Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 23, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
242701 7.5 危険 netsprint - Netsprint Toolbar の toolbar.dll におけるバッファオーバーフローの脆弱性 - CVE-2007-2678 2012-09-25 16:47 2007-05-14 Show GitHub Exploit DB Packet Storm
242702 7.5 危険 open translation engine - OTE の skins/header.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2676 2012-09-25 16:47 2007-05-14 Show GitHub Exploit DB Packet Storm
242703 7.1 危険 Mozilla Foundation - Mozilla Firefox におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2671 2012-09-25 16:47 2007-05-14 Show GitHub Exploit DB Packet Storm
242704 7.6 危険 Don Ho
scintilla
- notepad++ で使用される Scintilla の LexRuby.cxx におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-2666 2012-09-25 16:47 2007-05-14 Show GitHub Exploit DB Packet Storm
242705 7.5 危険 php firstpost - PhpFirstPost の block.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2665 2012-09-25 16:47 2007-05-14 Show GitHub Exploit DB Packet Storm
242706 3.5 注意 MySQL AB - MySQL におけるパーティションで区切られたテーブルから重要な情報を取得される脆弱性 - CVE-2007-2693 2012-09-25 16:47 2006-10-26 Show GitHub Exploit DB Packet Storm
242707 7.8 危険 idautomation - IDAutomationLinear6.dll の ID Automation Linear Barcode ActiveX コントロールにおけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2658 2012-09-25 16:47 2007-05-14 Show GitHub Exploit DB Packet Storm
242708 7.8 危険 ヒューレット・パッカード - hpqvwocx.dll におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-2656 2012-09-25 16:47 2007-05-14 Show GitHub Exploit DB Packet Storm
242709 7.5 危険 Netwin Ltd - SurgeMail の NetWin Webmail におけるリモートコードを実行される脆弱性 CWE-134
書式文字列の問題
CVE-2007-2655 2012-09-25 16:47 2007-05-14 Show GitHub Exploit DB Packet Storm
242710 6.5 警告 monalbum - Monalbum の admin/admin_configuration.php における PHP コードを挿入される脆弱性 - CVE-2007-2647 2012-09-25 16:47 2007-05-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 24, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
285671 - reality66 cart66_lite SQL injection vulnerability in models/Cart66Ajax.php in the Cart66 Lite plugin before 1.5.4 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the q parameter in a … CWE-89
SQL Injection
CVE-2014-9442 2024-11-21 11:20 2015-01-3 Show GitHub Exploit DB Packet Storm
285672 - lightbox_photo_gallery_project lightbox_photo_gallery Multiple cross-site request forgery (CSRF) vulnerabilities in the Lightbox Photo Gallery plugin 1.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests th… CWE-352
 Origin Validation Error
CVE-2014-9441 2024-11-21 11:20 2015-01-3 Show GitHub Exploit DB Packet Storm
285673 - phpmyrecipes_project phpmyrecipes SQL injection vulnerability in browse.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL commands via the category parameter. CWE-89
SQL Injection
CVE-2014-9440 2024-11-21 11:20 2015-01-3 Show GitHub Exploit DB Packet Storm
285674 - efssoft easy_file_sharing_web_server Cross-site scripting (XSS) vulnerability in Easy File Sharing Web Server 6.8 allows remote attackers to inject arbitrary web script or HTML via the username field during registration, which is not pr… CWE-79
Cross-site Scripting
CVE-2014-9439 2024-11-21 11:20 2015-01-3 Show GitHub Exploit DB Packet Storm
285675 - vbulletin vbulletin Cross-site request forgery (CSRF) vulnerability in the Moderator Control Panel in vBulletin 4.2.2 allows remote attackers to hijack the authentication of administrators for requests that (1) ban a us… CWE-352
 Origin Validation Error
CVE-2014-9438 2024-11-21 11:20 2015-01-3 Show GitHub Exploit DB Packet Storm
285676 - sliding_social_icons_project sliding_social_icons Multiple cross-site request forgery (CSRF) vulnerabilities in the Sliding Social Icons plugin 1.61 for WordPress allow remote attackers to hijack the authentication of administrators for requests tha… CWE-352
 Origin Validation Error
CVE-2014-9437 2024-11-21 11:20 2015-01-3 Show GitHub Exploit DB Packet Storm
285677 - sysaid sysaid Absolute path traversal vulnerability in SysAid On-Premise before 14.4.2 allows remote attackers to read arbitrary files via a \\\\ (four backslashes) in the fileName parameter to getRdsLogFile. CWE-22
Path Traversal
CVE-2014-9436 2024-11-21 11:20 2015-01-3 Show GitHub Exploit DB Packet Storm
285678 - absolutengine absolut_engine Multiple SQL injection vulnerabilities in Absolut Engine 1.73 allow remote authenticated users to execute arbitrary SQL commands via the (1) sectionID parameter to admin/managersection.php, (2) userI… CWE-89
SQL Injection
CVE-2014-9435 2024-11-21 11:20 2015-01-3 Show GitHub Exploit DB Packet Storm
285679 - absolutengine absolut_engine Cross-site scripting (XSS) vulnerability in admin/managerrelated.php in the administrative backend in Absolut Engine 1.73 allows remote authenticated users to inject arbitrary web script or HTML via … CWE-79
Cross-site Scripting
CVE-2014-9434 2024-11-21 11:20 2015-01-3 Show GitHub Exploit DB Packet Storm
285680 - contenido contendio Multiple cross-site scripting (XSS) vulnerabilities in cms/front_content.php in Contenido before 4.9.6, when advanced mod rewrite (AMR) is disabled, allow remote attackers to inject arbitrary web scr… CWE-79
Cross-site Scripting
CVE-2014-9433 2024-11-21 11:20 2015-01-1 Show GitHub Exploit DB Packet Storm