Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 25, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
240151 10 危険 Novell - Novell ZAM などの Msg.dll における整数オーバーフローの脆弱性 - CVE-2006-6299 2012-09-25 15:36 2006-12-5 Show GitHub Exploit DB Packet Storm
240152 7.5 危険 maxiasp - Metyus Okul Yonetim Sistemi の uye_giris_islem.asp における SQL インジェクションの脆弱性 - CVE-2006-6298 2012-09-25 15:36 2006-12-5 Show GitHub Exploit DB Packet Storm
240153 5 警告 KDE project - KDE イメージブラウザで使用される KFILE JPEG プラグインにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2006-6297 2012-09-25 15:36 2006-11-29 Show GitHub Exploit DB Packet Storm
240154 6.1 警告 マイクロソフト - Microsoft Windows 2000 SP4 などの Print Spooler サービスにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2006-6296 2012-09-25 15:36 2006-12-5 Show GitHub Exploit DB Packet Storm
240155 6.8 警告 mxbb - MxBB Portal 用の mx_tinies Module における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-6295 2012-09-25 15:36 2006-12-5 Show GitHub Exploit DB Packet Storm
240156 6.8 警告 MailEnable - MailEnable の IMAP モジュールにおけるスタックオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2006-6291 2012-09-25 15:36 2006-12-5 Show GitHub Exploit DB Packet Storm
240157 6.5 警告 MailEnable - MailEnable の IMAP モジュールにおけるスタックベースバッファオーバーフローの脆弱性 - CVE-2006-6290 2012-09-25 15:36 2006-12-5 Show GitHub Exploit DB Packet Storm
240158 4.6 警告 niek albers - Niek Albers CoolPlayer におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2006-6288 2012-09-25 15:36 2006-12-4 Show GitHub Exploit DB Packet Storm
240159 1.7 注意 palm - Palm Desktop における重要な情報を取得される脆弱性 - CVE-2006-6286 2012-09-25 15:36 2006-12-4 Show GitHub Exploit DB Packet Storm
240160 7.5 危険 o2php.com - O2PHP Bulletin Board の viewthread.php における SQL インジェクションの脆弱性 - CVE-2006-6280 2012-09-25 15:36 2006-12-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 25, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
285541 - google
lenovo
android
shareit
java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute ar… CWE-94
Code Injection
CVE-2014-1939 2024-11-21 11:05 2014-03-3 Show GitHub Exploit DB Packet Storm
285542 - drinkedin drinkedin_barfinder The DrinkedIn BarFinder application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently obtain sensitive fine-geo… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-1887 2024-11-21 11:05 2014-03-3 Show GitHub Exploit DB Packet Storm
285543 - edinburghtour edinburgh_by_bus The Edinburgh by Bus application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently access external-storage reso… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-1886 2024-11-21 11:05 2014-03-3 Show GitHub Exploit DB Packet Storm
285544 - hsgroup forzearmate The ForzeArmate application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently obtain write access to external-s… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-1885 2024-11-21 11:05 2014-03-3 Show GitHub Exploit DB Packet Storm
285545 - apache
adobe
cordova
phonegap
Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier on Windows Phone 7 and 8 do not properly restrict navigation events, which allows remote attackers to bypass intended device-reso… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-1884 2024-11-21 11:05 2014-03-3 Show GitHub Exploit DB Packet Storm
285546 - adobe phonegap Adobe PhoneGap before 2.6.0 on Android uses the shouldOverrideUrlLoading callback instead of the proper shouldInterceptRequest callback, which allows remote attackers to bypass intended device-resour… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-1883 2024-11-21 11:05 2014-03-3 Show GitHub Exploit DB Packet Storm
285547 - adobe
apache
phonegap
cordova
Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an event-based bridge via a crafted library clone that … CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-1882 2024-11-21 11:05 2014-03-3 Show GitHub Exploit DB Packet Storm
285548 - apache
adobe
cordova
phonegap
Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an event-based bridge via a crafted library clone that … CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-1881 2024-11-21 11:05 2014-03-3 Show GitHub Exploit DB Packet Storm
285549 - synology diskstation_manager The OpenVPN module in Synology DiskStation Manager (DSM) 4.3-3810 update 1 has a hardcoded root password of synopass, which makes it easier for remote attackers to obtain access via a VPN session. CWE-255
CWE-200
Credentials Management
Information Exposure
CVE-2014-2264 2024-11-21 11:05 2014-03-3 Show GitHub Exploit DB Packet Storm
285550 - cmsmadesimple cms_made_simple Cross-site scripting (XSS) vulnerability in lib/filemanager/ImageManager/editorFrame.php in CMS Made Simple 1.11.10 allows remote attackers to inject arbitrary web script or HTML via the action param… CWE-79
Cross-site Scripting
CVE-2014-2092 2024-11-21 11:05 2014-03-3 Show GitHub Exploit DB Packet Storm