Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
233651 7.5 危険 iexpress - iExpress の Property Pro の vir_login.asp における SQL インジェクションの脆弱性 - CVE-2007-3992 2012-09-25 16:47 2007-07-25 Show GitHub Exploit DB Packet Storm
233652 7.5 危険 junction quest - ImageRacer の SearchResults.asp における SQL インジェクションの脆弱性 - CVE-2007-3987 2012-09-25 16:47 2007-07-25 Show GitHub Exploit DB Packet Storm
233653 6.8 警告 NetArt Media - BlogSite Professional の index.php における SQL インジェクションの脆弱性 - CVE-2007-3979 2012-09-25 16:47 2007-07-25 Show GitHub Exploit DB Packet Storm
233654 7.5 危険 jblog - JBlog の admin/ajoutaut.php における任意のアカウントを作成される脆弱性 - CVE-2007-3974 2012-09-25 16:47 2007-07-25 Show GitHub Exploit DB Packet Storm
233655 6.8 警告 jblog - JBlog におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3973 2012-09-25 16:47 2007-07-25 Show GitHub Exploit DB Packet Storm
233656 9.3 危険 Panda Security - Panda Antivirus におけるバッファオーバーフローの脆弱性 - CVE-2007-3969 2012-09-25 16:47 2007-07-25 Show GitHub Exploit DB Packet Storm
233657 5 警告 iexpress - Munch Pro における SQL インジェクションの脆弱性 - CVE-2007-3966 2012-09-25 16:47 2007-07-25 Show GitHub Exploit DB Packet Storm
233658 5 警告 itaka - Itaka における重要な情報を取得される脆弱性 - CVE-2007-3964 2012-09-25 16:47 2007-07-25 Show GitHub Exploit DB Packet Storm
233659 5 警告 Ipswitch, Inc. - ICS の Ipswitch Instant Messaging の IM Server におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-3959 2012-09-25 16:47 2007-07-24 Show GitHub Exploit DB Packet Storm
233660 7.1 危険 マイクロソフト - Windows 2000 などで稼働する Microsoft Windows Explorer におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-3958 2012-09-25 16:47 2007-07-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 26, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
285001 - mozilla firefox Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a… CWE-79
Cross-site Scripting
CVE-2007-5414 2018-10-16 06:44 2007-10-13 Show GitHub Exploit DB Packet Storm
285002 - mozilla firefox Cross-site scripting (XSS) vulnerability in Mozilla Firefox 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a gopher… CWE-79
Cross-site Scripting
CVE-2007-5415 2018-10-16 06:44 2007-10-13 Show GitHub Exploit DB Packet Storm
285003 - drupal drupal Drupal 5.2 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers t… CWE-189
Numeric Errors
CVE-2007-5416 2018-10-16 06:44 2007-10-13 Show GitHub Exploit DB Packet Storm
285004 - boastmachine boastmachine Directory traversal vulnerability in index.php in boastMachine (aka bMachine) 2.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter. CWE-22
Path Traversal
CVE-2007-5417 2018-10-16 06:44 2007-10-13 Show GitHub Exploit DB Packet Storm
285005 - care2x 2g Multiple PHP remote file inclusion vulnerabilities in CARE2X 2G 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) en_copyrite.php, (2) vi_copyrite.p… CWE-94
Code Injection
CVE-2007-5418 2018-10-16 06:44 2007-10-13 Show GitHub Exploit DB Packet Storm
285006 - 3com 3crwe554g72t The 3Com 3CRWER100-75 router with 1.2.10ww software, when enabling an optional virtual server, configures this server to accept all source IP addresses on the external (Internet) interface unless the… CWE-16
Configuration
CVE-2007-5419 2018-10-16 06:44 2007-10-13 Show GitHub Exploit DB Packet Storm
285007 - 3com 3crwe554g72t The 3Com 3CRWER100-75 router with 1.2.10ww software, when remote management is disabled but a web server has been configured, serves a web page to external clients, which might allow remote attackers… CWE-16
CWE-200
Configuration
Information Exposure
CVE-2007-5420 2018-10-16 06:44 2007-10-13 Show GitHub Exploit DB Packet Storm
285008 - tiki tikiwiki_cms\/groupware tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, which are processed by create_function. CWE-94
Code Injection
CVE-2007-5423 2018-10-16 06:44 2007-10-13 Show GitHub Exploit DB Packet Storm
285009 - php php The disable_functions feature in PHP 4 and 5 allows attackers to bypass intended restrictions by using an alias, as demonstrated by using ini_alter when ini_set is disabled. NVD-CWE-Other
CVE-2007-5424 2018-10-16 06:44 2007-10-13 Show GitHub Exploit DB Packet Storm
285010 - interspire activekb SQL injection vulnerability in admin/index.php in Interspire ActiveKB 1.5 allows remote attackers to execute arbitrary SQL commands via the questId parameter in a hideQuestion ToDo action. NOTE: the… CWE-94
Code Injection
CVE-2007-5425 2018-10-16 06:44 2007-10-13 Show GitHub Exploit DB Packet Storm