Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227771 7.5 危険 web-scripts - Visual Events Calendar の calendar.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4060 2012-12-20 18:02 2006-08-9 Show GitHub Exploit DB Packet Storm
227772 7.5 危険 usolved - USOLVED NEWSolved Lite における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4059 2012-12-20 18:02 2006-08-9 Show GitHub Exploit DB Packet Storm
227773 6.8 警告 simplog - Simpliciti Locked Browser におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-4058 2012-12-20 18:02 2006-08-9 Show GitHub Exploit DB Packet Storm
227774 7.5 危険 the address book reloaded
the address book
- katzlbt Address Book などの認証プロセスにおける SQL インジェクションの脆弱性 - CVE-2006-4056 2012-12-20 18:02 2006-08-9 Show GitHub Exploit DB Packet Storm
227775 7.5 危険 tsep - Olaf Noehring TSEP における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4055 2012-12-20 18:02 2006-08-9 Show GitHub Exploit DB Packet Storm
227776 7.5 危険 turnkey web tools - Turnkey Web Tools PHP Simple Shop における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4052 2012-12-20 18:02 2006-08-9 Show GitHub Exploit DB Packet Storm
227777 7.5 危険 turnkey web tools - Turnkey Web Tools PHP Live Helper の global.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4051 2012-12-20 18:02 2006-08-9 Show GitHub Exploit DB Packet Storm
227778 2.1 注意 サン・マイクロシステムズ - Sun Ray Server Software のユーティリティ utxconfig における任意のファイルを上書きされる脆弱性 - CVE-2006-4049 2012-12-20 18:02 2006-07-7 Show GitHub Exploit DB Packet Storm
227779 7.5 危険 torbstoff - Torbstoff News の news.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4045 2012-12-20 18:02 2006-08-9 Show GitHub Exploit DB Packet Storm
227780 7.5 危険 pike - Pike における SQL インジェクションの脆弱性 - CVE-2006-4041 2012-12-20 18:02 2006-08-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 20, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
249591 - - - In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the packet_monitor function. - CVE-2024-51301 2024-11-1 21:57 2024-10-30 Show GitHub Exploit DB Packet Storm
249592 - - - In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_rrd function. - CVE-2024-51300 2024-11-1 21:57 2024-10-30 Show GitHub Exploit DB Packet Storm
249593 - - - In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the dumpSyslog function. - CVE-2024-51299 2024-11-1 21:57 2024-10-30 Show GitHub Exploit DB Packet Storm
249594 - - - In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doGRETunnel function. - CVE-2024-51298 2024-11-1 21:57 2024-10-30 Show GitHub Exploit DB Packet Storm
249595 - - - In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the pingtrace function. - CVE-2024-51296 2024-11-1 21:57 2024-10-30 Show GitHub Exploit DB Packet Storm
249596 - - - DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doCertificate function. - CVE-2024-51257 2024-11-1 21:57 2024-10-30 Show GitHub Exploit DB Packet Storm
249597 - - - In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ldap_search_dn function. - CVE-2024-51304 2024-11-1 21:57 2024-10-30 Show GitHub Exploit DB Packet Storm
249598 - - - In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridge connection, and that bridge connection has an incoming topic configured that … - CVE-2024-3935 2024-11-1 21:57 2024-10-30 Show GitHub Exploit DB Packet Storm
249599 - - - In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access whe… - CVE-2024-10525 2024-11-1 21:57 2024-10-30 Show GitHub Exploit DB Packet Storm
249600 - - - The Black Widgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.3.7 due to insufficient input sanitizati… CWE-79
Cross-site Scripting
CVE-2024-9388 2024-11-1 21:57 2024-10-30 Show GitHub Exploit DB Packet Storm