Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
240911 9.3 危険 netsieben - NetSieben SSH Library の Ne7sshSftp::addOpenHandle 関数におけるバッファオーバーフローの脆弱性 - CVE-2007-1654 2012-09-25 16:47 2007-03-23 Show GitHub Exploit DB Packet Storm
240912 7.5 危険 OpenID - OpenID における OpenID で有効にされたサイトへユーザーの個人情報を漏洩される脆弱性 - CVE-2007-1652 2012-09-25 16:47 2007-03-22 Show GitHub Exploit DB Packet Storm
240913 6.8 警告 OpenID - OpenID におけるクロスサイトリクエストフォージェリの脆弱性 - CVE-2007-1651 2012-09-25 16:47 2007-03-22 Show GitHub Exploit DB Packet Storm
240914 7.8 危険 pcapsipdump - pcapsipdump の pcapsipdump.cpp におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-1650 2012-09-25 16:47 2007-03-23 Show GitHub Exploit DB Packet Storm
240915 7.8 危険 Moodle - Moodle におけるパスワードハッシュなどの重要な情報を取得される脆弱性 - CVE-2007-1647 2012-09-25 16:47 2007-03-23 Show GitHub Exploit DB Packet Storm
240916 10 危険 マイクロソフト - Microsoft Windows 上の DNS Server サービスにおけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-1644 2012-09-25 16:47 2007-03-23 Show GitHub Exploit DB Packet Storm
240917 10 危険 lan management system - LMS における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-1643 2012-09-25 16:47 2007-03-23 Show GitHub Exploit DB Packet Storm
240918 4 警告 Zoho Corporation - ManageEngine Firewall Analyzer における任意の共通ファイルへアクセスされる脆弱性 CWE-noinfo
情報不足
CVE-2007-1642 2012-09-25 16:47 2007-03-23 Show GitHub Exploit DB Packet Storm
240919 9.3 危険 Ipswitch, Inc. - Ipswitch IMail Server の IMAILAPILib ActiveX コントロールにおけるバッファオーバーフローの脆弱性 - CVE-2007-1637 2012-09-25 16:47 2007-03-5 Show GitHub Exploit DB Packet Storm
240920 9 危険 net portal dynamic system - NPDS の admin/settings.php における任意の PHP コードを挿入される脆弱性 - CVE-2007-1635 2012-09-25 16:47 2007-03-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 10, 2026, 5 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
287661 - ostenta yawpp Multiple SQL injection vulnerabilities in the yawpp plugin 1.2 for WordPress allow remote authenticated users with Contributor privileges to execute arbitrary SQL commands via vectors related to (1) … CWE-89
SQL Injection
CVE-2014-5182 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
287662 - last.fm_rotation_plugin_project lastfm-rotation_plugin Directory traversal vulnerability in lastfm-proxy.php in the Last.fm Rotation (lastfm-rotation) plugin 1.0 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the snod… CWE-22
Path Traversal
CVE-2014-5181 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
287663 - hdwplayer hdw-player-video-player-video-gallery SQL injection vulnerability in the videos page in the HDW Player Plugin (hdw-player-video-player-video-gallery) 2.4.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL… CWE-89
SQL Injection
CVE-2014-5180 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
287664 - freelinking_for_case_tracker_project
freelinking_project
freelinking_for_case_tracker
freelinking
The freelinking module for Drupal, as used in the Freelinking for Case Tracker module, does not properly check access permissions for (1) nodes or (2) users, which allows remote attackers to obtain s… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-5179 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
287665 - efssoft easy_file_sharing_web_server Multiple cross-site scripting (XSS) vulnerabilities in Easy File Sharing (EFS) Web Server 6.8 allow remote authenticated users to inject arbitrary web script or HTML via the content parameter when (1… CWE-79
Cross-site Scripting
CVE-2014-5178 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
287666 - status2k status2k admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the Location field in Add Logs in the Admin Panel. CWE-94
Code Injection
CVE-2014-5090 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
287667 - status2k status2k SQL injection vulnerability in admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary SQL commands via the log parameter. CWE-89
SQL Injection
CVE-2014-5089 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
287668 - status2k status2k Cross-site scripting (XSS) vulnerability in Status2k allows remote attackers to inject arbitrary web script or HTML via the username to login.php. CWE-79
Cross-site Scripting
CVE-2014-5088 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
287669 - sphider sphider Multiple SQL injection vulnerabilities in admin/admin.php in Sphider 1.3.6 and earlier, Sphider Pro, and Sphider-plus allow remote attackers to execute arbitrary SQL commands via the (1) site_id or (… CWE-89
SQL Injection
CVE-2014-5082 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
287670 - redhat
opensuse
enterprise_linux
opensuse
enterprise_virtualization
libvirt
libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declarat… CWE-20
 Improper Input Validation 
CVE-2014-5177 2024-11-21 11:11 2014-08-4 Show GitHub Exploit DB Packet Storm