Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 8, 2026, 12:07 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
236431 4.3 警告 Mort Bay Consulting - Mort Bay Jetty の WebApp JSP Snoop ページにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4612 2012-09-25 17:38 2010-01-13 Show GitHub Exploit DB Packet Storm
236432 7.5 危険 Mort Bay Consulting - Mort Bay Jetty における任意のコマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2009-4611 2012-09-25 17:38 2010-01-13 Show GitHub Exploit DB Packet Storm
236433 4.3 警告 Mort Bay Consulting - Mort Bay Jetty におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4610 2012-09-25 17:38 2010-01-13 Show GitHub Exploit DB Packet Storm
236434 5 警告 Mort Bay Consulting - Mort Bay Jetty の Dump Servlet における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2009-4609 2012-09-25 17:38 2010-01-13 Show GitHub Exploit DB Packet Storm
236435 7.2 危険 overlandstorage - GuardianOS 上で稼動する Overland Storage Snap Server のコマンドラインインターフェースにおける権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-4607 2012-09-25 17:38 2010-01-13 Show GitHub Exploit DB Packet Storm
236436 7.5 危険 NetArt Media - NetArt Media Real Estate Portal における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4600 2012-09-25 17:38 2010-01-12 Show GitHub Exploit DB Packet Storm
236437 7.5 危険 joomshark - Joomla! 用の jsjobs コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4599 2012-09-25 17:38 2010-01-12 Show GitHub Exploit DB Packet Storm
236438 5 警告 jesse smith - Bftpd の bftpdutmp_log 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2009-4593 2012-09-25 17:38 2010-01-7 Show GitHub Exploit DB Packet Storm
236439 7.5 危険 Joomla! - Joomla! 用の DhForum における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4583 2012-09-25 17:38 2010-01-6 Show GitHub Exploit DB Packet Storm
236440 4.3 警告 hastablog - Hasta Blog におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4580 2012-09-25 17:38 2010-01-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 8, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
346841 - aliacom open_business_management Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers to inject arbitrary HTML or web script via the (1) tf_lang, (2) tf_name, (3) tf_… NVD-CWE-Other
CVE-2006-3009 2017-07-20 10:31 2006-06-14 Show GitHub Exploit DB Packet Storm
346842 - aliacom open_business_management Multiple SQL injection vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers to execute arbitrary SQL commands via the (1) new_order and (2) order_dir parameters to (a) i… NVD-CWE-Other
CVE-2006-3010 2017-07-20 10:31 2006-06-14 Show GitHub Exploit DB Packet Storm
346843 - php php The error_log function in basic_functions.c in PHP before 4.4.4 and 5.x before 5.1.5 allows local users to bypass safe mode and open_basedir restrictions via a "php://" or other scheme in the third a… CWE-264
Permissions, Privileges, and Access Controls
CVE-2006-3011 2017-07-20 10:31 2006-06-27 Show GitHub Exploit DB Packet Storm
346844 - planete_afrique ws-album Multiple cross-site scripting (XSS) vulnerabilities in FullPhoto.asp in WS-Album 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) image and (2) PublisedDate p… NVD-CWE-Other
CVE-2006-3020 2017-07-20 10:31 2006-06-15 Show GitHub Exploit DB Packet Storm
346845 - blue-collar_productions i-gallery Multiple cross-site scripting (XSS) vulnerabilities in BlueCollar i-Gallery 4.1 PLUS and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) n and (2) d parameters in (a… NVD-CWE-Other
CVE-2006-3021 2017-07-20 10:31 2006-06-15 Show GitHub Exploit DB Packet Storm
346846 - fipsasp fipsgallery Cross-site scripting (XSS) vulnerability in zoom.php in fipsGallery 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the path parameter. NVD-CWE-Other
CVE-2006-3022 2017-07-20 10:31 2006-06-15 Show GitHub Exploit DB Packet Storm
346847 - uapplication uphotogallery Multiple cross-site scripting (XSS) vulnerabilities in thumbnails.asp in Uapplication Uphotogallery 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) s and (2)… NVD-CWE-Other
CVE-2006-3023 2017-07-20 10:31 2006-06-15 Show GitHub Exploit DB Packet Storm
346848 - evgenius evgenius_counter Multiple cross-site scripting (XSS) vulnerabilities in EvGenius Counter 3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the page parameter in (1) monthly.php and (2)… NVD-CWE-Other
CVE-2006-3024 2017-07-20 10:31 2006-06-15 Show GitHub Exploit DB Packet Storm
346849 - clicktech clickgallery Multiple cross-site scripting (XSS) vulnerabilities in ClickGallery 5.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in gallery.asp and (… NVD-CWE-Other
CVE-2006-3026 2017-07-20 10:31 2006-06-15 Show GitHub Exploit DB Packet Storm
346850 - clicktech clickcart Cross-site scripting (XSS) vulnerability in default.asp in ClickTech Clickcart 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter. NVD-CWE-Other
CVE-2006-3029 2017-07-20 10:31 2006-06-15 Show GitHub Exploit DB Packet Storm