Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 5, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
231421 7.5 危険 Trivantis Corporation Inc. - Trivantis CourseMill Enterprise Learning Management System の userlogin.jsp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6338 2012-12-20 18:34 2007-12-14 Show GitHub Exploit DB Packet Storm
231422 5 警告 sergey lyubka - Windows 上で稼動する Sergey Lyubka Simple HTTPD におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2007-6326 2012-12-20 18:34 2007-12-13 Show GitHub Exploit DB Packet Storm
231423 5 警告 xml2owl - xml2owl の filedownload.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-6322 2012-12-20 18:34 2007-12-13 Show GitHub Exploit DB Packet Storm
231424 4.3 警告 Roundcube.net - RoundCube webmail におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6321 2012-12-20 18:34 2007-12-11 Show GitHub Exploit DB Packet Storm
231425 6.8 警告 WordPress.org - WordPress の wp-includes/query.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6318 2012-12-20 18:34 2007-12-11 Show GitHub Exploit DB Packet Storm
231426 5.5 警告 Real Time Logic - BarracudaDrive Web Server におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-6317 2012-12-20 18:34 2007-12-11 Show GitHub Exploit DB Packet Storm
231427 4.3 警告 Real Time Logic - BarracudaDrive Web Server におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6316 2012-12-20 18:34 2007-12-11 Show GitHub Exploit DB Packet Storm
231428 4 警告 Real Time Logic - Group Chat の BarracudaDrive Web Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2007-6315 2012-12-20 18:34 2007-12-11 Show GitHub Exploit DB Packet Storm
231429 5 警告 Real Time Logic - BarracudaDrive Web Server における Web スクリプトに対するソースコードを読まれる脆弱性 CWE-20
不適切な入力確認
CVE-2007-6314 2012-12-20 18:34 2007-12-11 Show GitHub Exploit DB Packet Storm
231430 4.3 警告 ウェブセンス - Websense Enterprise および Web Security Suite の Web Reporting Tools portal におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6312 2012-12-20 18:34 2007-12-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 5, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
297511 - moodle moodle The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute files via a modified Portfolio API callback. CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-5479 2024-11-21 10:44 2012-11-21 Show GitHub Exploit DB Packet Storm
297512 - moodle moodle The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different group's users via an ad… CWE-200
Information Exposure
CVE-2012-5473 2024-11-21 10:44 2012-11-21 Show GitHub Exploit DB Packet Storm
297513 - moodle moodle lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field. CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-5472 2024-11-21 10:44 2012-11-21 Show GitHub Exploit DB Packet Storm
297514 - moodle moodle The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to access the Dropbox of a different user by leveraging a… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-5471 2024-11-21 10:44 2012-11-21 Show GitHub Exploit DB Packet Storm
297515 - firebirdsql firebird TraceManager in Firebird 2.5.0 and 2.5.1, when trace is enabled, allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) by preparing an empty dynamic SQL … CWE-399
 Resource Management Errors
CVE-2012-5529 2024-11-21 10:44 2012-11-20 Show GitHub Exploit DB Packet Storm
297516 - apple cups CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local use… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-5519 2024-11-21 10:44 2012-11-20 Show GitHub Exploit DB Packet Storm
297517 - asial monaca_debugger The Asial Monaca Debugger application before 1.4.2 for Android allows remote attackers to obtain sensitive (1) account or (2) session ID information in a system log file via a crafted application. CWE-200
Information Exposure
CVE-2012-5172 2024-11-21 10:44 2012-11-17 Show GitHub Exploit DB Packet Storm
297518 - mantisbt mantisbt core/email_api.php in MantisBT before 1.2.12 does not properly manage the sending of e-mail notifications about restricted bugs, which might allow remote authenticated users to obtain sensitive infor… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-5523 2024-11-21 10:44 2012-11-16 Show GitHub Exploit DB Packet Storm
297519 - mantisbt mantisbt MantisBT before 1.2.12 does not use an expected default value during decisions about whether a user may modify the status of a bug, which allows remote authenticated users to bypass intended access r… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-5522 2024-11-21 10:44 2012-11-16 Show GitHub Exploit DB Packet Storm
297520 - vmware player
workstation
Untrusted search path vulnerability in VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows allows host OS users to gain host OS privileges via a Trojan horse DLL in a "s… NVD-CWE-Other
CVE-2012-5459 2024-11-21 10:44 2012-11-14 Show GitHub Exploit DB Packet Storm