Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
216071 2.6 注意 phpMyFAQ - phpMyFAQ におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-0813 2014-02-20 13:57 2014-02-7 Show GitHub Exploit DB Packet Storm
216072 4.3 警告 デル - DELL SonicWALL GMS/Analyzer/UMA にクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-0332 2014-02-20 13:55 2014-02-11 Show GitHub Exploit DB Packet Storm
216073 4.3 警告 Mozilla Foundation - Mozilla Thunderbird および SeaMonkey におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2018 2014-02-19 19:08 2014-02-6 Show GitHub Exploit DB Packet Storm
216074 6.8 警告 Mozilla Foundation - Mozilla Firefox における永続的なログアウトに関するクロスサイトリクエストフォージェリに相当する攻撃を実行される脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-6167 2014-02-19 19:08 2013-04-4 Show GitHub Exploit DB Packet Storm
216075 4.3 警告 Canonical - Ubuntu Metal as a Service の API におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-1070 2014-02-19 18:55 2013-11-14 Show GitHub Exploit DB Packet Storm
216076 2.1 注意 Canonical - Ubuntu Metal as a Service における RabbitMQ 認証資格情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1069 2014-02-19 18:55 2013-11-22 Show GitHub Exploit DB Packet Storm
216077 7.5 危険 Csound - Csound におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-0270 2014-02-19 18:54 2012-04-5 Show GitHub Exploit DB Packet Storm
216078 5 警告 Litech Systems Design - router advertisement daemon の process_rs 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2011-3605 2014-02-19 18:54 2011-10-6 Show GitHub Exploit DB Packet Storm
216079 7.5 危険 Litech Systems Design - router advertisement daemon の process_ra 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2011-3604 2014-02-19 18:53 2011-10-6 Show GitHub Exploit DB Packet Storm
216080 7.5 危険 Litech Systems Design - router advertisement daemon の process_ra 関数におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-3601 2014-02-19 18:53 2011-10-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 26, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
280081 - photocycle photocycle Cross-site scripting (XSS) vulnerability in photocycle in Photocycle 1.0 allows remote attackers to inject arbitrary web script or HTML via the phpage parameter. NVD-CWE-Other
CVE-2006-3680 2018-10-19 01:48 2006-07-21 Show GitHub Exploit DB Packet Storm
280082 - flipper_poll flipper_poll PHP remote file inclusion vulnerability in poll.php in Flipper Poll 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. NVD-CWE-Other
CVE-2006-3683 2018-10-19 01:48 2006-07-21 Show GitHub Exploit DB Packet Storm
280083 - softcomplex php_event_calendar PHP remote file inclusion vulnerability in calendar.php in SoftComplex PHP Event Calendar 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_calendar parameter, which … NVD-CWE-Other
CVE-2006-3684 2018-10-19 01:48 2006-07-21 Show GitHub Exploit DB Packet Storm
280084 - francisco_charrua photo-gallery SQL injection vulnerability in Room.php in Francisco Charrua Photo-Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. CWE-89
SQL Injection
CVE-2006-3688 2018-10-19 01:48 2006-07-21 Show GitHub Exploit DB Packet Storm
280085 - minibb forum Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) components/com… NVD-CWE-Other
CVE-2006-3690 2018-10-19 01:48 2006-07-21 Show GitHub Exploit DB Packet Storm
280086 - vbzoom vbzoom Multiple SQL injection vulnerabilities in VBZooM 1.11 and earlier allow remote attackers to execute arbitrary SQL commands via the UserID parameter to (1) ignore-pm.php, (2) sendmail.php, (3) reply.p… NVD-CWE-Other
CVE-2006-3691 2018-10-19 01:48 2006-07-21 Show GitHub Exploit DB Packet Storm
280087 - rocks_clusters rocks_clusters Rocks Clusters 4.1 and earlier allows local users to gain privileges via commands enclosed with escaped backticks (\`) in an argument to the (1) mount-loop (mount-loop.c) or (2) umount-loop (umount-l… NVD-CWE-Other
CVE-2006-3693 2018-10-19 01:48 2006-07-21 Show GitHub Exploit DB Packet Storm
280088 - agnitum
lavasoft
novell
outpost_firewall
lavasoft_personal_firewall
client_firewall
Agnitum Outpost Firewall Pro 3.51.759.6511 (462), as used in (1) Lavasoft Personal Firewall 1.0.543.5722 (433) and (2) Novell BorderManager Novell Client Firewall 2.0, does not properly restrict user… CWE-264
Permissions, Privileges, and Access Controls
CVE-2006-3697 2018-10-19 01:48 2006-07-21 Show GitHub Exploit DB Packet Storm
280089 - oracle database_server Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5 and 9.2.0.6 has unknown impact and attack vectors, aka Oracle Vuln# DB02. NVD-CWE-noinfo
CVE-2006-3699 2018-10-19 01:48 2006-07-21 Show GitHub Exploit DB Packet Storm
280090 - newsphp newsphp Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) cat_id, and (4) tim p… NVD-CWE-Other
CVE-2006-3358 2018-10-19 01:47 2006-07-7 Show GitHub Exploit DB Packet Storm