Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 2, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
240081 9.3 危険 maklerplus - MaklerPlus における脆弱性 - CVE-2007-0509 2012-09-25 16:47 2007-01-25 Show GitHub Exploit DB Packet Storm
240082 6.8 警告 mafia scum tools - Matthew Wardrop adv-random-gen の Mafia Scum Tools における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-0501 2012-09-25 16:47 2007-01-25 Show GitHub Exploit DB Packet Storm
240083 10 危険 neon labs - Neon Labs Website の lib/nl/nl.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-0496 2012-09-25 16:47 2007-01-25 Show GitHub Exploit DB Packet Storm
240084 5 警告 Transparent Technologies - Open-Realty の index.php における重要な情報 (フルパス) を取得される脆弱性 - CVE-2007-0490 2012-09-25 16:47 2007-01-24 Show GitHub Exploit DB Packet Storm
240085 5 警告 Huawei - Quidway R1600 Router におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-0488 2012-09-25 16:47 2007-01-24 Show GitHub Exploit DB Packet Storm
240086 6.8 警告 マイクロソフト - Microsoft Visual Studio 6.0 SP6 の MSVC におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-0468 2012-09-25 16:47 2007-01-23 Show GitHub Exploit DB Packet Storm
240087 10 危険 The PHP Group - PHP の fopen 関数における safe_mode 制限を回避される脆弱性 - CVE-2007-0448 2012-09-25 16:47 2007-05-24 Show GitHub Exploit DB Packet Storm
240088 10 危険 ヒューレット・パッカード - Hewlett-Packard Mercury LoadRunner Agent におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-0446 2012-09-25 16:47 2007-02-8 Show GitHub Exploit DB Packet Storm
240089 10 危険 カスペルスキー - Kaspersky Anti-Virus の OnDemand Scanner におけるヒープベースのバッファオーバーフローの脆弱性 - CVE-2007-0445 2012-09-25 16:47 2007-04-5 Show GitHub Exploit DB Packet Storm
240090 5 警告 IBM - IBM OS/400 における脆弱性 - CVE-2007-0442 2012-09-25 16:47 2007-01-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 2, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
285151 9.8 CRITICAL
Network
microsemi s350i_firmware SQL injection vulnerability in the checkPassword function in Symmetricom s350i 2.70.15 allows remote attackers to execute arbitrary SQL commands via vectors involving a username. CWE-89
SQL Injection
CVE-2014-5071 2024-11-21 11:11 2018-01-9 Show GitHub Exploit DB Packet Storm
285152 6.1 MEDIUM
Network
microsemi s350i_firmware Cross-site scripting (XSS) vulnerability in Symmetricom s350i 2.70.15 allows remote attackers to inject arbitrary web script or HTML via vectors involving system logs. CWE-79
Cross-site Scripting
CVE-2014-5069 2024-11-21 11:11 2018-01-9 Show GitHub Exploit DB Packet Storm
285153 9.8 CRITICAL
Network
ajax_upload_for_gravity_forms_project ajax_upload_for_gravity_forms Unrestricted file upload vulnerability in the Gravity Upload Ajax plugin 1.1 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extensi… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2014-4972 2024-11-21 11:11 2018-01-9 Show GitHub Exploit DB Packet Storm
285154 5.5 MEDIUM
Local
rawstudio
fedoraproject
rawstudio
fedora
The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to truncate arbitrary files via a symlink attack on (1) /tmp/rs-filter-graph.png or (2) /tmp/rs-filter-gr… CWE-59
Link Following
CVE-2014-4978 2024-11-21 11:11 2017-12-30 Show GitHub Exploit DB Packet Storm
285155 9.8 CRITICAL
Network
zend
debian
zend_framework
debian_linux
The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors. CWE-89
SQL Injection
CVE-2014-4914 2024-11-21 11:11 2017-12-29 Show GitHub Exploit DB Packet Storm
285156 7.2 HIGH
Network
landesk landesk_management_suite The admin interface in Landesk Management Suite 9.6 and earlier allows remote attackers to conduct remote file inclusion attacks involving ASPX pages from third-party sites via the d parameter to (1)… CWE-20
 Improper Input Validation 
CVE-2014-5362 2024-11-21 11:11 2017-09-20 Show GitHub Exploit DB Packet Storm
285157 8.8 HIGH
Network
manageengine servicedesk_plus
assetexplorer
supportcenter
it360
Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4 allows remote authenticated users to ex… CWE-22
Path Traversal
CVE-2014-5302 2024-11-21 11:11 2017-08-29 Show GitHub Exploit DB Packet Storm
285158 8.8 HIGH
Network
manageengine servicedesk_plus
assetexplorer
supportcenter
it360
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4. CWE-22
Path Traversal
CVE-2014-5301 2024-11-21 11:11 2017-08-29 Show GitHub Exploit DB Packet Storm
285159 6.1 MEDIUM
Network
good good_for_enterprise Cross-site scripting (XSS) vulnerability in Good for Enterprise for Android 2.8.0.398 and 1.9.0.40. CWE-79
Cross-site Scripting
CVE-2014-4925 2024-11-21 11:11 2017-08-29 Show GitHub Exploit DB Packet Storm
285160 5.4 MEDIUM
Network
telescopeapp telescope Cross-site scripting (XSS) vulnerability in Telescope before 0.9.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted markdown. CWE-79
Cross-site Scripting
CVE-2014-5144 2024-11-21 11:11 2017-08-10 Show GitHub Exploit DB Packet Storm