Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
216741 7.2 危険 マイクロソフト - Microsoft Windows XP および Windows Server 2003 のカーネルの NDProxy.sys における権限昇格の脆弱性 CWE-20
不適切な入力確認
CVE-2013-5065 2014-01-15 11:30 2013-11-27 Show GitHub Exploit DB Packet Storm
216742 9.3 危険 Graphviz - Graphviz の lib/cgraph/scan.l 内の yyerror 関数におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2014-0978 2014-01-15 10:41 2014-01-9 Show GitHub Exploit DB Packet Storm
216743 4.3 警告 シックス・アパート株式会社 - Movable Type の Rich Text Editor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-0977 2014-01-15 10:35 2013-11-15 Show GitHub Exploit DB Packet Storm
216744 7.8 危険 Conceptronic - Conceptronic C54APM アクセスポイントにおけるアクセス権を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2014-1408 2014-01-15 10:12 2014-01-7 Show GitHub Exploit DB Packet Storm
216745 4.3 警告 Conceptronic - Conceptronic C54APM アクセスポイントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-1407 2014-01-15 10:11 2014-01-7 Show GitHub Exploit DB Packet Storm
216746 4.3 警告 Conceptronic - Conceptronic C54APM アクセスポイントの goform/formWlSiteSurvey における CRLF インジェクションの脆弱性 CWE-20
不適切な入力確認
CVE-2014-1406 2014-01-15 10:09 2014-01-7 Show GitHub Exploit DB Packet Storm
216747 5.8 警告 Conceptronic - Conceptronic C54APM アクセスポイントにおけるオープンリダイレクトの脆弱性 CWE-20
不適切な入力確認
CVE-2014-1405 2014-01-15 10:08 2014-01-7 Show GitHub Exploit DB Packet Storm
216748 3.5 注意 MantisBT Group - MantisBT の account_sponsor_page.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-4460 2014-01-15 10:00 2013-10-19 Show GitHub Exploit DB Packet Storm
216749 6.4 警告 Jethro Carr - Amberdms Billing System におけるアクセス権を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-5291 2014-01-14 18:45 2010-03-8 Show GitHub Exploit DB Packet Storm
216750 1.9 注意 Jethro Carr - Amberdms Billing System における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2010-5292 2014-01-14 18:43 2010-03-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 20, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
279971 - invision_power_services invision_power_board SQL injection vulnerability in index.php, possibly during a showtopic operation, in Invision Power Board (IPB) 2.1.5 allows remote attackers to execute arbitrary SQL commands via the st parameter. NVD-CWE-Other
CVE-2006-1076 2018-10-19 01:30 2006-03-9 Show GitHub Exploit DB Packet Storm
279972 - evo-dev evoblog Multiple cross-site scripting (XSS) vulnerabilities in the commentary in Evo-Dev evoBlog allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter and (2) other unspeci… NVD-CWE-Other
CVE-2006-1077 2018-10-19 01:30 2006-03-9 Show GitHub Exploit DB Packet Storm
279973 - jonathan_beckett pluggedout_nexus SQL injection vulnerability in forgotten_password.php in Jonathan Beckett PluggedOut Nexus 0.1 allows remote attackers to execute arbitrary SQL commands via the email parameter. NVD-CWE-Other
CVE-2006-1081 2018-10-19 01:30 2006-03-9 Show GitHub Exploit DB Packet Storm
279974 - phparcadescript phparcadescript Multiple cross-site scripting (XSS) vulnerabilities in phpArcadeScript 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the gamename parameter in tellafriend.php,… NVD-CWE-Other
CVE-2006-1082 2018-10-19 01:30 2006-03-9 Show GitHub Exploit DB Packet Storm
279975 - php-stats php-stats Multiple directory traversal vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to read and possibly execute arbitrary files via a .. (dot dot) in the (1) option[language] and (2… NVD-CWE-Other
CVE-2006-1083 2018-10-19 01:30 2006-03-9 Show GitHub Exploit DB Packet Storm
279976 - php-stats php-stats Multiple SQL injection vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the option[prefix] parameter in admin.php and other unspecifie… NVD-CWE-Other
CVE-2006-1084 2018-10-19 01:30 2006-03-9 Show GitHub Exploit DB Packet Storm
279977 - php-stats php-stats admin.php in PHP-Stats 0.1.9.1 and earlier allows remote attackers to bypass authentication, gain administrator privileges, and execute arbitrary PHP code by modifying the option[admin_pass] paramete… NVD-CWE-Other
CVE-2006-1085 2018-10-19 01:30 2006-03-9 Show GitHub Exploit DB Packet Storm
279978 - php-stats php-stats Direct static code injection vulnerability in the modify_config action in admin.php for PHP-Stats 0.1.9.1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the … NVD-CWE-Other
CVE-2006-1087 2018-10-19 01:30 2006-03-9 Show GitHub Exploit DB Packet Storm
279979 - php-stats php-stats PHP-Stats 0.1.9.1 and earlier allows remote attackers to obtain potentially sensitive information via a direct request to checktables.php, which lists the database table_prefix. NVD-CWE-Other
CVE-2006-1088 2018-10-19 01:30 2006-03-9 Show GitHub Exploit DB Packet Storm
279980 - sauerbraten cube
sauerbraten
Buffer overflow in the sgetstr function in shared/cube.h in Sauerbraten 2006_02_28 and earlier, as derived from the Cube engine, allows remote attackers to execute arbitrary code via long streams of … NVD-CWE-Other
CVE-2006-1100 2018-10-19 01:30 2006-03-9 Show GitHub Exploit DB Packet Storm