Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
242401 6.8 警告 Drupal - Drupal 用の MySite モジュールにおけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6647 2012-06-26 15:38 2006-12-18 Show GitHub Exploit DB Packet Storm
242402 6.8 警告 Drupal - Drupal Project Issue Tracking および Drupal Project におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6646 2012-06-26 15:38 2006-12-18 Show GitHub Exploit DB Packet Storm
242403 5 警告 fightersoft multimedia - Fightersoft Multimedia Star FTP サーバにおけるサービス運用妨害 (DoS) の脆弱性 - CVE-2006-6643 2012-06-26 15:38 2006-12-19 Show GitHub Exploit DB Packet Storm
242404 7.5 危険 contra haber sistemi - Contra Haber Sistemi の haber.asp における SQL インジェクションの脆弱性 - CVE-2006-6642 2012-06-26 15:38 2006-12-19 Show GitHub Exploit DB Packet Storm
242405 7.5 危険 etrust
cleverpath
Arcserve
unicenter
CA Technologies
- BrightStor Portal などで使用される CA CleverPath Portal における異なる Portal サーバのユーザのセッションおよび資格情報を継承される脆弱性 - CVE-2006-6641 2012-06-26 15:38 2006-12-19 Show GitHub Exploit DB Packet Storm
242406 4.6 警告 chetcpasswd - chetcpasswd における権限を取得される脆弱性 - CVE-2006-6639 2012-06-26 15:38 2006-12-19 Show GitHub Exploit DB Packet Storm
242407 6.8 警告 genepi - Genepi の genepi.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-6632 2012-06-26 15:38 2006-12-18 Show GitHub Exploit DB Packet Storm
242408 7.2 危険 シマンテック - Sygate Personal Firewall における実行中の製品コントロールを回避される脆弱性 - CVE-2006-6623 2012-06-26 15:38 2006-12-18 Show GitHub Exploit DB Packet Storm
242409 7.2 危険 soft4ever - Soft4Ever LnS における実行中の製品コントロールを回避される脆弱性 - CVE-2006-6622 2012-06-26 15:38 2006-12-18 Show GitHub Exploit DB Packet Storm
242410 7.2 危険 filseclab - Filseclab Personal Firewall における実行中の製品コントロールを回避される脆弱性 - CVE-2006-6621 2012-06-26 15:38 2006-12-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 27, 2026, 1:20 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
251441 5.5 MEDIUM
Local
linux linux_kernel The sg_ioctl function in drivers/scsi/sg.c in the Linux kernel before 4.13.4 allows local users to obtain sensitive information from uninitialized kernel heap-memory locations via an SG_GET_REQUEST_T… CWE-200
Information Exposure
CVE-2017-14991 2024-11-21 12:13 2017-10-4 Show GitHub Exploit DB Packet Storm
251442 6.1 MEDIUM
Network
wso2 machine_learner
data_services_server
dashboard_server
complex_event_processor
business_rules_server
business_process_server
application_server
data_analytics_server
The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Da… CWE-79
Cross-site Scripting
CVE-2017-14995 2024-11-21 12:13 2017-10-4 Show GitHub Exploit DB Packet Storm
251443 6.5 MEDIUM
Network
wordpress
debian
wordpress
debian_linux
WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack u… CWE-312
 Cleartext Storage of Sensitive Information
CVE-2017-14990 2024-11-21 12:13 2017-10-3 Show GitHub Exploit DB Packet Storm
251444 6.5 MEDIUM
Network
imagemagick imagemagick A use-after-free in RenderFreetype in MagickCore/annotate.c in ImageMagick 7.0.7-4 Q16 allows attackers to crash the application via a crafted font file, because the FT_Done_Glyph function (from Free… CWE-416
 Use After Free
CVE-2017-14989 2024-11-21 12:13 2017-10-3 Show GitHub Exploit DB Packet Storm
251445 5.5 MEDIUM
Local
openexr openexr Header::readfrom in IlmImf/ImfHeader.cpp in OpenEXR 2.2.0 allows remote attackers to cause a denial of service (excessive memory allocation) via a crafted file that is accessed with the ImfOpenInputF… CWE-400
 Uncontrolled Resource Consumption
CVE-2017-14988 2024-11-21 12:13 2017-10-3 Show GitHub Exploit DB Packet Storm
251446 5.4 MEDIUM
Network
eyesofnetwork eyesofnetwork Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated users to inject arbitrary web script or HTML via the url parameter to module… CWE-79
Cross-site Scripting
CVE-2017-14985 2024-11-21 12:13 2017-10-3 Show GitHub Exploit DB Packet Storm
251447 5.4 MEDIUM
Network
eyesofnetwork eyesofnetwork Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated users to inject arbitrary web script or HTML via the bp_name parameter to /m… CWE-79
Cross-site Scripting
CVE-2017-14984 2024-11-21 12:13 2017-10-3 Show GitHub Exploit DB Packet Storm
251448 4.8 MEDIUM
Network
eyesofnetwork eyesofnetwork Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to inject arbitrary web script or HTML via the object paramet… CWE-79
Cross-site Scripting
CVE-2017-14983 2024-11-21 12:13 2017-10-3 Show GitHub Exploit DB Packet Storm
251449 5.4 MEDIUM
Network
atutor atutor Cross-Site Scripting (XSS) was discovered in ATutor before 2.2.3. The vulnerability exists due to insufficient filtration of data (url in /mods/_standard/rss_feeds/edit_feed.php). An attacker could i… CWE-79
Cross-site Scripting
CVE-2017-14981 2024-11-21 12:13 2017-10-3 Show GitHub Exploit DB Packet Storm
251450 7.5 HIGH
Network
gxlcms gxlcms Gxlcms uses an unsafe character-replacement approach in an attempt to restrict access, which allows remote attackers to read arbitrary files via modified pathnames in the s parameter to index.php, re… NVD-CWE-noinfo
CVE-2017-14979 2024-11-21 12:13 2017-10-3 Show GitHub Exploit DB Packet Storm