Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230491 4.3 警告 Patrick Przybilla - Drupal の AddToAny におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4043 2012-09-25 17:38 2009-11-11 Show GitHub Exploit DB Packet Storm
230492 4.3 警告 marek sotak - Drupal 用の RootCandy theme におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4042 2012-09-25 17:38 2009-11-11 Show GitHub Exploit DB Packet Storm
230493 4.3 警告 NCH - NCH Software Axon Virtual PBX におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4038 2012-09-25 17:38 2009-11-20 Show GitHub Exploit DB Packet Storm
230494 7.8 危険 Linux - Linux kernel の mac80211 サブシステムにおけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2009-4026 2012-09-25 17:38 2009-11-22 Show GitHub Exploit DB Packet Storm
230495 10 危険 PEAR - PEAR の Net_Traceroute パッケージにおける任意のシェルコマンドを実行される脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2009-4025 2012-09-25 17:38 2009-11-14 Show GitHub Exploit DB Packet Storm
230496 10 危険 PEAR - PEAR の Net_Ping パッケージにおける任意のシェルコマンドを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2009-4024 2012-09-25 17:38 2009-11-14 Show GitHub Exploit DB Packet Storm
230497 7.5 危険 PEAR - PEAR の Mail パッケージにおける任意のファイルを読まれる脆弱性 CWE-94
コード・インジェクション
CVE-2009-4023 2012-09-25 17:38 2009-05-7 Show GitHub Exploit DB Packet Storm
230498 5 警告 OpenTTD - OpenTTD の src/train_cmd.cpp の NormaliseTrainConsist 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2009-4007 2012-09-25 17:38 2009-12-11 Show GitHub Exploit DB Packet Storm
230499 7.2 危険 Linux - Linux kernel の KVM サブシステムにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-4004 2012-09-25 17:38 2009-10-23 Show GitHub Exploit DB Packet Storm
230500 4.3 警告 Mozilla Foundation - Bugzilla における重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-3989 2012-09-25 17:38 2010-01-31 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 26, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
285541 - mysql community_server MySQL Community Server before 5.0.45 allows remote attackers to cause a denial of service (daemon crash) via a malformed password packet in the connection protocol. NVD-CWE-noinfo
CWE-20
 Improper Input Validation 
CVE-2007-3780 2018-10-16 06:30 2007-07-16 Show GitHub Exploit DB Packet Storm
285542 - mysql community_server MySQL Community Server before 5.0.45 does not require privileges such as SELECT for the source table in a CREATE TABLE LIKE statement, which allows remote authenticated users to obtain sensitive info… NVD-CWE-Other
CVE-2007-3781 2018-10-16 06:30 2007-07-16 Show GitHub Exploit DB Packet Storm
285543 - mysql community_server MySQL Community Server before 5.0.45 allows remote authenticated users to gain update privileges for a table in another database via a view that refers to this external table. CWE-264
Permissions, Privileges, and Access Controls
CVE-2007-3782 2018-10-16 06:30 2007-07-16 Show GitHub Exploit DB Packet Storm
285544 - envivosoft envivo_cms SQL injection vulnerability in default.asp in enVivo!CMS allows remote attackers to execute arbitrary SQL commands via the ID parameter in an article action. NOTE: this is probably different from CV… NVD-CWE-Other
CVE-2007-3783 2018-10-16 06:30 2007-07-16 Show GitHub Exploit DB Packet Storm
285545 - esoft instagate_ex2_utm The eSoft InstaGate EX2 UTM device does not require entry of the old password when changing the admin password, which might allow remote attackers to gain privileges by conducting a CSRF attack, maki… NVD-CWE-Other
CVE-2007-3787 2018-10-16 06:30 2007-07-16 Show GitHub Exploit DB Packet Storm
285546 - esoft instagate_ex2_utm The eSoft InstaGate EX2 UTM device stores the admin password within the settings HTML document, which might allow context-dependent attackers to obtain sensitive information by reading this document. NVD-CWE-Other
CVE-2007-3788 2018-10-16 06:30 2007-07-16 Show GitHub Exploit DB Packet Storm
285547 - azerbaijan_development_group azdgdating Multiple PHP remote file inclusion vulnerabilities in AzDG Dating Gold 3.0.5 allow remote attackers to execute arbitrary PHP code via a URL in the int_path parameter to (1) header.php, (2) footer.php… NVD-CWE-Other
CVE-2007-3792 2018-10-16 06:30 2007-07-16 Show GitHub Exploit DB Packet Storm
285548 - sun jdk
jre
sdk
Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 5.0 Update 11 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, for Windows allows … CWE-22
Path Traversal
CVE-2007-3504 2018-10-16 06:29 2007-06-30 Show GitHub Exploit DB Packet Storm
285549 - flac123 flac123 Stack-based buffer overflow in the local__vcentry_parse_value function in vorbiscomment.c in flac123 (aka flac-tools or flac) before 0.0.10 allows user-assisted remote attackers to execute arbitrary … NVD-CWE-Other
CVE-2007-3507 2018-10-16 06:29 2007-07-3 Show GitHub Exploit DB Packet Storm
285550 - phpdirector phpdirector videos.php in PHPDirector 0.21 and earlier allows remote attackers to obtain sensitive information via an empty value of the id[] parameter, which reveals the path in an error message. NVD-CWE-Other
CVE-2007-3529 2018-10-16 06:29 2007-07-4 Show GitHub Exploit DB Packet Storm