Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":July 1, 2026, 4:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
239801 7.5 危険 mischa heimann - TYPO3 用の YATSE エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1004 2012-09-25 17:38 2010-03-19 Show GitHub Exploit DB Packet Storm
239802 5.8 警告 KDE project - KDE SC の KGet におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-1000 2012-09-25 17:38 2010-05-13 Show GitHub Exploit DB Packet Storm
239803 4.3 警告 Joomla Mo - Joomla! 用の CARTwebERP コンポーネントにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-0982 2012-09-25 17:38 2010-03-16 Show GitHub Exploit DB Packet Storm
239804 7.5 危険 mitchell sleeper - L4D Stats の player.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-0980 2012-09-25 17:38 2010-03-16 Show GitHub Exploit DB Packet Storm
239805 4.3 警告 obsession-design - ODIG の display.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-0979 2012-09-25 17:38 2010-03-16 Show GitHub Exploit DB Packet Storm
239806 5 警告 KMSoft - KMSoft Guestbook におけるデータベースをダウンロードされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-0978 2012-09-25 17:38 2010-03-16 Show GitHub Exploit DB Packet Storm
239807 7.5 危険 jorik berkepas - PhpMyLogon の phpmylogon.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-0970 2012-09-25 17:38 2010-03-16 Show GitHub Exploit DB Packet Storm
239808 5 警告 Stichting NLnet Labs - Unbound におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2010-0969 2012-09-25 17:38 2010-03-11 Show GitHub Exploit DB Packet Storm
239809 5 警告 jevci.net - Jevci Siparis Formu Scripti におけるデータベースをダウンロードされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-0965 2012-09-25 17:38 2010-03-16 Show GitHub Exploit DB Packet Storm
239810 7.5 危険 media-products - Eros Webkatalog の start.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-0964 2012-09-25 17:38 2010-03-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:July 1, 2026, 4:27 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
345951 - thomastsoi quirex Absolute path traversal vulnerability in convert.cgi in Quirex 2.0.2 and earlier allows remote attackers to read arbitrary files, and possibly execute arbitrary code, via the (1) quiz_head, (2) quiz_… CWE-22
Path Traversal
CVE-2006-0795 2018-10-19 01:29 2006-02-20 Show GitHub Exploit DB Packet Storm
345952 - francisco_burzi php-nuke The CAPTCHA functionality in php-Nuke 6.0 through 7.9 uses fixed challenge/response pairs that only vary once per day based on the User Agent (HTTP_USER_AGENT), which allows remote attackers to bypas… NVD-CWE-Other
CVE-2006-0805 2018-10-19 01:29 2006-02-21 Show GitHub Exploit DB Packet Storm
345953 - john_lim adodb Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbitrary web script or HTML via (1) the next_page par… CWE-79
Cross-site Scripting
CVE-2006-0806 2018-10-19 01:29 2006-02-21 Show GitHub Exploit DB Packet Storm
345954 - njstar chinese_word_processor
japanese_word_processor
Stack-based buffer overflow in NJStar Chinese and Japanese Word Processor 4.x and 5.x before 5.10 allows user-assisted attackers to execute arbitrary code via font names in NJStar (.njx) documents. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2006-0807 2018-10-19 01:29 2006-02-21 Show GitHub Exploit DB Packet Storm
345955 - visnetic visnetic_antivirus_plug-in_for_mail_server The VisNetic AntiVirus Plug-in (DKAVUpSch.exe) for Mail Server 4.6.0.4, 4.6.1.1, and possibly other versions before 4.6.1.2, does not drop privileges before executing other programs, which allows loc… NVD-CWE-Other
CVE-2006-0812 2018-10-19 01:29 2006-02-24 Show GitHub Exploit DB Packet Storm
345956 - winace winace Heap-based buffer overflow in WinACE 2.60 allows user-assisted attackers to execute arbitrary code via a large header block in an ARJ archive. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2006-0813 2018-10-19 01:29 2006-02-24 Show GitHub Exploit DB Packet Storm
345957 - lighttpd lighttpd response.c in Lighttpd 1.4.10 and possibly previous versions, when run on Windows, allows remote attackers to read arbitrary source code via requests that contain trailing (1) "." (dot) and (2) space… NVD-CWE-Other
CVE-2006-0814 2018-10-19 01:29 2006-03-7 Show GitHub Exploit DB Packet Storm
345958 - networkactiv networkactiv_web_server NetworkActiv Web Server 3.5.15 allows remote attackers to read script source code via a crafted URL with a "/" (forward slash) after the file extension. NVD-CWE-Other
CVE-2006-0815 2018-10-19 01:29 2006-03-7 Show GitHub Exploit DB Packet Storm
345959 - orionserver orion_application_server Orion Application Server before 2.0.7, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot) and (2) space characters in the extension of a URL. NVD-CWE-Other
CVE-2006-0816 2018-10-19 01:29 2006-03-24 Show GitHub Exploit DB Packet Storm
345960 - orionserver orion_application_server Update to version 2.0.7 or contact the vendor for a patch. NVD-CWE-Other
CVE-2006-0816 2018-10-19 01:29 2006-03-24 Show GitHub Exploit DB Packet Storm