Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
248001 10 危険 アップル - DiskManagement.framework の DiskManagementTool における権限を取得される脆弱性 - CVE-2007-0117 2012-06-26 15:38 2007-01-8 Show GitHub Exploit DB Packet Storm
248002 7.5 危険 digger solutions - Digger Solutions IOS におけるパスワードを含むデータベースをダウンロードされる脆弱性 - CVE-2007-0116 2012-06-26 15:38 2007-01-8 Show GitHub Exploit DB Packet Storm
248003 6 警告 Coppermine Photo Gallery - Coppermine Photo Gallery における任意の PHP コードを実行される脆弱性 - CVE-2007-0115 2012-06-26 15:38 2007-01-8 Show GitHub Exploit DB Packet Storm
248004 7.5 危険 createauction - createauction の cats.asp における SQL インジェクションの脆弱性 - CVE-2007-0112 2012-06-26 15:38 2007-01-8 Show GitHub Exploit DB Packet Storm
248005 7.5 危険 シスコシステムズ - Cisco Secure ACS の CSAdmin サービスにおけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-0105 2012-06-26 15:38 2007-01-5 Show GitHub Exploit DB Packet Storm
248006 6.8 警告 アドビシステムズ - Adobe Acrobat に実装される Adobe PDF 仕様におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2007-0103 2012-06-26 15:38 2007-01-8 Show GitHub Exploit DB Packet Storm
248007 6.8 警告 アップル - Apple Mac OS X Preview で実装される Adobe PDF におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2007-0102 2012-06-26 15:38 2007-01-8 Show GitHub Exploit DB Packet Storm
248008 9.3 危険 ConeXware, Inc. - ConeXware PowerArchiver 2006 の PAISO.DLL の LoadTree 関数におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-0097 2012-06-26 15:38 2007-01-5 Show GitHub Exploit DB Packet Storm
248009 7.5 危険 carboncommunities - CarbonCommunities におけるパスワードを含むデータベースをダウンロードされる脆弱性 - CVE-2007-0096 2012-06-26 15:38 2007-01-5 Show GitHub Exploit DB Packet Storm
248010 7.5 危険 Simple Web Content Management System - Simple Web Content Management System の page.php における SQL インジェクションの脆弱性 - CVE-2007-0093 2012-06-26 15:38 2007-01-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 5, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
315081 7.8 HIGH
Local
philiphazel xfpt xfpt versions prior to 1.01 fails to handle appropriately some parameters inside the input data, resulting in a stack-based buffer overflow vulnerability. When a user of the affected product is trick… CWE-787
 Out-of-bounds Write
CVE-2024-43700 2024-10-15 23:35 2024-08-29 Show GitHub Exploit DB Packet Storm
315082 8.8 HIGH
Network
google chrome Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page… CWE-787
 Out-of-bounds Write
CVE-2024-8198 2024-10-15 23:35 2024-08-29 Show GitHub Exploit DB Packet Storm
315083 8.8 HIGH
Network
google chrome Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CWE-787
 Out-of-bounds Write
CVE-2024-7534 2024-10-15 23:35 2024-08-7 Show GitHub Exploit DB Packet Storm
315084 5.4 MEDIUM
Network
wpuserplus userplus The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.… CWE-862
 Missing Authorization
CVE-2024-9520 2024-10-15 23:34 2024-10-10 Show GitHub Exploit DB Packet Storm
315085 5.4 MEDIUM
Network
esri portal_for_arcgis There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could render arb… CWE-79
Cross-site Scripting
CVE-2024-38039 2024-10-15 23:34 2024-10-5 Show GitHub Exploit DB Packet Storm
315086 6.1 MEDIUM
Network
esri portal_for_arcgis There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and 10.9.1 that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary … CWE-601
Open Redirect
CVE-2024-38037 2024-10-15 23:34 2024-10-5 Show GitHub Exploit DB Packet Storm
315087 5.4 MEDIUM
Network
esri portal_for_arcgis There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1, 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked coul… CWE-79
Cross-site Scripting
CVE-2024-38036 2024-10-15 23:34 2024-10-5 Show GitHub Exploit DB Packet Storm
315088 4.8 MEDIUM
Network
esri portal_for_arcgis There is a reflected cross site scripting in Esri Portal for ArcGIS 11.1 and below on Windows and Linux x64 allows a remote authenticated attacker with administrative access to supply a crafted strin… CWE-79
Cross-site Scripting
CVE-2024-25707 2024-10-15 23:34 2024-10-5 Show GitHub Exploit DB Packet Storm
315089 6.1 MEDIUM
Network
esri portal_for_arcgis There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1, 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked coul… CWE-79
Cross-site Scripting
CVE-2024-38038 2024-10-15 23:33 2024-10-5 Show GitHub Exploit DB Packet Storm
315090 4.3 MEDIUM
Network
andreamarinucci notification_for_telegram The Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing capability check on the 'nftb_test_action' function in versions up to, and inclu… CWE-862
 Missing Authorization
CVE-2024-9685 2024-10-15 23:30 2024-10-10 Show GitHub Exploit DB Packet Storm