE-2007-2543 2012-12-20 18:19 2007-05-8 Show GitHub Exploit DB Packet Storm
232326 7.5 危険 workbench survival guide - workbench survival guide の header.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2542 2012-12-20 18:19 2007-05-8 Show GitHub Exploit DB Packet Storm
232327 7.5 危険 versado cms - Versado CMS の includes/ajax_listado.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2541 2012-12-20 18:19 2007-05-8 Show GitHub Exploit DB Packet Storm
232328 7.5 危険 pmecms - PMECMS における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2540 2012-12-20 18:19 2007-05-8 Show GitHub Exploit DB Packet Storm
232329 7.8 危険 runcms - RunCms の show_files 関数における重要な情報 (ファイルの存在およびファイルメタデータ) を取得される脆弱性 - CVE-2007-2539 2012-12-20 18:19 2007-05-8 Show GitHub Exploit DB Packet Storm
232330 7.5 危険 runcms - RunCms の class/debug/debug_show.php における SQL インジェクションの脆弱性 - CVE-2007-2538 2012-12-20 18:19 2007-05-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 6, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313951 - - - SparkShop <=1.1.7 is vulnerable to server-side request forgery (SSRF). This vulnerability allows attacks to scan ports on the Intranet or local network where the server resides, attack applications r… - CVE-2024-48107 2024-10-31 02:35 2024-10-29 Show GitHub Exploit DB Packet Storm
313952 - - - LyLme Spage 1.2.0 through 1.6.0 is vulnerable to SQL Injection via /admin/apply.php. - CVE-2024-48357 2024-10-31 02:35 2024-10-29 Show GitHub Exploit DB Packet Storm
313953 - - - An issue was discovered in Samsung eMMC with KLMAG2GE4A and KLM8G1WEMB firmware. Code bypass through Electromagnetic Fault Injection allows an attacker to successfully authenticate and write to the R… - CVE-2024-31955 2024-10-31 02:35 2024-10-16 Show GitHub Exploit DB Packet Storm
313954 5.3 MEDIUM
Network
djangoproject django An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers to… NVD-CWE-noinfo
CVE-2024-45231 2024-10-31 02:35 2024-10-9 Show GitHub Exploit DB Packet Storm
313955 7.5 HIGH
Network
djangoproject django An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via ve… NVD-CWE-noinfo
CVE-2024-45230 2024-10-31 02:35 2024-10-9 Show GitHub Exploit DB Packet Storm
313956 7.5 HIGH
Network
mozilla firefox
thunderbird
firefox_esr
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This acces… NVD-CWE-Other
CVE-2024-9393 2024-10-31 02:35 2024-10-2 Show GitHub Exploit DB Packet Storm
313957 5.3 MEDIUM
Network
mozilla firefox Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullscreen mode after the fix for CVE-2023-6870 in Firefox 121.… NVD-CWE-noinfo
CVE-2024-8388 2024-10-31 02:35 2024-09-3 Show GitHub Exploit DB Packet Storm
313958 6.1 MEDIUM
Network
mozilla firefox
firefox_esr
If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130… CWE-601
Open Redirect
CVE-2024-8386 2024-10-31 02:35 2024-09-3 Show GitHub Exploit DB Packet Storm
313959 8.8 HIGH
Network
mozilla firefox_esr
firefox
Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those interfaces would not be able to… NVD-CWE-noinfo
CVE-2024-8382 2024-10-31 02:35 2024-09-3 Show GitHub Exploit DB Packet Storm
313960 7.5 HIGH
Network
mozilla firefox_esr
firefox
Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-re… NVD-CWE-noinfo
CVE-2024-8383 2024-10-31 02:35 2024-09-3 Show GitHub Exploit DB Packet Storm