Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
240921 7.5 危険 net portal dynamic system - NPDS の grab_globals.php における SQL インジェクション攻撃を実行される脆弱性 - CVE-2007-1634 2012-09-25 16:47 2007-03-23 Show GitHub Exploit DB Packet Storm
240922 10 危険 lbstone - APB の templates/head.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-1621 2012-09-25 16:47 2007-03-22 Show GitHub Exploit DB Packet Storm
240923 10 危険 php db designer - PHP DB Designer における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-1620 2012-09-25 16:47 2007-03-22 Show GitHub Exploit DB Packet Storm
240924 7.5 危険 mpm chat - MPlayer の libmpdemux/demux_vqf.c におけるディレクトリトラバーサルの脆弱性 - CVE-2007-1613 2012-09-25 16:47 2007-03-22 Show GitHub Exploit DB Packet Storm
240925 7.5 危険 katalog plyt audio - Katalog Plyt Audio の index.php における SQL インジェクションの脆弱性 - CVE-2007-1612 2012-09-25 16:47 2007-03-22 Show GitHub Exploit DB Packet Storm
240926 4.3 警告 オラクル - OAS の DMS におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-1609 2012-09-25 16:47 2007-03-22 Show GitHub Exploit DB Packet Storm
240927 6.8 警告 intervations - InterVations FileCOPA FTP Server におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-1598 2012-09-25 16:47 2007-03-22 Show GitHub Exploit DB Packet Storm
240928 9.3 危険 Mambo Foundation
Joomla!
- Mambo および Joomla! 用の NFN Address Book における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-1596 2012-09-25 16:47 2007-03-22 Show GitHub Exploit DB Packet Storm
240929 7.5 危険 myserver - MyServer の server.cpp における CGI プログラムを実行される脆弱性 - CVE-2007-1588 2012-09-25 16:47 2007-03-21 Show GitHub Exploit DB Packet Storm
240930 5 警告 シスコシステムズ (Linksys) - Linksys WAG200G などにおける重要な情報 (パスワードおよび設定データ) を取得される脆弱性 - CVE-2007-1585 2012-09-25 16:47 2007-03-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 10, 2026, 5 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
287661 - ostenta yawpp Multiple SQL injection vulnerabilities in the yawpp plugin 1.2 for WordPress allow remote authenticated users with Contributor privileges to execute arbitrary SQL commands via vectors related to (1) … CWE-89
SQL Injection
CVE-2014-5182 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
287662 - last.fm_rotation_plugin_project lastfm-rotation_plugin Directory traversal vulnerability in lastfm-proxy.php in the Last.fm Rotation (lastfm-rotation) plugin 1.0 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the snod… CWE-22
Path Traversal
CVE-2014-5181 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
287663 - hdwplayer hdw-player-video-player-video-gallery SQL injection vulnerability in the videos page in the HDW Player Plugin (hdw-player-video-player-video-gallery) 2.4.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL… CWE-89
SQL Injection
CVE-2014-5180 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
287664 - freelinking_for_case_tracker_project
freelinking_project
freelinking_for_case_tracker
freelinking
The freelinking module for Drupal, as used in the Freelinking for Case Tracker module, does not properly check access permissions for (1) nodes or (2) users, which allows remote attackers to obtain s… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-5179 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
287665 - efssoft easy_file_sharing_web_server Multiple cross-site scripting (XSS) vulnerabilities in Easy File Sharing (EFS) Web Server 6.8 allow remote authenticated users to inject arbitrary web script or HTML via the content parameter when (1… CWE-79
Cross-site Scripting
CVE-2014-5178 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
287666 - status2k status2k admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the Location field in Add Logs in the Admin Panel. CWE-94
Code Injection
CVE-2014-5090 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
287667 - status2k status2k SQL injection vulnerability in admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary SQL commands via the log parameter. CWE-89
SQL Injection
CVE-2014-5089 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
287668 - status2k status2k Cross-site scripting (XSS) vulnerability in Status2k allows remote attackers to inject arbitrary web script or HTML via the username to login.php. CWE-79
Cross-site Scripting
CVE-2014-5088 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
287669 - sphider sphider Multiple SQL injection vulnerabilities in admin/admin.php in Sphider 1.3.6 and earlier, Sphider Pro, and Sphider-plus allow remote attackers to execute arbitrary SQL commands via the (1) site_id or (… CWE-89
SQL Injection
CVE-2014-5082 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
287670 - redhat
opensuse
enterprise_linux
opensuse
enterprise_virtualization
libvirt
libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declarat… CWE-20
 Improper Input Validation 
CVE-2014-5177 2024-11-21 11:11 2014-08-4 Show GitHub Exploit DB Packet Storm