Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1181 7.8 重要
Local
クアルコム WSA8835 ファームウェア
fastconnect 6200 ファームウェア
sw5100 ファームウェア
wcd9395 ファームウェア
WCD9385 ファームウェア
WCN3988 ファームウェア
wcn7880 ファームウェア
SXR2330P ファーム…
クアルコムのfastconnect 6200 ファームウェア等の複数製品における古典的バッファオーバーフローの脆弱性 CWE-120
古典的バッファオーバーフロー
CVE-2025-47388 2026-01-28 12:42 2026-01-7 Show GitHub Exploit DB Packet Storm
1182 7.8 重要
Local
クアルコム WSA8835 ファームウェア
fastconnect 6200 ファームウェア
sw5100 ファームウェア
wcd9395 ファームウェア
WCD9385 ファームウェア
WCN3988 ファームウェア
wcn7880 ファームウェア
SXR2330P ファーム…
クアルコムのfastconnect 6200 ファームウェア等の複数製品における古典的バッファオーバーフローの脆弱性 CWE-120
古典的バッファオーバーフロー
CVE-2025-47394 2026-01-28 12:42 2026-01-7 Show GitHub Exploit DB Packet Storm
1183 7.8 重要
Local
クアルコム WSA8835 ファームウェア
fastconnect 6200 ファームウェア
sw5100 ファームウェア
wcd9395 ファームウェア
Snapdragon AR1 Gen 1 Platform "Luna1" ファームウェア
W…
クアルコムのfastconnect 6200 ファームウェア等の複数製品における二重解放に関する脆弱性 CWE-415
二重解放
CVE-2025-47396 2026-01-28 12:42 2026-01-7 Show GitHub Exploit DB Packet Storm
1184 6.1 警告
Network
Sick
firefly
Package Analytics
Field Analytics
Tire Analytics
media server
Logistics Diagnostic Analytics
Baggage Analytics
SickのBaggage Analytics等の複数製品における保護メカニズムの不具合に関する脆弱性 CWE-693
保護メカニズムの不具合
CVE-2025-49193 2026-01-28 12:42 2025-06-12 Show GitHub Exploit DB Packet Storm
1185 7.5 重要
Network
firefly media server SickのMedia Serverにおける重要な情報の平文での送信に関する脆弱性 CWE-319
重要な情報の平文での送信
CVE-2025-49194 2026-01-28 12:42 2025-06-12 Show GitHub Exploit DB Packet Storm
1186 9.8 緊急
Network
firefly media server SickのMedia Serverにおける過度な認証試行の不適切な制限に関する脆弱性 CWE-307
過度な認証試行の不適切な制限
CVE-2025-49195 2026-01-28 12:42 2025-06-12 Show GitHub Exploit DB Packet Storm
1187 9.1 緊急
Network
Sick Field Analytics SickのField Analyticsにおける暗号アルゴリズムの使用に関する脆弱性 CWE-327
不完全、または危険な暗号アルゴリズムの使用
CVE-2025-49196 2026-01-28 12:42 2025-06-12 Show GitHub Exploit DB Packet Storm
1188 7.5 重要
Network
firefly media server SickのMedia Serverにおける弱いハッシュの使用に関する脆弱性 CWE-328
脆弱なハッシュの使用
CVE-2025-49197 2026-01-28 12:42 2025-06-12 Show GitHub Exploit DB Packet Storm
1189 7.5 重要
Network
firefly media server SickのMedia Serverにおける不十分なランダム値の使用に関する脆弱性 CWE-330
不十分なランダム値の使用
CVE-2025-49198 2026-01-28 12:42 2025-06-12 Show GitHub Exploit DB Packet Storm
1190 9.8 緊急
Network
Sick Field Analytics SickのField Analyticsにおけるデータの信頼性についての不十分な検証に関する脆弱性 CWE-345
データの信頼性についての不十分な検証
CVE-2025-49199 2026-01-28 12:42 2025-06-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
283481 - x.org tog-cup
xserver
The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to read the contents of arbitrary memory locations via a request … NVD-CWE-Other
CVE-2007-6428 2018-10-16 06:53 2008-01-19 Show GitHub Exploit DB Packet Storm
283482 - x.org evi
mit-shm
xserver
Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing a 32-bit value that is improperly used … CWE-189
CWE-362
Numeric Errors
Race Condition
CVE-2007-6429 2018-10-16 06:53 2008-01-19 Show GitHub Exploit DB Packet Storm
283483 - real_time_logic barracudadrive_web_server
barracudadrive_web_server_home_server
BarracudaDrive Web Server before 3.8 allows remote attackers to read the source code for web scripts by appending a (1) + (plus), (2) . (dot), or (3) %80 and similar characters to the file name in th… CWE-20
 Improper Input Validation 
CVE-2007-6314 2018-10-16 06:52 2007-12-12 Show GitHub Exploit DB Packet Storm
283484 - real_time_logic barracudadrive_web_server
barracudadrive_web_server_home_server
Group Chat in BarracudaDrive Web Server before 3.8 allows remote authenticated users to cause a denial of service (crash) via a HTTP request to /eh/chat.ehintf/C. that does not contain a Connection I… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-6315 2018-10-16 06:52 2007-12-12 Show GitHub Exploit DB Packet Storm
283485 - real_time_logic barracudadrive_web_server
barracudadrive_web_server_home_server
Cross-site scripting (XSS) vulnerability in BarracudaDrive Web Server before 3.8 allows remote attackers to inject arbitrary web script or HTML via the URI path in an HTTP GET request, which is activ… CWE-79
Cross-site Scripting
CVE-2007-6316 2018-10-16 06:52 2007-12-12 Show GitHub Exploit DB Packet Storm
283486 - real_time_logic barracudadrive_web_server
barracudadrive_web_server_home_server
Multiple directory traversal vulnerabilities in BarracudaDrive Web Server before 3.8 allow (1) remote attackers to read arbitrary files via certain ..\ (dot dot backslash) sequences in the URL path, … CWE-22
Path Traversal
CVE-2007-6317 2018-10-16 06:52 2007-12-12 Show GitHub Exploit DB Packet Storm
283487 - wordpress wordpress SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the s parameter, when DB_CHARSET is set to (1) Big5, … CWE-89
SQL Injection
CVE-2007-6318 2018-10-16 06:52 2007-12-12 Show GitHub Exploit DB Packet Storm
283488 - lyris list_manager Multiple unspecified vulnerabilities in Lyris ListManager 8.x before 8.95d, 9.2 before 9.2c, and 9.3 before 9.3b allow remote attackers to (1) gain list administrator privileges or (2) access arbitra… NVD-CWE-noinfo
CWE-264
Permissions, Privileges, and Access Controls
CVE-2007-6319 2018-10-16 06:52 2008-02-20 Show GitHub Exploit DB Packet Storm
283489 - roundcube webmail Cross-site scripting (XSS) vulnerability in RoundCube webmail 0.1rc2, 2007-12-09, and earlier versions, when using Internet Explorer, allows remote attackers to inject arbitrary web script or HTML vi… CWE-79
Cross-site Scripting
CVE-2007-6321 2018-10-16 06:52 2007-12-12 Show GitHub Exploit DB Packet Storm
283490 - microsoft office Microsoft Office 2007 12.0.6015.5000 and MSO 12.0.6017.5000 do not sign the metadata of Office Open XML (OOXML) documents, which makes it easier for remote attackers to modify Dublin Core metadata fi… CWE-255
Credentials Management
CVE-2007-6329 2018-10-16 06:52 2007-12-14 Show GitHub Exploit DB Packet Storm