Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
233221 5 警告 schoolalumni portal - SchoolAlumni Portal の mod.php におけるディレクトリトラバーサルの脆弱性 - CVE-2006-5528 2012-12-20 18:02 2006-10-26 Show GitHub Exploit DB Packet Storm
233222 5.1 警告 PHPNUKE - PHP-Nuke の mainfile.php における SQL インジェクション攻撃を実行される脆弱性 - CVE-2006-5525 2012-12-20 18:02 2006-10-26 Show GitHub Exploit DB Packet Storm
233223 6.8 警告 phpList - phplist の index.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-5524 2012-12-20 18:02 2006-10-26 Show GitHub Exploit DB Packet Storm
233224 7.5 危険 rhode island secretary of state - Rhode Island OMFA における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-5517 2012-12-20 18:02 2006-10-26 Show GitHub Exploit DB Packet Storm
233225 4.3 警告 wikini - WikiNi の actions/usersettings.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-5516 2012-12-20 18:02 2006-10-26 Show GitHub Exploit DB Packet Storm
233226 7.5 危険 web group communication center - WGCC の quiz.php における SQL インジェクションの脆弱性 - CVE-2006-5514 2012-12-20 18:02 2006-10-26 Show GitHub Exploit DB Packet Storm
233227 4.3 警告 zwahlen informatik - Zwahlen Online Shop の article.htm におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-5512 2012-12-20 18:02 2006-10-25 Show GitHub Exploit DB Packet Storm
233228 7.5 危険 woltlab - WoltLab Burning Book の addentry.php における任意の PHP コードを実行される脆弱性 - CVE-2006-5509 2012-12-20 18:02 2006-10-25 Show GitHub Exploit DB Packet Storm
233229 7.5 危険 woltlab - WoltLab Burning Book の addentry.php における SQL インジェクションの脆弱性 - CVE-2006-5508 2012-12-20 18:02 2006-10-25 Show GitHub Exploit DB Packet Storm
233230 7.5 危険 wiclear - WiClear における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-5506 2012-12-20 18:02 2006-10-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 5, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
292421 - elemata elemata_cms SQL injection vulnerability in functions/global.php in Elemata CMS RC 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. CWE-89
SQL Injection
CVE-2013-4952 2024-11-21 10:56 2013-07-30 Show GitHub Exploit DB Packet Storm
292422 - mintboard mintboard Multiple cross-site scripting (XSS) vulnerabilities in Mintboard 0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) pass parameter in views/login.php or (3) nam… CWE-79
Cross-site Scripting
CVE-2013-4951 2024-11-21 10:56 2013-07-30 Show GitHub Exploit DB Packet Storm
292423 - machform machform Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web script or HTML via the element_2 parameter. CWE-79
Cross-site Scripting
CVE-2013-4950 2024-11-21 10:56 2013-07-30 Show GitHub Exploit DB Packet Storm
292424 - machform machform Unrestricted file upload vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in t… NVD-CWE-Other
CVE-2013-4949 2024-11-21 10:56 2013-07-30 Show GitHub Exploit DB Packet Storm
292425 - machform machform SQL injection vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary SQL commands via the element_2 parameter. CWE-89
SQL Injection
CVE-2013-4948 2024-11-21 10:56 2013-07-30 Show GitHub Exploit DB Packet Storm
292426 - sawmill sawmill Unspecified vulnerability in the update and build database page in Sawmill before 8.6.3 allows remote attackers to have unknown impact and attack vectors. NVD-CWE-noinfo
CVE-2013-4947 2024-11-21 10:56 2013-07-30 Show GitHub Exploit DB Packet Storm
292427 - bmc service_desk_express Multiple cross-site scripting (XSS) vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to inject arbitrary web script or HTML via the (1) SelTab parameter to QV_admin.… CWE-79
Cross-site Scripting
CVE-2013-4946 2024-11-21 10:56 2013-07-30 Show GitHub Exploit DB Packet Storm
292428 - bmc service_desk_express Multiple SQL injection vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to execute arbitrary SQL commands via the (1) ASPSESSIONIDASSRATTQ, (2) TABLE_WIDGET_1, (3) T… CWE-89
SQL Injection
CVE-2013-4945 2024-11-21 10:56 2013-07-30 Show GitHub Exploit DB Packet Storm
292429 - fusedpress buddypress-extended-frienship-request Cross-site scripting (XSS) vulnerability in the BuddyPress Extended Friendship Request plugin before 1.0.2 for WordPress, when the "Friend Connections" component is enabled, allows remote attackers t… CWE-79
Cross-site Scripting
CVE-2013-4944 2024-11-21 10:56 2013-07-30 Show GitHub Exploit DB Packet Storm
292430 - freebsd freebsd The vfs_hang_addrlist function in sys/kern/vfs_export.c in the NFS server implementation in the kernel in FreeBSD 8.3 and 9.x through 9.1-RELEASE-p5 controls authorization for host/subnet export entr… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-4851 2024-11-21 10:56 2013-07-29 Show GitHub Exploit DB Packet Storm