Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
211851 7.5 危険 Vicent Marti - Redcarpet の HTML レンダラの header_anchor 関数におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2015-5147 2015-07-15 14:22 2015-06-22 Show GitHub Exploit DB Packet Storm
211852 4.3 警告 シスコシステムズ - Cisco Unified Communications Manager の ccmivr ページにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-4272 2015-07-15 12:31 2015-07-13 Show GitHub Exploit DB Packet Storm
211853 4 警告 シスコシステムズ - Cisco Unified Communications Manager の Tomcat のスロットリング機能におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2015-4269 2015-07-15 12:23 2015-07-13 Show GitHub Exploit DB Packet Storm
211854 4.3 警告 thoughtbot - Ruby on Rails 用ライブラリ Paperclip におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-2963 2015-07-14 18:14 2015-06-18 Show GitHub Exploit DB Packet Storm
211855 5 警告 LEMON-S PHP - シンプルお絵描き掲示板におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-2969 2015-07-14 18:06 2015-07-10 Show GitHub Exploit DB Packet Storm
211856 6.4 警告 LEMON-S PHP - シンプルお絵描き掲示板における任意のファイル削除の脆弱性 CWE-22
パス・トラバーサル
CVE-2015-2970 2015-07-14 18:05 2015-07-10 Show GitHub Exploit DB Packet Storm
211857 2.6 注意 The Cacti Group - Cacti におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-2967 2015-07-14 18:02 2015-07-9 Show GitHub Exploit DB Packet Storm
211858 6.5 警告 Intelliants - Subrion CMS に SQL インジェクションの脆弱性 CWE-89
CWE-Other
CVE-2015-4129 2015-07-14 17:39 2015-05-8 Show GitHub Exploit DB Packet Storm
211859 5 警告 Namshi - namshi/jose におけるトークンの署名検証回避の脆弱性 CWE-Other
その他
CVE-2015-2964 2015-07-14 17:18 2015-06-25 Show GitHub Exploit DB Packet Storm
211860 5 警告 OpenEMR - OpenEMR における認証回避の脆弱性 CWE-287
不適切な認証
CVE-2015-4453 2015-07-14 17:15 2015-06-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 10, 2026, 5 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
3321 8.2 HIGH
Network
- - HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php that allow attackers to manipulate database queries by injecting SQL code through the 'id' parameter. An unauthenticate… CWE-89
SQL Injection
CVE-2018-25386 2026-05-30 01:29 2026-05-30 Show GitHub Exploit DB Packet Storm
3322 5.3 MEDIUM
Network
- - HaPe PKH 1.1 contains a cross-site request forgery vulnerability that allows attackers to change administrator passwords by submitting forged requests to the user update endpoint. Attackers can craft… CWE-352
 Origin Validation Error
CVE-2018-25387 2026-05-30 01:29 2026-05-30 Show GitHub Exploit DB Packet Storm
3323 8.8 HIGH
Network
- - HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. Attackers can upload PHP files through mu… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2018-25388 2026-05-30 01:29 2026-05-30 Show GitHub Exploit DB Packet Storm
3324 8.2 HIGH
Network
- - HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'nama_kelompok' POST parameter sent to lap-… CWE-89
SQL Injection
CVE-2018-25389 2026-05-30 01:29 2026-05-30 Show GitHub Exploit DB Packet Storm
3325 8.2 HIGH
Network
- - HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'desa' POST parameter sent to lap-peserta-p… CWE-89
SQL Injection
CVE-2018-25390 2026-05-30 01:29 2026-05-30 Show GitHub Exploit DB Packet Storm
3326 7.5 HIGH
Network
- - HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to delete arbitrary records by sending a crafted request that specifies the target rec… CWE-862
 Missing Authorization
CVE-2018-25391 2026-05-30 01:29 2026-05-30 Show GitHub Exploit DB Packet Storm
3327 7.1 HIGH
Network
- - MaxOn ERP Software 8.x-9.x contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries through the nomor, user, and jenis parameters in the log_activity f… CWE-89
SQL Injection
CVE-2018-25392 2026-05-30 01:29 2026-05-30 Show GitHub Exploit DB Packet Storm
3328 6.5 MEDIUM
Network
- - Navigate CMS 2.8.5 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by injecting directory traversal sequences in the id parameter. Attackers can se… CWE-22
Path Traversal
CVE-2018-25393 2026-05-30 01:29 2026-05-30 Show GitHub Exploit DB Packet Storm
3329 8.2 HIGH
Network
- - Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the release_id parameter of board… CWE-89
SQL Injection
CVE-2018-25394 2026-05-30 01:29 2026-05-30 Show GitHub Exploit DB Packet Storm
3330 8.2 HIGH
Network
- - Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the feature_id parameter of board… CWE-89
SQL Injection
CVE-2018-25395 2026-05-30 01:29 2026-05-30 Show GitHub Exploit DB Packet Storm