Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1201 5.3 警告
Network
Sick Enterprise Analytics SickのEnterprise Analyticsにおける不適切なログ出力の無効化に関する脆弱性 CWE-117
不適切なログ出力の無効化
CVE-2025-58580 2026-01-28 12:41 2025-10-6 Show GitHub Exploit DB Packet Storm
1202 4.3 警告
Network
Sick Enterprise Analytics SickのEnterprise Analyticsにおける情報漏えいに関する脆弱性 CWE-200
CWE-noinfo
CVE-2025-58581 2026-01-28 12:41 2025-10-6 Show GitHub Exploit DB Packet Storm
1203 7.5 重要
Network
Sick Enterprise Analytics SickのEnterprise Analyticsにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2025-58582 2026-01-28 12:41 2025-10-6 Show GitHub Exploit DB Packet Storm
1204 5.3 警告
Network
Sick Enterprise Analytics SickのEnterprise Analyticsにおける認可されていない制御領域への重要情報の漏えいに関する脆弱性 CWE-497
認可されていない制御領域への重要情報の漏えい
CVE-2025-58583 2026-01-28 12:41 2025-10-6 Show GitHub Exploit DB Packet Storm
1205 7.5 重要
Network
Sick Enterprise Analytics
Package Analytics
Tire Analytics
Logistics Diagnostic Analytics
Baggage Analytics
SickのBaggage Analytics等の複数製品におけるGET リクエストにおけるクエリ文字列からの情報漏えいに関する脆弱性 CWE-598
GET リクエストにおけるクエリ文字列からの情報漏えい
CVE-2025-58584 2026-01-28 12:41 2025-10-6 Show GitHub Exploit DB Packet Storm
1206 6.1 警告
Network
Astun Technology Ltd iShare Maps Astun Technology LtdのiShare Mapsにおけるオープンリダイレクトの脆弱性 CWE-601
オープンリダイレクト
CVE-2025-6089 2026-01-28 12:41 2025-06-15 Show GitHub Exploit DB Packet Storm
1207 9.8 緊急
Network
Nitro Software Inc. Nitro PDF Pro Nitro Software Inc.のNitro PDF Proにおける同一生成元ポリシー違反に関する脆弱性 CWE-346
同一生成元ポリシー違反
CVE-2025-67825 2026-01-28 12:41 2026-01-8 Show GitHub Exploit DB Packet Storm
1208 8.1 重要
Network
Qode Interactive Wellspring Qode InteractiveのWordPress用WellspringにおけるPHP リモートファイルインクルージョンの脆弱性 CWE-98
PHP リモートファイルインクルージョン
CVE-2025-67934 2026-01-28 12:41 2026-01-8 Show GitHub Exploit DB Packet Storm
1209 6.5 警告
Network
Apache Software Foundation Apache Spatial Information System (SIS) Apache Software FoundationのApache Spatial Information System (SIS)におけるXML 外部エンティティの脆弱性 CWE-611
XML 外部エンティティ参照の不適切な制限
CVE-2025-68280 2026-01-28 12:41 2026-01-5 Show GitHub Exploit DB Packet Storm
1210 4.8 警告
Network
Centreon Centreon Open Tickets CentreonのCentreon Open Ticketsにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-8460 2026-01-28 12:41 2025-12-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 24, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
283691 - oracle database_server Buffer overflow in MDSYS.SDO_CS in Oracle Database Server 8iR3, 9iR1, 9iR2 up to 9.2.0.6, and 10gR1 up to 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) and execute a… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-5897 2018-10-16 06:46 2007-11-9 Show GitHub Exploit DB Packet Storm
283692 - php php The (1) htmlentities and (2) htmlspecialchars functions in PHP before 5.2.5 accept partial multibyte sequences, which has unknown impact and attack vectors, a different issue than CVE-2006-5465. NVD-CWE-noinfo
CVE-2007-5898 2018-10-16 06:46 2007-11-21 Show GitHub Exploit DB Packet Storm
283693 - php php The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive in… CWE-200
Information Exposure
CVE-2007-5899 2018-10-16 06:46 2007-11-21 Show GitHub Exploit DB Packet Storm
283694 - viart shop ideal_process.php in the iDEAL payment module in ViArt Shop 3.3 beta and earlier might allow remote attackers to obtain the pathname for certificate and key files via an "iDEAL transaction", possibly… CWE-22
Path Traversal
CVE-2007-5463 2018-10-16 06:45 2007-10-16 Show GitHub Exploit DB Packet Storm
283695 - lfs live_for_speed Stack-based buffer overflow in Live for Speed 0.5X10 and earlier allows remote authenticated users to cause a denial of service (client crash) and possibly execute arbitrary code via a long skin name. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-5464 2018-10-16 06:45 2007-10-16 Show GitHub Exploit DB Packet Storm
283696 - atheros
linksys
ar5416-ac1e_chipset
wrt350n
The driver for the Linksys WRT350N Wi-Fi access point with firmware 2.00.17 on the Atheros AR5416-AC1E chipset does not properly parse the Atheros vendor-specific information element in an associatio… CWE-20
 Improper Input Validation 
CVE-2007-5474 2018-10-16 06:45 2008-09-6 Show GitHub Exploit DB Packet Storm
283697 - marvell
linksys
88w8361p-bem_chipset
wap4400n
Multiple buffer overflows in the Marvell wireless driver, as used in Linksys WAP4400N Wi-Fi access point with firmware 1.2.17 on the Marvell 88W8361P-BEM1 chipset, and other products, allow remote 80… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-5475 2018-10-16 06:45 2009-11-13 Show GitHub Exploit DB Packet Storm
283698 - nabh_information_systems stringbeans_portal Cross-site scripting (XSS) vulnerability in projects in Nabh Stringbeans Portal (sbportal) 3.2 allows remote attackers to inject arbitrary web script or HTML via the project_name parameter. CWE-79
Cross-site Scripting
CVE-2007-5478 2018-10-16 06:45 2007-10-17 Show GitHub Exploit DB Packet Storm
283699 - xcomputer xcomputer Cross-site scripting (XSS) vulnerability in Search.asp in Xcomputer allows remote attackers to inject arbitrary web script or HTML via the EXPS parameter. CWE-79
Cross-site Scripting
CVE-2007-5479 2018-10-16 06:45 2007-10-17 Show GitHub Exploit DB Packet Storm
283700 - wwwisis wwwisis Directory traversal vulnerability in wxis.exe in WWWISIS 7.1 allows local users to read arbitrary files via a .. (dot dot) in the IsisScript parameter to iah. CWE-22
Path Traversal
CVE-2007-5484 2018-10-16 06:45 2007-10-17 Show GitHub Exploit DB Packet Storm