Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
219121 6 警告 Open-Xchange - Open-Xchange Server のサブスクリプション機能における任意のアウトバウンド TCP トラフィックを誘発される脆弱性 CWE-20
不適切な入力確認
CVE-2013-1648 2013-09-6 16:33 2013-03-13 Show GitHub Exploit DB Packet Storm
219122 5 警告 Open-Xchange - Open-Xchange Server における CRLF インジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2013-1647 2013-09-6 16:20 2013-03-13 Show GitHub Exploit DB Packet Storm
219123 4.3 警告 Open-Xchange - Open-Xchange Server におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-1646 2013-09-6 16:18 2013-03-13 Show GitHub Exploit DB Packet Storm
219124 4 警告 Open-Xchange - Open-Xchange Server におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2013-1645 2013-09-6 16:14 2013-03-13 Show GitHub Exploit DB Packet Storm
219125 3.5 注意 Open-Xchange - Open-Xchange App Suite および Server におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-5698 2013-09-6 16:11 2013-06-3 Show GitHub Exploit DB Packet Storm
219126 3.5 注意 Open-Xchange - Open-Xchange App Suite における他のユーザの電子メールの認証情報を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2013-4790 2013-09-6 16:03 2013-07-31 Show GitHub Exploit DB Packet Storm
219127 4.3 警告 Open-Xchange - Open-Xchange App Suite および Server におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-3106 2013-09-6 15:03 2013-06-3 Show GitHub Exploit DB Packet Storm
219128 4.3 警告 Open-Xchange - Open-Xchange App Suite および Server におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-2583 2013-09-6 14:54 2013-04-17 Show GitHub Exploit DB Packet Storm
219129 5 警告 Open-Xchange - Open-Xchange App Suite および Server のリダイレクトサーブレットにおける CRLF インジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2013-2582 2013-09-6 14:47 2013-04-17 Show GitHub Exploit DB Packet Storm
219130 5.8 警告 DELL EMC (旧 EMC Corporation) - EMC RSA Archer GRC におけるオープンリダイレクトの脆弱性 CWE-20
不適切な入力確認
CVE-2013-3277 2013-09-6 12:06 2013-09-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
278081 - orbicule undercover Orbicule Undercover allows attackers with physical or root access to disable the protection by using the chmod command to change the permissions of the /private/etc/uc.app/Contents/MacOS/uc file, whi… NVD-CWE-Other
CVE-2006-0640 2018-10-20 00:45 2006-02-10 Show GitHub Exploit DB Packet Storm
278082 - orbicule undercover Orbicule Undercover uses a third-party web server to determine the IP address through which the computer is accessing the Internet, but does not document this third-party disclosure, which leads to a… NVD-CWE-Other
CVE-2006-0641 2018-10-20 00:45 2006-02-10 Show GitHub Exploit DB Packet Storm
278083 - trend_micro interscan_messaging_security_suite
interscan_web_security_suite
serverprotect
Trend Micro ServerProtect 5.58, and possibly InterScan Messaging Security Suite and InterScan Web Security Suite, have a default configuration setting of "Do not scan compressed files when Extracted … NVD-CWE-Other
CVE-2006-0642 2018-10-20 00:45 2006-02-10 Show GitHub Exploit DB Packet Storm
278084 - wiredred e_pop_web_conferencing Cross-site scripting (XSS) vulnerability in WiredRed e/pop Web Conferencing 4.1.0.755 allows remote authenticated users to inject arbitrary web script or HTML via the topic name of a conference. NVD-CWE-Other
CVE-2006-0643 2018-10-20 00:45 2006-02-10 Show GitHub Exploit DB Packet Storm
278085 - cpg-nuke dragonfly_cms Multiple directory traversal vulnerabilities in install.php in CPG-Nuke Dragonfly CMS (aka CPG Dragonfly CMS) 9.0.6.1 allow remote attackers to include and execute arbitrary local files via directory… NVD-CWE-Other
CVE-2006-0644 2018-10-20 00:45 2006-02-10 Show GitHub Exploit DB Packet Storm
278086 - free_software_foundation_inc. libtasn1 Tiny ASN.1 Library (libtasn1) before 0.2.18, as used by (1) GnuTLS 1.2.x before 1.2.10 and 1.3.x before 1.3.4, and (2) GNU Shishi, allows attackers to crash the DER decoder and possibly execute arbit… NVD-CWE-Other
CVE-2006-0645 2018-10-20 00:45 2006-02-11 Show GitHub Exploit DB Packet Storm
278087 - php_icalendar php_icalendar Multiple directory traversal vulnerabilities in PHP iCalendar 2.0.1, 2.1, and 2.2 allow remote attackers to include arbitrary files via the (1) getdate and possibly other parameters used in the repla… NVD-CWE-Other
CVE-2006-0648 2018-10-20 00:45 2006-02-13 Show GitHub Exploit DB Packet Storm
278088 - cpaint cpaint Cross-site scripting (XSS) vulnerability in cpaint2.inc.php in the CPAINT library before 2.0.3, as used in multiple scripts, allows remote attackers to inject arbitrary web script or HTML via the cpa… NVD-CWE-Other
CVE-2006-0650 2018-10-20 00:45 2006-02-13 Show GitHub Exploit DB Packet Storm
278089 - hinton_design phpht_topsites Multiple SQL injection vulnerabilities in Hinton Design phpht Topsites 1.3 allow remote attackers to execute arbitrary SQL commands via multiple vectors including the username parameter. NVD-CWE-Other
CVE-2006-0653 2018-10-20 00:45 2006-02-13 Show GitHub Exploit DB Packet Storm
278090 - hinton_design phpht_topsites check.php in Hinton Design phpht Topsites 1.3 does not validate passwords when using cookies, which allows remote attackers to bypass authentication via unspecified cookies. NVD-CWE-Other
CVE-2006-0654 2018-10-20 00:45 2006-02-13 Show GitHub Exploit DB Packet Storm