Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
193861 6.1 警告
Network
MyBB Group - MyBB および Merge System のメンバー検証におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-9405 2017-02-13 15:31 2016-03-11 Show GitHub Exploit DB Packet Storm
193862 6.1 警告
Network
MyBB Group - MyBB および Merge System におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-9404 2017-02-13 15:31 2016-03-11 Show GitHub Exploit DB Packet Storm
193863 9.8 緊急
Network
MyBB Group - MyBB および Merge System の newreply.php における脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-9403 2017-02-13 15:31 2016-03-11 Show GitHub Exploit DB Packet Storm
193864 9.8 緊急
Network
MyBB Group - MyBB および Merge System の moderation ツールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2016-9402 2017-02-13 15:31 2016-03-11 Show GitHub Exploit DB Packet Storm
193865 7.5 重要
Network
MyBB Group - MyBB および Merge System におけるインストールパスを取得される脆弱性 CWE-532
ログファイルからの情報漏えい
CVE-2015-8977 2017-02-13 15:30 2015-09-7 Show GitHub Exploit DB Packet Storm
193866 6.1 警告
Network
MyBB Group - MyBB および Merge System におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-8976 2017-02-13 15:30 2015-09-7 Show GitHub Exploit DB Packet Storm
193867 6.1 警告
Network
MyBB Group - MyBB および Merge System のエラーハンドラにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-8975 2017-02-13 15:30 2015-09-7 Show GitHub Exploit DB Packet Storm
193868 10 緊急
Network
MyBB Group - MyBB および Merge System の管理制御パネルの Group Promotions モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2015-8974 2017-02-13 15:30 2015-09-7 Show GitHub Exploit DB Packet Storm
193869 8.3 重要
Network
MyBB Group - MyBB および Merge System の xmlhttp.php におけるアクセス制限を回避される脆弱性 CWE-284
不適切なアクセス制御
CVE-2015-8973 2017-02-13 15:30 2015-09-7 Show GitHub Exploit DB Packet Storm
193870 7.5 重要
Network
Libical project - Libical の icaltime_from_string 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-125
境界外読み取り
CVE-2016-5827 2017-02-13 15:25 2016-06-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
294641 - censura censura SQL injection vulnerability in censura.php in Censura 1.16.04 allows remote attackers to execute arbitrary SQL commands via the itemid parameter in a details action. CWE-89
SQL Injection
CVE-2009-2593 2017-09-19 10:29 2009-07-25 Show GitHub Exploit DB Packet Storm
294642 - censura censura Cross-site scripting (XSS) vulnerability in censura.php in Censura 1.16.04 allows remote attackers to inject arbitrary web script or HTML via the itemid parameter in a details action. CWE-79
Cross-site Scripting
CVE-2009-2594 2017-09-19 10:29 2009-07-25 Show GitHub Exploit DB Packet Storm
294643 - radscripts radclassifieds SQL injection vulnerability in index.php in RadCLASSIFIEDS Gold 2.0 allows remote attackers to execute arbitrary SQL commands via the seller parameter in a search action. CWE-89
SQL Injection
CVE-2009-2599 2017-09-19 10:29 2009-07-27 Show GitHub Exploit DB Packet Storm
294644 - akiva webboard Multiple directory traversal vulnerabilities in view.php in Webboard 2.90 beta and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the topic parameter. CWE-22
Path Traversal
CVE-2009-2600 2017-09-19 10:29 2009-07-27 Show GitHub Exploit DB Packet Storm
294645 - joomlaequipment juser SQL injection vulnerability in the Joomlaequipment (aka JUser or com_juser) component 2.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a show_profil… CWE-89
SQL Injection
CVE-2009-2601 2017-09-19 10:29 2009-07-27 Show GitHub Exploit DB Packet Storm
294646 - r2newsletter r2_newsletter_lite
r2_newsletter_pro
r2_newsletter_stats
R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request f… CWE-264
Permissions, Privileges, and Access Controls
CVE-2009-2602 2017-09-19 10:29 2009-07-27 Show GitHub Exploit DB Packet Storm
294647 - e-supportportal escon_supportportal_pro Multiple SQL injection vulnerabilities in index.php in Escon SupportPortal Pro 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) cat and (2) tid parameters. CWE-89
SQL Injection
CVE-2009-2603 2017-09-19 10:29 2009-07-27 Show GitHub Exploit DB Packet Storm
294648 - zenhelpdesk zen_help_desk Multiple SQL injection vulnerabilities in adminlogin.asp in Zen Help Desk 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) userid (aka username) and (2) PassWord parameters to… CWE-89
SQL Injection
CVE-2009-2604 2017-09-19 10:29 2009-07-27 Show GitHub Exploit DB Packet Storm
294649 - traidnt traidnt_up Multiple SQL injection vulnerabilities in adminquery.php in Traidnt Up 2.0 allow remote attackers to execute arbitrary SQL commands via (1) trupuser and (2) truppassword cookies to uploadcp/index.php. CWE-89
SQL Injection
CVE-2009-2605 2017-09-19 10:29 2009-07-27 Show GitHub Exploit DB Packet Storm
294650 - brainjar asp_football_pool ASP Football Pool 2.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for NFL.mdb. CWE-264
Permissions, Privileges, and Access Controls
CVE-2009-2606 2017-09-19 10:29 2009-07-27 Show GitHub Exploit DB Packet Storm