Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229301 6.8 警告 GLPI-PROJECT.ORG - GLPI-PROJECT GLPI におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-4002 2012-10-12 15:45 2012-06-28 Show GitHub Exploit DB Packet Storm
229302 5 警告 OpenTTD - OpenTTD におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2012-3436 2012-10-12 15:23 2012-07-27 Show GitHub Exploit DB Packet Storm
229303 6 警告 Pay With Tweet - WordPress 用 Pay With Tweet プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-5350 2012-10-12 15:21 2012-10-9 Show GitHub Exploit DB Packet Storm
229304 2.6 注意 Pay With Tweet - WordPress 用 Pay With Tweet プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-5349 2012-10-12 15:20 2012-10-9 Show GitHub Exploit DB Packet Storm
229305 6.8 警告 Steven Wilson - MangosWeb Enhanced における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-5348 2012-10-12 15:18 2012-10-9 Show GitHub Exploit DB Packet Storm
229306 7.5 危険 TinyWebGallery - TinyWebGallery における任意のコードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2012-5347 2012-10-12 15:18 2012-10-9 Show GitHub Exploit DB Packet Storm
229307 4.3 警告 Bence Meszaros - WordPress 用 WP Live.php モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-5346 2012-10-12 15:11 2012-10-9 Show GitHub Exploit DB Packet Storm
229308 5 警告 Kepler Lam - IPtools の Remote command server におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-5345 2012-10-12 15:06 2012-10-9 Show GitHub Exploit DB Packet Storm
229309 5 警告 Kepler Lam - IPtools の WebServer におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2012-5344 2012-10-12 15:03 2012-10-9 Show GitHub Exploit DB Packet Storm
229310 4.3 警告 Limny - Limny の admin/login.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-5343 2012-10-12 15:01 2012-10-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 25, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
285431 - virtual_hosting_control_system virtual_hosting_control_system Session fixation vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. CWE-287
Improper Authentication
CVE-2007-3988 2018-10-16 06:32 2007-07-26 Show GitHub Exploit DB Packet Storm
285432 - cpanel cpanel Cross-site scripting (XSS) vulnerability in frontend/x/htaccess/changepro.html in cPanel 10.9.1 allows remote attackers to inject arbitrary web script or HTML via the resname parameter. NVD-CWE-Other
CVE-2007-4022 2018-10-16 06:32 2007-07-27 Show GitHub Exploit DB Packet Storm
285433 - areca cli Buffer overflow in cli32 in Areca CLI 1.72.250 and earlier might allow local users to gain privileges via a long argument. NOTE: this program is not setuid by default, but there are some usage scena… NVD-CWE-Other
CVE-2007-4027 2018-10-16 06:32 2007-07-27 Show GitHub Exploit DB Packet Storm
285434 - webspell webspell Absolute path traversal vulnerability in index.php in Webspell 4.01.02 allows remote attackers to include and execute arbitrary local files via a full pathname in the site parameter. NOTE: some of t… NVD-CWE-Other
CVE-2007-4028 2018-10-16 06:32 2007-07-27 Show GitHub Exploit DB Packet Storm
285435 - webspell webspell Vendor has supplied a patch for this vulnerability: http://cms.webspell.org/index.php?site=files&cat=10 NVD-CWE-Other
CVE-2007-4028 2018-10-16 06:32 2007-07-27 Show GitHub Exploit DB Packet Storm
285436 - libvorbis libvorbis libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service via (1) an invalid mapping type, which triggers an out-of-bounds read in the… NVD-CWE-Other
CVE-2007-4029 2018-10-16 06:32 2007-07-27 Show GitHub Exploit DB Packet Storm
285437 - libvorbis libvorbis Vendor has issued upgrade for this vulnerability: https://issues.rpath.com/browse/RPL-1590 NVD-CWE-Other
CVE-2007-4029 2018-10-16 06:32 2007-07-27 Show GitHub Exploit DB Packet Storm
285438 - php
t1lib
php
t1lib
Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary code via a long FileName parameter. NOTE: this is… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-4033 2018-10-16 06:32 2007-07-28 Show GitHub Exploit DB Packet Storm
285439 - sitescape sitescape_forum Multiple cross-site scripting (XSS) vulnerabilities in SiteScape Forum before 7.3 allow remote attackers to inject arbitrary web script or HTML via the user name field in the login procedure, and oth… NVD-CWE-Other
CVE-2007-3807 2018-10-16 06:31 2007-07-17 Show GitHub Exploit DB Packet Storm
285440 - mkportal mkportal Multiple SQL injection vulnerabilities in MKPortal 1.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the idurlo field in the delete_urlo function in (a) index.php in the urlobox … NVD-CWE-Other
CVE-2007-3814 2018-10-16 06:31 2007-07-17 Show GitHub Exploit DB Packet Storm