Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 31, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
233081 2.6 注意 siteatschool - S@S の starnet/editors/htmlarea/popups/images.php におけるディレクトリトラバーサルの脆弱性 - CVE-2006-4919 2012-12-20 18:02 2006-09-20 Show GitHub Exploit DB Packet Storm
233082 7.5 危険 simple discussion board - Simple Discussion Board における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4918 2012-12-20 18:02 2006-09-20 Show GitHub Exploit DB Packet Storm
233083 4.3 警告 pt news - PT News の search.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-4917 2012-12-20 18:02 2006-09-20 Show GitHub Exploit DB Packet Storm
233084 7.5 危険 Qualiteam Software Limited - Qualiteam X-Cart の cmpi.php における任意のプログラム変数を上書きされる脆弱性 - CVE-2006-4904 2012-12-20 18:02 2006-09-20 Show GitHub Exploit DB Packet Storm
233085 10 危険 シマンテック - Symantec Veritas NetBackup の NetBackup bpcd デーモンにおける任意のコマンドを実行される脆弱性 - CVE-2006-4902 2012-12-20 18:02 2006-12-13 Show GitHub Exploit DB Packet Storm
233086 7.5 危険 phpbb xs - phpBB XS の bb_usage_stats/includes/bb_usage_stats.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4893 2012-12-20 18:02 2006-09-19 Show GitHub Exploit DB Packet Storm
233087 7.5 危険 techno dreams - Techno Dreams FAQ Manager Package の faqview.asp における SQL インジェクションの脆弱性 - CVE-2006-4892 2012-12-20 18:02 2006-09-19 Show GitHub Exploit DB Packet Storm
233088 7.5 危険 techno dreams - Techno Dreams Articles & Papers Package の ArticlesTableview.asp における SQL インジェクションの脆弱性 - CVE-2006-4891 2012-12-20 18:02 2006-09-19 Show GitHub Exploit DB Packet Storm
233089 7.5 危険 unak - UNAK-CMS における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4890 2012-12-20 18:02 2006-09-19 Show GitHub Exploit DB Packet Storm
233090 5.1 警告 telekorn - Telekorn SL における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4889 2012-12-20 18:02 2006-09-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 1, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
292421 - lockon ec-cube Directory traversal vulnerability in the lfCheckFileName function in data/class/pages/LC_Page_ResizeImage.php in LOCKON EC-CUBE before 2.12.5 allows remote attackers to read arbitrary image files via… CWE-22
Path Traversal
CVE-2013-3650 2024-11-21 10:54 2013-07-1 Show GitHub Exploit DB Packet Storm
292422 - ds3 authentication_server ServerAdmin/ErrorViewer.jsp in DS3 Authentication Server allow remote attackers to inject arbitrary error-page text via the message parameter. CWE-20
 Improper Input Validation 
CVE-2013-4098 2024-11-21 10:54 2013-06-29 Show GitHub Exploit DB Packet Storm
292423 - ds3 authentication_server ServerAdmin/TestDRConnection.jsp in DS3 Authentication Server allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in a -REG-E-OPEN error … CWE-22
Path Traversal
CVE-2013-4097 2024-11-21 10:54 2013-06-29 Show GitHub Exploit DB Packet Storm
292424 - ds3 authentication_server ServerAdmin/TestTelnetConnection.jsp in DS3 Authentication Server allows remote authenticated users to execute arbitrary commands via shell metacharacters in the HOST_NAME field. CWE-20
 Improper Input Validation 
CVE-2013-4096 2024-11-21 10:54 2013-06-29 Show GitHub Exploit DB Packet Storm
292425 - imperva securesphere plain/actionsets.html in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated users to execute arbitrary commands via a task with a … CWE-20
 Improper Input Validation 
CVE-2013-4095 2024-11-21 10:54 2013-06-29 Show GitHub Exploit DB Packet Storm
292426 - imperva securesphere The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated users to upload executable files via the (1) priv… CWE-20
 Improper Input Validation 
CVE-2013-4094 2024-11-21 10:54 2013-06-29 Show GitHub Exploit DB Packet Storm
292427 - imperva securesphere The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote attackers to obtain sensitive information via (1) a direct request to dwr/call/plaincall/Asyn… CWE-22
Path Traversal
CVE-2013-4093 2024-11-21 10:54 2013-06-29 Show GitHub Exploit DB Packet Storm
292428 - imperva securesphere The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows context-dependent attackers to obtain sensitive information by leveraging the presence of (1) a sess… CWE-255
Credentials Management
CVE-2013-4092 2024-11-21 10:54 2013-06-29 Show GitHub Exploit DB Packet Storm
292429 - imperva securesphere The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 does not have an off autocomplete attribute for the password (aka j_password) field on the secsphLogin.jsp … CWE-255
Credentials Management
CVE-2013-4091 2024-11-21 10:54 2013-06-29 Show GitHub Exploit DB Packet Storm
292430 - kent-web clip-mail Cross-site scripting (XSS) vulnerability in KENT-WEB CLIP-MAIL before 3.4, when Internet Explorer 7 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via an unspecifi… CWE-79
Cross-site Scripting
CVE-2013-3649 2024-11-21 10:54 2013-06-29 Show GitHub Exploit DB Packet Storm