Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
194381 6.5 警告
Network
w3m project
openSUSE project
- w3m の parsetagx.c におけるアプリケーションのクラッシュを引き起こされる脆弱性 CWE-20
不適切な入力確認
CVE-2016-9436 2017-01-30 16:57 2016-08-20 Show GitHub Exploit DB Packet Storm
194382 6.5 警告
Network
w3m project
openSUSE project
- w3m の file.c の HTMLtagproc1 関数におけるアプリケーションのクラッシュを引き起こされる脆弱性 CWE-20
不適切な入力確認
CVE-2016-9435 2017-01-30 16:57 2016-08-20 Show GitHub Exploit DB Packet Storm
194383 7 重要
Local
Lenovo - Lenovo XClarity Administrator における権限を昇格される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-8221 2017-01-30 16:48 2016-10-13 Show GitHub Exploit DB Packet Storm
194384 6.1 警告
Network
Exponent CMS project - Exponent CMS におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-8684 2017-01-30 16:46 2015-12-25 Show GitHub Exploit DB Packet Storm
194385 6.1 警告
Network
Exponent CMS project - Exponent CMS の Reset Your Password モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-8667 2017-01-30 16:46 2015-12-24 Show GitHub Exploit DB Packet Storm
194386 7.8 重要
Local
サムスン - Samsung Note デバイスの Telecom アプリケーションの SmartCall Activity コンポーネントにおけるサービス運用妨害 (DoS) の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-6527 2017-01-30 16:45 2016-05-11 Show GitHub Exploit DB Packet Storm
194387 7.8 重要
Local
サムスン - Samsung Note デバイスの Telecom アプリケーションの SpamCall Activity コンポーネントにおけるサービス運用妨害 (DoS) の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-6526 2017-01-30 16:45 2016-05-11 Show GitHub Exploit DB Packet Storm
194388 5.5 警告
Local
ImageMagick - ImageMagick の magick/attribute.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-416
解放済みメモリの使用
CVE-2016-7906 2017-01-30 15:58 2016-10-2 Show GitHub Exploit DB Packet Storm
194389 5.5 警告
Local
ImageMagick - ImageMagick の MagickCore/profile.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-125
境界外読み取り
CVE-2016-7799 2017-01-30 15:58 2016-10-2 Show GitHub Exploit DB Packet Storm
194390 6.5 警告
Network
ImageMagick - ImageMagick の SGI コーダにおけるサービス運用妨害 (DoS) の脆弱性 CWE-125
境界外読み取り
CVE-2016-7101 2017-01-30 15:58 2016-08-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 24, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
293231 - shop-script shop-script Directory traversal vulnerability in index.php in Shop-Script 2.0 and possibly other versions allows remote attackers to read arbitrary files via a .. (dot dot) in the aux_page parameter. CWE-22
Path Traversal
CVE-2008-0158 2017-09-29 10:30 2008-01-9 Show GitHub Exploit DB Packet Storm
293232 - eggblog eggblog SQL injection vulnerability in index.php in eggBlog 3.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the eggblogpassword parameter in a cookie. CWE-89
SQL Injection
CVE-2008-0159 2017-09-29 10:30 2008-01-9 Show GitHub Exploit DB Packet Storm
293233 - spacial_audio_solutions samphpweb SQL injection vulnerability in songinfo.php in SAM Broadcaster samPHPweb, possibly 4.2.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the songid parameter. CWE-89
SQL Injection
CVE-2008-0187 2017-09-29 10:30 2008-01-10 Show GitHub Exploit DB Packet Storm
293234 - uebimiau webmail Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests, which allows remote attackers to bypass authentication via a sess[auth]=1 param… CWE-287
Improper Authentication
CVE-2008-0210 2017-09-29 10:30 2008-01-10 Show GitHub Exploit DB Packet Storm
293235 - php_webquest php_webquest SQL injection vulnerability in soporte_horizontal_w.php in PHP Webquest 2.6 allows remote attackers to execute arbitrary SQL commands via the id_actividad parameter, a different vector than CVE-2007-… CWE-89
SQL Injection
CVE-2008-0219 2017-09-29 10:30 2008-01-11 Show GitHub Exploit DB Packet Storm
293236 - gateway cweblaunchctl_activex_control
weblaunch
Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allow remote attackers to execute arbitrary cod… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2008-0220 2017-09-29 10:30 2008-01-11 Show GitHub Exploit DB Packet Storm
293237 - gateway weblaunch Directory traversal vulnerability in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allows remote attackers to execute arbitrary progra… CWE-22
Path Traversal
CVE-2008-0221 2017-09-29 10:30 2008-01-11 Show GitHub Exploit DB Packet Storm
293238 - wordpress filemanager Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors. CWE-94
Code Injection
CVE-2008-0222 2017-09-29 10:30 2008-01-11 Show GitHub Exploit DB Packet Storm
293239 - osdate osdate PHP remote file inclusion vulnerability in php121db.php in osDate 2.0.8 and possibly earlier versions allows remote attackers to execute arbitrary PHP code via a URL in the php121dir parameter. CWE-94
Code Injection
CVE-2008-0230 2017-09-29 10:30 2008-01-11 Show GitHub Exploit DB Packet Storm
293240 - zero_cms zero_cms Multiple SQL injection vulnerabilities in Zero CMS 1.0 Alpha allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to index.php, or the (2) f or t parameters to forums/ind… CWE-89
SQL Injection
CVE-2008-0232 2017-09-29 10:30 2008-01-11 Show GitHub Exploit DB Packet Storm