Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
231501 3.3 注意 sony ericsson - Sony Ericsson K700i および W810i 電話機におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2007-0521 2012-12-20 18:19 2007-01-25 Show GitHub Exploit DB Packet Storm
231502 7.5 危険 unique ads - UDS の banner.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-0520 2012-12-20 18:19 2007-01-25 Show GitHub Exploit DB Packet Storm
231503 3.5 注意 xmb software - XMB U2U Instant Messenger の memcp.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-0519 2012-12-20 18:19 2007-01-25 Show GitHub Exploit DB Packet Storm
231504 7.5 危険 Scriptsez.net - Scriptsez Smart PHP Subscriber におけるエンコードされたパスワードを取得される脆弱性 - CVE-2007-0518 2012-12-20 18:19 2007-01-25 Show GitHub Exploit DB Packet Storm
231505 7.5 危険 Scriptsez.net - Scriptsez Random PHP Quote におけるパスワード情報を取得される脆弱性 - CVE-2007-0517 2012-12-20 18:19 2007-01-25 Show GitHub Exploit DB Packet Storm
231506 4.9 警告 yana framework - Yana Framework における任意のゲストブックプロファイルを変更される脆弱性 CWE-noinfo
情報不足
CVE-2007-0516 2012-12-20 18:19 2007-01-25 Show GitHub Exploit DB Packet Storm
231507 6.8 警告 phpxmldom - phpXD における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-0511 2012-12-20 18:19 2007-01-25 Show GitHub Exploit DB Packet Storm
231508 10 危険 vote pro - Vote! Pro の poll_frame.php における任意の PHP コードを実行される脆弱性 - CVE-2007-0504 2012-12-20 18:19 2007-01-25 Show GitHub Exploit DB Packet Storm
231509 7.5 危険 webSPELL - webSPELL の gallery.php における SQL インジェクションの脆弱性 - CVE-2007-0502 2012-12-20 18:19 2007-01-25 Show GitHub Exploit DB Packet Storm
231510 6.8 警告 sangwan kim - Sangwan Kim phpIndexPage の config.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-0499 2012-12-20 18:19 2007-01-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 20, 2026, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
293991 - mystorexpress tienda_virtual SQL injection vulnerability in art_detalle.php in MyStore Xpress Tienda Virtual allows remote attackers to execute arbitrary SQL commands via the id parameter. CWE-89
SQL Injection
CVE-2012-5294 2024-11-21 10:44 2012-10-5 Show GitHub Exploit DB Packet Storm
293992 - redgraphic sapid_cms Multiple PHP remote file inclusion vulnerabilities in SAPID CMS 1.2.3 Stable allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[root_path] parameter to usr/extensions/g… CWE-94
Code Injection
CVE-2012-5293 2024-11-21 10:44 2012-10-5 Show GitHub Exploit DB Packet Storm
293993 - atar2b atar2b_cms Multiple SQL injection vulnerabilities in Atar2b CMS 4.0.1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) gallery_e.php, (2) pageE.php, or (3) pageH.php. CWE-89
SQL Injection
CVE-2012-5292 2024-11-21 10:44 2012-10-5 Show GitHub Exploit DB Packet Storm
293994 - possesports posse_softball_director_cms SQL injection vulnerability in team.php in Posse Softball Director CMS allows remote attackers to execute arbitrary SQL commands via the idteam parameter. CWE-89
SQL Injection
CVE-2012-5291 2024-11-21 10:44 2012-10-5 Show GitHub Exploit DB Packet Storm
293995 - wcs4web easywebrealestate Multiple SQL injection vulnerabilities in EasyWebRealEstate allow remote attackers to execute arbitrary SQL commands via the (1) lstid parameter to listings.php or (2) infoid parameter to index.php. CWE-89
SQL Injection
CVE-2012-5290 2024-11-21 10:44 2012-10-5 Show GitHub Exploit DB Packet Storm
293996 - plogger plogger Multiple SQL injection vulnerabilities in Plogger 1.0 RC1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) index.php or (2) gallery.php. CWE-89
SQL Injection
CVE-2012-5289 2024-11-21 10:44 2012-10-5 Show GitHub Exploit DB Packet Storm
293997 - accomplishtechnology phpmydirectory SQL injection vulnerability in page.php in phpMyDirectory 1.3.3 allows remote attackers to execute arbitrary SQL commands via the id parameter. CWE-89
SQL Injection
CVE-2012-5288 2024-11-21 10:44 2012-10-5 Show GitHub Exploit DB Packet Storm
293998 - ocportal ocportal Open redirect vulnerability in index.php in ocPortal before 7.1.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter. CWE-20
 Improper Input Validation 
CVE-2012-5234 2024-11-21 10:44 2012-10-2 Show GitHub Exploit DB Packet Storm
293999 - luke_herrington stickynote Cross-site scripting (XSS) vulnerability in the stickynote module before 7.x-1.1 for Drupal allows remote authenticated users with edit stickynotes privileges to inject arbitrary web script or HTML v… CWE-79
Cross-site Scripting
CVE-2012-5233 2024-11-21 10:44 2012-10-2 Show GitHub Exploit DB Packet Storm
294000 - mediafire mod_quick_form Cross-site scripting (XSS) vulnerability in the Quickl Form component for Joomla! allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2012-5232 2024-11-21 10:44 2012-10-2 Show GitHub Exploit DB Packet Storm