Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 13, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
242361 7.5 危険 cfmsource - CF_Forum の forummessages.cfm における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6324 2012-06-26 16:10 2009-02-27 Show GitHub Exploit DB Packet Storm
242362 7.5 危険 cfmsource - CFMSource CF_Auction の forummessages.cfm における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6323 2012-06-26 16:10 2009-02-27 Show GitHub Exploit DB Packet Storm
242363 7.5 危険 cfmsource - CFMSource CFMBlog の index.cfm における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6322 2012-06-26 16:10 2009-02-27 Show GitHub Exploit DB Packet Storm
242364 5 警告 cfshopkart - CF Shopkart におけるユーザ名およびパスワード等の重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-6321 2012-06-26 16:10 2009-02-27 Show GitHub Exploit DB Packet Storm
242365 7.5 危険 cfshopkart - CF Shopkart の index.cfm における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6320 2012-06-26 16:10 2009-02-27 Show GitHub Exploit DB Packet Storm
242366 7.5 危険 cfmsource - CF_Calendar の calendarevent.cfm における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6319 2012-06-26 16:10 2009-02-27 Show GitHub Exploit DB Packet Storm
242367 7.5 危険 butterflymedia - Butterfly Organizer の view.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6311 2012-06-26 16:10 2009-02-27 Show GitHub Exploit DB Packet Storm
242368 7.5 危険 e-topbiz - E-topbiz Link Back Checker における管理者アクセス権を取得される脆弱性 CWE-287
不適切な認証
CVE-2008-6307 2012-06-26 16:10 2009-02-26 Show GitHub Exploit DB Packet Storm
242369 6.8 警告 freedirectoryscript - Free Directory Script の init.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-6305 2012-06-26 16:10 2009-02-26 Show GitHub Exploit DB Packet Storm
242370 4.3 警告 dhcart - DHCart の order.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6297 2012-06-26 16:10 2009-02-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
267371 8.1 HIGH
Network
grunt-webdriver-qunit_project grunt-webdriver-qunit grunt-webdriver-qunit is a grunt plugin to run qunit with webdriver in grunt grunt-webdriver-qunit downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible… CWE-310
Cryptographic Issues
CVE-2016-10606 2024-11-21 11:44 2018-06-2 Show GitHub Exploit DB Packet Storm
267372 8.1 HIGH
Network
dalekjs dalekjs dalek-browser-ie is Internet Explorer bindings for DalekJS. dalek-browser-ie downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code … CWE-310
Cryptographic Issues
CVE-2016-10605 2024-11-21 11:44 2018-06-2 Show GitHub Exploit DB Packet Storm
267373 8.1 HIGH
Network
dalekjs dalekjs dalek-browser-chrome is Google Chrome bindings for DalekJS. dalek-browser-chrome downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote c… CWE-310
Cryptographic Issues
CVE-2016-10604 2024-11-21 11:44 2018-06-2 Show GitHub Exploit DB Packet Storm
267374 8.1 HIGH
Network
air-sdk_project air-sdk air-sdk is a NPM wrapper for the Adobe AIR SDK. air-sdk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by sw… CWE-310
Cryptographic Issues
CVE-2016-10603 2024-11-21 11:44 2018-06-2 Show GitHub Exploit DB Packet Storm
267375 8.1 HIGH
Network
haxe haxe haxe is a cross-platform toolkit haxe downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the req… CWE-310
Cryptographic Issues
CVE-2016-10602 2024-11-21 11:44 2018-06-2 Show GitHub Exploit DB Packet Storm
267376 8.1 HIGH
Network
webrtc webrtc-native webrtc-native uses WebRTC from chromium project. webrtc-native downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE… CWE-310
Cryptographic Issues
CVE-2016-10600 2024-11-21 11:44 2018-06-2 Show GitHub Exploit DB Packet Storm
267377 8.1 HIGH
Network
node-sauce-connect_project node-sauce-connect sauce-connect is a Node.js wrapper over the SauceLabs SauceConnect.jar program for establishing a secure tunnel for intranet testing. sauce-connect downloads binary resources over HTTP, which leaves … CWE-310
Cryptographic Issues
CVE-2016-10599 2024-11-21 11:44 2018-06-2 Show GitHub Exploit DB Packet Storm
267378 7.5 HIGH
Network
arrayfire-js_project arrayfire-js arrayfire-js is a module for ArrayFire for the Node.js platform. arrayfire-js downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code… CWE-310
Cryptographic Issues
CVE-2016-10598 2024-11-21 11:44 2018-06-2 Show GitHub Exploit DB Packet Storm
267379 5.9 MEDIUM
Network
cobalt-cli_project cobalt-cli cobalt-cli downloads resources over HTTP, which leaves it vulnerable to MITM attacks. CWE-311
Missing Encryption of Sensitive Data
CVE-2016-10597 2024-11-21 11:44 2018-06-2 Show GitHub Exploit DB Packet Storm
267380 8.1 HIGH
Network
imageoptim_project imageoptim imageoptim is a Node.js wrapper for some images compression algorithms. imageoptim downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote… CWE-310
Cryptographic Issues
CVE-2016-10596 2024-11-21 11:44 2018-06-2 Show GitHub Exploit DB Packet Storm