Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
217521 9.3 危険 アップル - Apple QuickTime における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2012-0671 2013-12-2 18:28 2012-05-16 Show GitHub Exploit DB Packet Storm
217522 9.3 危険 アップル - Apple QuickTime における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2012-0670 2013-12-2 18:12 2012-05-16 Show GitHub Exploit DB Packet Storm
217523 5.8 警告 The PHP Group
アップル
- PHP のファイルアップロードの実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2012-1172 2013-12-2 17:58 2012-03-1 Show GitHub Exploit DB Packet Storm
217524 9.3 危険 FFmpeg - FFmpeg の libavcodec/h264.c の field_end 関数における脆弱性 CWE-119
バッファエラー
CVE-2013-0869 2013-12-2 17:41 2013-02-6 Show GitHub Exploit DB Packet Storm
217525 9.3 危険 アップル - Apple QuickTime におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-0668 2013-12-2 17:37 2012-05-16 Show GitHub Exploit DB Packet Storm
217526 6.8 警告 The PHP Group
アップル
- PHP における SQL インジェクション攻撃を行われる脆弱性 CWE-20
不適切な入力確認
CVE-2012-0831 2013-12-2 16:47 2012-02-10 Show GitHub Exploit DB Packet Storm
217527 5 警告 シスコシステムズ - Cisco IOS XR の SNMP モジュールにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-6700 2013-12-2 16:26 2013-11-27 Show GitHub Exploit DB Packet Storm
217528 7.5 危険 ヒューレット・パッカード - HP Service Manager および ServiceCenter における任意のコードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2013-4844 2013-12-2 16:08 2013-11-26 Show GitHub Exploit DB Packet Storm
217529 3.5 注意 IBM - IBM Sterling Selling and Fulfillment Suite の Sterling Order Management におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-6322 2013-12-2 16:06 2013-11-22 Show GitHub Exploit DB Packet Storm
217530 7.5 危険 CiviCRM - CiviCRM の CRM/Core/Page/AJAX/Location.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-5957 2013-12-2 16:04 2012-10-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 25, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
279261 - mybulletinboard mybulletinboard Cross-site scripting (XSS) vulnerability in search.php in MyBB (aka MyBulletinBoard) 1.0.2 allows remote attackers with knowledge of the table prefix to inject arbitrary web script or HTML via a URL … NVD-CWE-Other
CVE-2006-0639 2018-10-20 00:45 2006-02-10 Show GitHub Exploit DB Packet Storm
279262 - orbicule undercover Orbicule Undercover allows attackers with physical or root access to disable the protection by using the chmod command to change the permissions of the /private/etc/uc.app/Contents/MacOS/uc file, whi… NVD-CWE-Other
CVE-2006-0640 2018-10-20 00:45 2006-02-10 Show GitHub Exploit DB Packet Storm
279263 - orbicule undercover Orbicule Undercover uses a third-party web server to determine the IP address through which the computer is accessing the Internet, but does not document this third-party disclosure, which leads to a… NVD-CWE-Other
CVE-2006-0641 2018-10-20 00:45 2006-02-10 Show GitHub Exploit DB Packet Storm
279264 - trend_micro interscan_messaging_security_suite
interscan_web_security_suite
serverprotect
Trend Micro ServerProtect 5.58, and possibly InterScan Messaging Security Suite and InterScan Web Security Suite, have a default configuration setting of "Do not scan compressed files when Extracted … NVD-CWE-Other
CVE-2006-0642 2018-10-20 00:45 2006-02-10 Show GitHub Exploit DB Packet Storm
279265 - wiredred e_pop_web_conferencing Cross-site scripting (XSS) vulnerability in WiredRed e/pop Web Conferencing 4.1.0.755 allows remote authenticated users to inject arbitrary web script or HTML via the topic name of a conference. NVD-CWE-Other
CVE-2006-0643 2018-10-20 00:45 2006-02-10 Show GitHub Exploit DB Packet Storm
279266 - cpg-nuke dragonfly_cms Multiple directory traversal vulnerabilities in install.php in CPG-Nuke Dragonfly CMS (aka CPG Dragonfly CMS) 9.0.6.1 allow remote attackers to include and execute arbitrary local files via directory… NVD-CWE-Other
CVE-2006-0644 2018-10-20 00:45 2006-02-10 Show GitHub Exploit DB Packet Storm
279267 - free_software_foundation_inc. libtasn1 Tiny ASN.1 Library (libtasn1) before 0.2.18, as used by (1) GnuTLS 1.2.x before 1.2.10 and 1.3.x before 1.3.4, and (2) GNU Shishi, allows attackers to crash the DER decoder and possibly execute arbit… NVD-CWE-Other
CVE-2006-0645 2018-10-20 00:45 2006-02-11 Show GitHub Exploit DB Packet Storm
279268 - php_icalendar php_icalendar Multiple directory traversal vulnerabilities in PHP iCalendar 2.0.1, 2.1, and 2.2 allow remote attackers to include arbitrary files via the (1) getdate and possibly other parameters used in the repla… NVD-CWE-Other
CVE-2006-0648 2018-10-20 00:45 2006-02-13 Show GitHub Exploit DB Packet Storm
279269 - cpaint cpaint Cross-site scripting (XSS) vulnerability in cpaint2.inc.php in the CPAINT library before 2.0.3, as used in multiple scripts, allows remote attackers to inject arbitrary web script or HTML via the cpa… NVD-CWE-Other
CVE-2006-0650 2018-10-20 00:45 2006-02-13 Show GitHub Exploit DB Packet Storm
279270 - hinton_design phpht_topsites Multiple SQL injection vulnerabilities in Hinton Design phpht Topsites 1.3 allow remote attackers to execute arbitrary SQL commands via multiple vectors including the username parameter. NVD-CWE-Other
CVE-2006-0653 2018-10-20 00:45 2006-02-13 Show GitHub Exploit DB Packet Storm