Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
193141 5.9 警告
Network
Movim - Movim の複数の XMPP クライアントの "XEP-0280: Message Carbons" の実装における連絡先を含むユーザになりすまされる脆弱性 CWE-20
CWE-346
CVE-2017-5605 2017-03-8 15:04 2017-01-28 Show GitHub Exploit DB Packet Storm
193142 5.9 警告
Network
mcabber - mcabber の複数の XMPP クライアントの "XEP-0280: Message Carbons" の実装における連絡先を含むユーザになりすまされる脆弱性 CWE-20
CWE-346
CVE-2017-5604 2017-03-8 15:04 2017-01-26 Show GitHub Exploit DB Packet Storm
193143 5.9 警告
Network
Jitsi - Jitsi の複数の XMPP クライアントの "XEP-0280: Message Carbons" の実装における連絡先を含むユーザになりすまされる脆弱性 CWE-20
CWE-346
CVE-2017-5603 2017-03-8 15:04 2017-01-27 Show GitHub Exploit DB Packet Storm
193144 5.9 警告
Network
Jappix - jappix の複数の XMPP クライアントの "XEP-0280: Message Carbons" の実装における連絡先を含むユーザになりすまされる脆弱性 CWE-20
CWE-346
CVE-2017-5602 2017-03-8 15:04 2017-01-27 Show GitHub Exploit DB Packet Storm
193145 5.9 警告
Network
Psi+ Dev Team - Psi+ の複数の XMPP クライアントの "XEP-0280: Message Carbons" の実装における連絡先を含むユーザになりすまされる脆弱性 CWE-20
CWE-346
CVE-2017-5593 2017-03-8 15:04 2017-01-25 Show GitHub Exploit DB Packet Storm
193146 5.9 警告
Network
profanity - profanity の複数の XMPP クライアントの "XEP-0280: Message Carbons" の実装における連絡先を含むユーザになりすまされる脆弱性 CWE-20
CWE-346
CVE-2017-5592 2017-03-8 15:04 2017-01-24 Show GitHub Exploit DB Packet Storm
193147 5.9 警告
Network
SleekXMPP project
Slixmpp project
- SleekXMPP および Slixmpp の複数の XMPP クライアントの "XEP-0280: Message Carbons" の実装における連絡先を含むユーザになりすまされる脆弱性 CWE-20
CWE-346
CVE-2017-5591 2017-03-8 15:04 2017-01-28 Show GitHub Exploit DB Packet Storm
193148 5.9 警告
Network
Georg Lukas - yaxim および Bruno の複数の XMPP クライアントの "XEP-0280: Message Carbons" の実装における連絡先を含むユーザになりすまされる脆弱性 CWE-20
CWE-346
CVE-2017-5589 2017-03-8 15:04 2017-01-30 Show GitHub Exploit DB Packet Storm
193149 6.1 警告
Network
Schneider Electric - Schneider Electric homeLYnk Controller におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-5157 2017-03-8 15:03 2017-01-18 Show GitHub Exploit DB Packet Storm
193150 9.8 緊急
Network
Schneider Electric - Schneider Electric PowerLogic PM8ECC におけるデバイスへのアクセスを許容される脆弱性 CWE-798
ハードコードされた認証情報の使用
CVE-2016-5818 2017-03-8 15:03 2016-10-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 26, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
294131 - alstrasoft askme_pro SQL injection vulnerability in profile.php in AlstraSoft AskMe Pro 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: The que_id parameter to forum… CWE-89
SQL Injection
CVE-2008-2902 2017-09-29 10:31 2008-07-1 Show GitHub Exploit DB Packet Storm
294132 - awbs advanced_webhost_billing_system SQL injection vulnerability in news.php in Advanced Webhost Billing System (AWBS) 2.3.3 through 2.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via… CWE-89
SQL Injection
CVE-2008-2903 2017-09-29 10:31 2008-07-1 Show GitHub Exploit DB Packet Storm
294133 - phpmycart phpmycart SQL injection vulnerability in shop.php in Conkurent PHPMyCart allows remote attackers to execute arbitrary SQL commands via the cat parameter. CWE-89
SQL Injection
CVE-2008-2904 2017-09-29 10:31 2008-07-1 Show GitHub Exploit DB Packet Storm
294134 - mambo mambo PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when register_globals is enabled, allows remote attackers to execute ar… CWE-94
Code Injection
CVE-2008-2905 2017-09-29 10:31 2008-07-1 Show GitHub Exploit DB Packet Storm
294135 - webchamado webchamado SQL injection vulnerability in lista_anexos.php in WebChamado 1.1 allows remote attackers to execute arbitrary SQL commands via the tsk_id parameter. CWE-89
SQL Injection
CVE-2008-2906 2017-09-29 10:31 2008-07-1 Show GitHub Exploit DB Packet Storm
294136 - webchamado webchamado SQL injection vulnerability in admin/index.php in WebChamado 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the eml parameter. CWE-89
SQL Injection
CVE-2008-2907 2017-09-29 10:31 2008-07-1 Show GitHub Exploit DB Packet Storm
294137 - muvee autoproducer Buffer overflow in the DXTTextOutEffect ActiveX control (aka the Text-Effect DXT Filter), as distributed in TextOut.dll 6.0.18.1 and mvtextout.dll, in muvee autoProducer 6.0 and 6.1 allows remote att… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2008-2910 2017-09-29 10:31 2008-07-1 Show GitHub Exploit DB Packet Storm
294138 - contenido contendio Multiple cross-site scripting (XSS) vulnerabilities in index.php in Contenido 4.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) contenido, (2) Belang, and (3) username p… CWE-79
Cross-site Scripting
CVE-2008-2911 2017-09-29 10:31 2008-07-1 Show GitHub Exploit DB Packet Storm
294139 - contenido contenido_cms Multiple PHP remote file inclusion vulnerabilities in Contenido CMS 4.8.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) contenido_path parameter to (a) contenido/backend_s… CWE-94
Code Injection
CVE-2008-2912 2017-09-29 10:31 2008-07-1 Show GitHub Exploit DB Packet Storm
294140 - devalcms devalcms Directory traversal vulnerability in func.php in Devalcms 1.4a, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the curre… CWE-22
Path Traversal
CVE-2008-2913 2017-09-29 10:31 2008-07-1 Show GitHub Exploit DB Packet Storm