Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 5, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
232671 4.3 警告 pyrophobia - Pyrophobia の modules/out.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-1159 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
232672 5 警告 postnuke software foundation - PostNuke 用の Pagesetter モジュールにおけるディレクトリトラバーサルの脆弱性 - CVE-2007-1158 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
232673 4.6 警告 webSPELL - webSPELL における任意の PHP コードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2007-1155 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
232674 6.8 警告 webSPELL - webSPELL における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-1154 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
232675 5 警告 pyrophobia - Pyrophobia におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-1152 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
232676 4.3 警告 reamday enterprises - Magic News Plus におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-1142 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
232677 7.5 危険 reamday enterprises - Magic News Plus の preview.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-1141 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
232678 5 警告 加藤和良 - Putmail の putmail.py における重要な情報を取得される脆弱性 - CVE-2007-1137 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
232679 6.8 警告 webmplayer - WebMplayer の index.php における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2007-1136 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
232680 6.8 警告 加藤和良 - WebMplayer における SQL インジェクションの脆弱性 - CVE-2007-1135 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 5, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
314611 7.5 HIGH
Network
microsoft windows_server_2012
windows_server_2016
windows_server_2022_23h2
windows_server_2022
windows_server_2019
Windows Hyper-V Denial of Service Vulnerability NVD-CWE-noinfo
CVE-2024-43521 2024-10-18 03:39 2024-10-9 Show GitHub Exploit DB Packet Storm
314612 7.0 HIGH
Local
microsoft windows_11_22h2
windows_11_23h2
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability NVD-CWE-noinfo
CVE-2024-43522 2024-10-18 03:38 2024-10-9 Show GitHub Exploit DB Packet Storm
314613 6.8 MEDIUM
Physics
microsoft windows_server_2022_23h2
windows_10_1809
windows_server_2019
windows_11_21h2
windows_10_21h2
windows_11_22h2
windows_10_22h2
windows_11_23h2
windows_11_24h2
Windows Mobile Broadband Driver Remote Code Execution Vulnerability NVD-CWE-noinfo
CVE-2024-43525 2024-10-18 03:37 2024-10-9 Show GitHub Exploit DB Packet Storm
314614 6.8 MEDIUM
Physics
microsoft windows_server_2022_23h2
windows_10_1809
windows_server_2019
windows_11_21h2
windows_10_21h2
windows_11_22h2
windows_10_22h2
windows_11_23h2
windows_11_24h2
Windows Mobile Broadband Driver Remote Code Execution Vulnerability NVD-CWE-noinfo
CVE-2024-43526 2024-10-18 03:36 2024-10-9 Show GitHub Exploit DB Packet Storm
314615 - - - Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair - CVE-2024-49195 2024-10-18 03:35 2024-10-16 Show GitHub Exploit DB Packet Storm
314616 - - - DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_subconfig function. - CVE-2024-48153 2024-10-18 03:35 2024-10-15 Show GitHub Exploit DB Packet Storm
314617 9.8 CRITICAL
Network
wavelog wavelog Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode. CWE-89
SQL Injection
CVE-2024-48251 2024-10-18 03:35 2024-10-15 Show GitHub Exploit DB Packet Storm
314618 6.5 MEDIUM
Adjacent
microsoft windows_server_2022_23h2
windows_10_1809
windows_server_2019
windows_11_21h2
windows_10_21h2
windows_11_22h2
windows_10_22h2
windows_11_23h2
windows_11_24h2
Windows Mobile Broadband Driver Denial of Service Vulnerability NVD-CWE-noinfo
CVE-2024-43538 2024-10-18 03:33 2024-10-9 Show GitHub Exploit DB Packet Storm
314619 7.5 HIGH
Network
microsoft windows_server_2012
windows_server_2016
windows_server_2022_23h2
windows_server_2022
windows_server_2019
Windows Hyper-V Denial of Service Vulnerability NVD-CWE-noinfo
CVE-2024-43567 2024-10-18 03:29 2024-10-9 Show GitHub Exploit DB Packet Storm
314620 5.4 MEDIUM
Network
filemanagerpro file_manager The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 8.3.9. This is due to a lack of proper checks on allowed file types. Th… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2024-8918 2024-10-18 03:25 2024-10-16 Show GitHub Exploit DB Packet Storm