NVD脆弱性情報トップ
検索メニュー表示
ベンダー名
プロダクト・サービス名
タイトル
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
公表日降順
更新日降順
表示数

NVD(National Vulnerability Database)で管理されている脆弱性の一覧を検索することが出来ます。
JVN(Japan Vulnerability Note)より先に脆弱性情報が更新される事が多いため、JVNに未記載の脆弱性が更新されている場合があります。

JVN(Japan Vulnerability Note)に関連した脆弱性がある場合は詳細画面で情報を表示します。

CWEで検索する場合は、CWE概要を参照して、CWE番号を確認してください。

  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW

更新日:2026年6月20日4:01

No CVSS レベル
攻撃区分
ベンダー名 プロダクト名 タイトル CWE CVE 更新日 公表日 影響表示 Exploit
PoC
検索
349251 4.3 MEDIUM
limbo_cms limbo_cms Cross-site scripting (XSS) vulnerability in webinsta Limbo 1.0.4.2 allows remote attackers to inject arbitrary web script or HTML via the message field in the Contact Form. NVD-CWE-Other
CVE-2006-0934 2017-07-20 10:30 2006-02-28 表示 GitHub Exploit DB Packet Storm
349252 5.0 MEDIUM
unu_networks mailgust U.N.U. Mailgust 1.9 allows remote attackers to obtain sensitive information via a direct request to index.php with method=showfullcsv, which reveals the POP3 server configuration, including account n… NVD-CWE-Other
CVE-2006-0937 2017-07-20 10:30 2006-02-28 表示 GitHub Exploit DB Packet Storm
349253 7.5 HIGH
dci-designs dci-taskeen SQL injection vulnerability in DCI-Taskeen 1.03 allows remote attackers to execute arbitrary SQL commands via the (1) id or (2) action parameter to (a) basket.php, or (3) id or (4) page parameter to … NVD-CWE-Other
CVE-2006-0939 2017-07-20 10:30 2006-03-1 表示 GitHub Exploit DB Packet Storm
349254 4.3 MEDIUM
thomson speedtouch Cross-site scripting (XSS) vulnerability in Thomson SpeedTouch modems running firmware 5.3.2.6.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter to the LocalNetw… NVD-CWE-Other
CVE-2006-0946 2017-07-20 10:30 2006-03-1 表示 GitHub Exploit DB Packet Storm
349255 5.0 MEDIUM
raidenhttpd raidenhttpd RaidenHTTPD 1.1.47 allows remote attackers to obtain source code of script files, including PHP, via crafted requests involving (1) "." (dot), (2) space, and (3) "/" (slash) characters. NVD-CWE-Other
CVE-2006-0949 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349256 5.0 MEDIUM
raidenhttpd raidenhttpd This vulnerability affects RaidenHTTPD, RaidenHTTPD version 1.1.47 and may affect all previous versions. NVD-CWE-Other
CVE-2006-0949 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349257 5.0 MEDIUM
compex netpassage_wpe54g uConfig agent in Compex NetPassage WPE54G router allows remote attackers to cause a denial of service (unresposiveness) via crafted datagrams to UDP port 7778. NVD-CWE-Other
CVE-2006-0960 2017-07-20 10:30 2006-03-3 表示 GitHub Exploit DB Packet Storm
349258 4.3 MEDIUM
battleaxe_software bttlxeforum Cross-site scripting (XSS) vulnerability in failure.asp in Battleaxe bttlxeForum 2.0 allows remote attackers to inject arbitrary web script or HTML via the err_txt parameter. NVD-CWE-Other
CVE-2006-0974 2017-07-20 10:30 2006-03-3 表示 GitHub Exploit DB Packet Storm
349259 4.3 MEDIUM
battleaxe_software bttlxeforum This vulnerability affects Battleaxe Software, bttlxeForum versions 2.0 and previous NVD-CWE-Other
CVE-2006-0974 2017-07-20 10:30 2006-03-3 表示 GitHub Exploit DB Packet Storm
349260 10.0 HIGH
nidelven_it issue_dealer Unspecified vulnerability in the local weblog publisher in Nidelven IT Issue Dealer before 0.9.96 has unknown impact and attack vectors. NVD-CWE-Other
CVE-2006-0979 2017-07-20 10:30 2006-03-3 表示 GitHub Exploit DB Packet Storm
349261 10.0 HIGH
nidelven_it issue_dealer This vulnerability affects Nidelven IT, Issue Dealer versions 0.9.95 and previous. NVD-CWE-Other
CVE-2006-0979 2017-07-20 10:30 2006-03-3 表示 GitHub Exploit DB Packet Storm
349262 5.0 MEDIUM
emc_dantz retrospect EMC Dantz Retrospect 7 backup client 7.0.107, and other versions before 7.0.109, and 6.5 before 6.5.138 allows remote attackers to cause a denial of service (client termination and loss of backup ser… NVD-CWE-Other
CVE-2006-0995 2017-07-20 10:30 2006-03-4 表示 GitHub Exploit DB Packet Storm
349263 5.0 MEDIUM
emc_dantz retrospect This vulnerability affects EMC Dantz, Retrospect versions 7.0.x (all 7.0.x versions previous to 7.0.109) as well as versions 6.5.x (all 6.5.x versions previous to 6.5.138) NVD-CWE-Other
CVE-2006-0995 2017-07-20 10:30 2006-03-4 表示 GitHub Exploit DB Packet Storm
349264 5.0 MEDIUM
netgear wgt624 The backup configuration option in NETGEAR WGT624 Wireless Firewall Router stores sensitive information in cleartext, which allows remote attackers to obtain passwords and gain privileges. NVD-CWE-Other
CVE-2006-1003 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349265 4.3 MEDIUM
cactusoft parodia Cross-site scripting (XSS) vulnerability in agencyprofile.asp in Parodia 6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the AG_ID parameter. NOTE: the provenance … NVD-CWE-Other
CVE-2006-1004 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349266 7.5 HIGH
sendcard sendcard Multiple SQL injection vulnerabilities in sendcard.php in sendcard before 3.3.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters. CWE-89
SQLインジェクション
CVE-2006-1006 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349267 4.6 MEDIUM
m4_project enigma-suite M4 Project enigma-suite before 0.73.3 (Windows) has a default password of "nominal" for the "enigma-client" account, which allows local users to gain access. NVD-CWE-Other
CVE-2006-1009 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349268 6.4 MEDIUM
crossfire crossfire Buffer overflow in socket/request.c in CrossFire before 1.9.0, when oldsocketmode is enabled, allows remote attackers to cause a denial of service (segmentation fault) and possibly execute code by se… NVD-CWE-Other
CVE-2006-1010 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349269 6.4 MEDIUM
crossfire crossfire This vulnerability affects CrossFire versions 1.8.0 and previous. NVD-CWE-Other
CVE-2006-1010 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349270 2.1 LOW
peters_software lettermerger LetterMerger 1.2 stores user information in Access database files with insecure permissions, which allows local users to obtain sensitive information. NOTE: the provenance of this information is unk… NVD-CWE-Other
CVE-2006-1011 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349271 7.5 HIGH
wordpress wordpress SQL injection vulnerability in WordPress 1.5.2, and possibly other versions before 2.0, allows remote attackers to execute arbitrary SQL commands via the User-Agent field in an HTTP header for a comm… NVD-CWE-Other
CVE-2006-1012 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349272 4.3 MEDIUM
ukiweb ukiboard Cross-site scripting (XSS) vulnerability in fce.php in UKiBoard 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a BBCode url tag when using the show_post function. NOTE: the… NVD-CWE-Other
CVE-2006-1019 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349273 7.5 HIGH
addsoft storebot SQL injection vulnerability in MgrLogin.asp in Addsoft StoreBot 2005 Professional allows remote attackers to execute arbitrary SQL commands via the Pwd parameter. NOTE: the provenance of this inform… NVD-CWE-Other
CVE-2006-1024 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349274 7.5 HIGH
addsoft storebot This vulnerability affects all versions of AddSoft, StoreBot 2005 Professional Edition. NVD-CWE-Other
CVE-2006-1024 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349275 6.8 MEDIUM
addsoft storebot Cross-site scripting (XSS) vulnerability in manage.asp in Addsoft StoreBot 2002 Standard allows remote attackers to inject arbitrary web script or HTML via the ShipMethod parameter. NOTE: the proven… NVD-CWE-Other
CVE-2006-1025 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349276 7.5 HIGH
jfacets jfacets JFacets before 0.2 allows remote attackers to gain privileges as any account via a GET request with a modified account profileID. NVD-CWE-Other
CVE-2006-1026 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349277 7.5 HIGH
jfacets jfacets This vulnerability affects JFacets versions prior to 0.2. NVD-CWE-Other
CVE-2006-1026 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349278 5.0 MEDIUM
joomla joomla Unspecified vulnerability in mod_templatechooser in Joomla! 1.0.7 allows remote attackers to obtain sensitive information via an unspecified attack vector that reveals the path. NVD-CWE-Other
CVE-2006-1030 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349279 7.5 HIGH
igenus igenus_webmail config/config_inc.php in iGENUS Webmail 2.02 and earlier allows remote attackers to include arbitrary local files via the SG_HOME parameter. CWE-94
コード・インジェクション
CVE-2006-1031 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349280 4.3 MEDIUM
cpg-nuke dragonfly_cms Multiple cross-site scripting (XSS) vulnerabilities in Dragonfly CMS before 9.0.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) uname, (2) error, (3) profile or (4) the user… NVD-CWE-Other
CVE-2006-1033 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349281 10.0 HIGH
van_dyke_technologies securecrt
securefx
Buffer overflow in SecureCRT 5.0.4 and earlier and SecureFX 3.0.4 and earlier allows remote attackers to have an unknown impact when a Unicode string is converted to a "narrow" string. NVD-CWE-Other
CVE-2006-1038 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349282 5.0 MEDIUM
monopd monopd server.cpp in Monopd 0.9.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a string containing a large number of characters that are escaped when Monopd produces… NVD-CWE-Other
CVE-2006-1046 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349283 5.0 MEDIUM
joomla joomla Joomla! 1.0.7 and earlier allows attackers to bypass intended access restrictions and gain certain privileges via certain attack vectors related to the (1) Weblink, (2) Polls, (3) Newsfeeds, (4) Webl… NVD-CWE-Other
CVE-2006-1048 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349284 5.0 MEDIUM
joomla joomla This vulnerability affects Joomla! versions 1.0.7 and previous. NVD-CWE-Other
CVE-2006-1048 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349285 7.5 HIGH
akarru social_bookmarking_engine SQL injection vulnerability in Akarru Social BookMarking Engine before 0.4.3.4 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors, possibly involving the username pa… NVD-CWE-Other
CVE-2006-1051 2017-07-20 10:30 2006-03-8 表示 GitHub Exploit DB Packet Storm
349286 7.5 HIGH
xzgv xzgv Heap-based buffer overflow in zgv before 5.8 and xzgv before 0.8 might allow user-assisted attackers to execute arbitrary code via a JPEG image with more than 3 output components, such as a CMYK or Y… CWE-119
バッファエラー
CVE-2006-1060 2017-07-20 10:30 2006-04-11 表示 GitHub Exploit DB Packet Storm
349287 7.5 HIGH
daniel_stenberg curl Heap-based buffer overflow in cURL and libcURL 7.15.0 through 7.15.2 allows remote attackers to execute arbitrary commands via a TFTP URL (tftp://) with a valid hostname and a long path. NVD-CWE-Other
CVE-2006-1061 2017-07-20 10:30 2006-03-21 表示 GitHub Exploit DB Packet Storm
349288 7.5 HIGH
daniel_stenberg curl Update to version 7.15.3. NVD-CWE-Other
CVE-2006-1061 2017-07-20 10:30 2006-03-21 表示 GitHub Exploit DB Packet Storm
349289 5.0 MEDIUM
lurker lurker Unspecified vulnerability in lurker.cgi for Lurker 2.0 and earlier allows attackers to read arbitrary files via unknown vectors. NVD-CWE-Other
CVE-2006-1062 2017-07-20 10:30 2006-03-8 表示 GitHub Exploit DB Packet Storm
349290 5.0 MEDIUM
lurker lurker This vulnerability affects all versions of Lurker from 0.1a through 0.2 NVD-CWE-Other
CVE-2006-1062 2017-07-20 10:30 2006-03-8 表示 GitHub Exploit DB Packet Storm
349291 5.0 MEDIUM
lurker lurker Unspecified vulnerability in Lurker 2.0 and earlier allows remote attackers to create or overwrite files in any writable directory that is named "mbox". NVD-CWE-Other
CVE-2006-1063 2017-07-20 10:30 2006-03-8 表示 GitHub Exploit DB Packet Storm
349292 5.0 MEDIUM
lurker lurker This vulnarability affects all verions of Lurker from 0.1a through 0.2 NVD-CWE-Other
CVE-2006-1063 2017-07-20 10:30 2006-03-8 表示 GitHub Exploit DB Packet Storm
349293 2.6 LOW
lurker lurker Multiple cross-site scripting (XSS) vulnerabilities in Lurker 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors. NVD-CWE-Other
CVE-2006-1064 2017-07-20 10:30 2006-03-8 表示 GitHub Exploit DB Packet Storm
349294 2.6 LOW
lurker lurker This vulnerability affects all verions of Lurker from 0.1a through 2.0 NVD-CWE-Other
CVE-2006-1064 2017-07-20 10:30 2006-03-8 表示 GitHub Exploit DB Packet Storm
349295 4.3 MEDIUM
punbb punbb Cross-site scripting (XSS) vulnerability in header.php in PunBB 1.2.10 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly handled when the PHP_SELF vari… NVD-CWE-Other
CVE-2006-1089 2017-07-20 10:30 2006-03-9 表示 GitHub Exploit DB Packet Storm
349296 7.8 HIGH
punbb punbb register.php in PunBB 1.2.10 allows remote attackers to cause an unspecified denial of service via a flood of new user registrations. NVD-CWE-Other
CVE-2006-1090 2017-07-20 10:30 2006-03-9 表示 GitHub Exploit DB Packet Storm
349297 7.8 HIGH
punbb punbb This vulnerability affects PunBB version 1.2.10, and may affect all previous versions. NVD-CWE-Other
CVE-2006-1090 2017-07-20 10:30 2006-03-9 表示 GitHub Exploit DB Packet Storm
349298 7.8 HIGH
kaspersky_lab kaspersky_anti-virus Kaspersky Antivirus 5.0.5 and 5.5.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via unknown attack vectors. NVD-CWE-Other
CVE-2006-1091 2017-07-20 10:30 2006-03-9 表示 GitHub Exploit DB Packet Storm
349299 7.2 HIGH
apache mod_python Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a crafted session cookie. CWE-22
パス・トラバーサル
CVE-2006-1095 2017-07-20 10:30 2006-03-9 表示 GitHub Exploit DB Packet Storm
349300 4.3 MEDIUM
datenbank_module datenbank_module Multiple cross-site scripting (XSS) vulnerabilities in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allow remote attackers to inject arbitrary web script or HTML via the fileid parameter t… NVD-CWE-Other
CVE-2006-1097 2017-07-20 10:30 2006-03-9 表示 GitHub Exploit DB Packet Storm