Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
193201 9.8 緊急
Network
Zend Technologies Ltd.
Fedora Project
- Zend Framework の Zend_Db_Select の order および group メソッドにおける SQL インジェクション攻撃を実行される脆弱性 CWE-89
SQLインジェクション
CVE-2016-6233 2017-03-7 15:36 2016-07-13 Show GitHub Exploit DB Packet Storm
193202 5.9 警告
Network
Timo Sirainen - Dovecot の auth コンポーネントにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2016-8652 2017-03-7 15:29 2016-12-3 Show GitHub Exploit DB Packet Storm
193203 6.1 警告
Network
Kabona AB - Kabona AB WebDatorCentral (WDC) アプリケーションにおける脆弱性 CWE-601
オープンリダイレクト
CVE-2016-8376 2017-03-7 15:18 2016-10-13 Show GitHub Exploit DB Packet Storm
193204 8.2 重要
Network
Kabona AB - Kabona AB WebDatorCentral (WDC) アプリケーションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-8356 2017-03-7 15:18 2016-10-13 Show GitHub Exploit DB Packet Storm
193205 9.8 緊急
Network
Algorithm - BINOM3 Universal Multifunctional Electric Power Quality Meter における脆弱性 CWE-798
ハードコードされた認証情報の使用
CVE-2017-5167 2017-03-7 15:15 2017-01-31 Show GitHub Exploit DB Packet Storm
193206 9.8 緊急
Network
Algorithm - BINOM3 Universal Multifunctional Electric Power Quality Meter におけるデバイスへのアクセス権を取得される脆弱性 CWE-200
情報漏えい
CVE-2017-5166 2017-03-7 15:15 2017-01-31 Show GitHub Exploit DB Packet Storm
193207 7.6 重要
Network
Algorithm - BINOM3 Universal Multifunctional Electric Power Quality Meter におけるデバイス上で認証されていない操作を実行される脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2017-5165 2017-03-7 15:15 2017-01-31 Show GitHub Exploit DB Packet Storm
193208 6.1 警告
Network
Algorithm - BINOM3 Universal Multifunctional Electric Power Quality Meter におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-5164 2017-03-7 15:15 2017-01-31 Show GitHub Exploit DB Packet Storm
193209 9.8 緊急
Network
Algorithm - BINOM3 Universal Multifunctional Electric Power Quality Meter におけるアプリケーションのセットアップと設定にアクセスされる脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2017-5162 2017-03-7 15:15 2017-01-31 Show GitHub Exploit DB Packet Storm
193210 8.6 重要
Network
Honeywell International Inc. - Honeywell XL Web II コントローラ XL1000C500 および XLWeb 500 におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2017-5143 2017-03-7 15:06 2017-02-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 24, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
293951 - auracms auracms Multiple SQL injection vulnerabilities in AuraCMS 1.5rc allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) hal.php, (2) cetak.php, (3) lihat.php, (4) pesan.php, and … CWE-89
SQL Injection
CVE-2007-4804 2017-09-29 10:29 2007-09-12 Show GitHub Exploit DB Packet Storm
293952 - fuzzylime fuzzylime Directory traversal vulnerability in getgalldata.php in fuzzylime (cms) 3.0 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) in the p parameter. CWE-22
Path Traversal
CVE-2007-4805 2017-09-29 10:29 2007-09-12 Show GitHub Exploit DB Packet Storm
293953 - focus_sis focus_sis PHP remote file inclusion vulnerability in modules/Discipline/CategoryBreakdownTime.php in Focus/SIS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the FocusPath parameter. CWE-94
Code Injection
CVE-2007-4806 2017-09-29 10:29 2007-09-12 Show GitHub Exploit DB Packet Storm
293954 - focus_sis focus_sis Multiple PHP remote file inclusion vulnerabilities in Focus/SIS 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the staticpath parameter to (1) modules/Discipline/CategoryBreakd… CWE-94
Code Injection
CVE-2007-4807 2017-09-29 10:29 2007-09-12 Show GitHub Exploit DB Packet Storm
293955 - tlm_cms tlm_cms Multiple SQL injection vulnerabilities in TLM CMS 3.2 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to news.php in a lirenews action, (2) the idnews parameter to g… CWE-89
SQL Injection
CVE-2007-4808 2017-09-29 10:29 2007-09-12 Show GitHub Exploit DB Packet Storm
293956 - online_fantasy_football_league offl Multiple PHP remote file inclusion vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 allow remote attackers to execute arbitrary PHP code via a URL in the DOC_ROOT parameter to (1) lib/f… CWE-94
Code Injection
CVE-2007-4809 2017-09-29 10:29 2007-09-12 Show GitHub Exploit DB Packet Storm
293957 - baofeng storm Multiple buffer overflows in the BaoFeng2 storm ActiveX control in Mps.dll allow remote attackers to have an unknown impact via a long (1) URL, (2) backImage, or (3) titleImage property value; (4) a … CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-4816 2017-09-29 10:29 2007-09-12 Show GitHub Exploit DB Packet Storm
293958 - detodas restaurante_component_for_joomla Unrestricted file upload vulnerability in the Restaurante (com_restaurante) component for Joomla! allows remote attackers to upload and execute arbitrary PHP code via an upload action specifying a fi… CWE-94
Code Injection
CVE-2007-4817 2017-09-29 10:29 2007-09-12 Show GitHub Exploit DB Packet Storm
293959 - sisfo_kampus sisfo_kampus Absolute path traversal vulnerability in blanko.preview.php in Sisfo Kampus 2006 allows remote attackers to read arbitrary local files, and possibly execute local PHP scripts, via the nmf parameter. CWE-22
Path Traversal
CVE-2007-4820 2017-09-29 10:29 2007-09-12 Show GitHub Exploit DB Packet Storm
293960 - edraw office_viewer_component Buffer overflow in a certain ActiveX control in officeviewer.ocx 5.2.218.1 in EDraw Office Viewer Component 5.2 allows remote attackers to execute arbitrary code via a long first argument to the Http… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-4821 2017-09-29 10:29 2007-09-12 Show GitHub Exploit DB Packet Storm