Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
244131 5.1 警告 MODX - Modx CMS における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5730 2012-09-25 15:36 2006-11-6 Show GitHub Exploit DB Packet Storm
244132 2.1 注意 mirabilis - ICQ の "Answering Service" 関数におけるヒープベースのバッファオーバーフローの脆弱性 - CVE-2006-5724 2012-09-25 15:36 2006-11-3 Show GitHub Exploit DB Packet Storm
244133 5.1 警告 middlebury college - Segue CMS における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5722 2012-09-25 15:36 2006-11-3 Show GitHub Exploit DB Packet Storm
244134 4.3 警告 mirapoint - Mirapoint WebMail におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-5712 2012-09-25 15:36 2006-11-3 Show GitHub Exploit DB Packet Storm
244135 7.2 危険 The PHP Group - PHP における open_basedir 制限を回避される脆弱性 CWE-noinfo
情報不足
CVE-2006-5706 2012-09-25 15:36 2006-11-3 Show GitHub Exploit DB Packet Storm
244136 6.2 警告 ヒューレット・パッカード - HP NonStop Server における任意のファイルを読まれる脆弱性 - CVE-2006-5704 2012-09-25 15:36 2006-10-26 Show GitHub Exploit DB Packet Storm
244137 4.9 警告 Linux
レッドハット
- Fedora Core 5 などで使用される Linux kernel におけるメモリ二重解放の脆弱性 - CVE-2006-5701 2012-09-25 15:36 2006-11-3 Show GitHub Exploit DB Packet Storm
244138 10 危険 Pentaho Corporation - Pentaho BI Suite における脆弱性 - CVE-2006-5675 2012-09-25 15:36 2006-11-2 Show GitHub Exploit DB Packet Storm
244139 7.5 危険 miniBB - miniBB における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5674 2012-09-25 15:36 2006-11-2 Show GitHub Exploit DB Packet Storm
244140 6.8 警告 miniBB - miniBB の bb_func_txt.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5673 2012-09-25 15:36 2006-11-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 28, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
253291 9.8 CRITICAL
Network
quest kace_system_management_appliance The 'reportID' parameter received by the '/common/run_report.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injection (in particular, an error-base… CWE-89
SQL Injection
CVE-2018-11140 2024-11-21 12:42 2018-06-1 Show GitHub Exploit DB Packet Storm
253292 8.8 HIGH
Network
quest kace_system_management_appliance The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticated user and can be abused to execute arbitrary commands on th… CWE-78
OS Command 
CVE-2018-11139 2024-11-21 12:42 2018-06-1 Show GitHub Exploit DB Packet Storm
253293 9.8 CRITICAL
Network
quest kace_system_management_appliance The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system. CWE-78
OS Command 
CVE-2018-11138 2024-11-21 12:42 2018-06-1 Show GitHub Exploit DB Packet Storm
253294 6.5 MEDIUM
Network
quest kace_system_management_appliance The 'checksum' parameter of the '/common/download_attachment.php' script in the Quest KACE System Management Appliance 8.0.318 can be abused to read arbitrary files with 'www' privileges via Director… CWE-22
Path Traversal
CVE-2018-11137 2024-11-21 12:42 2018-06-1 Show GitHub Exploit DB Packet Storm
253295 9.8 CRITICAL
Network
quest kace_system_management_appliance The 'orgID' parameter received by the '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injection (in particular, a … CWE-89
SQL Injection
CVE-2018-11136 2024-11-21 12:42 2018-06-1 Show GitHub Exploit DB Packet Storm
253296 8.8 HIGH
Network
quest kace_system_management_appliance The script '/adminui/error_details.php' in the Quest KACE System Management Appliance 8.0.318 allows authenticated users to conduct PHP object injection attacks. CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2018-11135 2024-11-21 12:42 2018-06-1 Show GitHub Exploit DB Packet Storm
253297 8.8 HIGH
Network
quest kace_system_management_appliance In order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue managed that runs with root privileges and only allows a set … CWE-640
 Weak Password Recovery Mechanism for Forgotten Password
CVE-2018-11134 2024-11-21 12:42 2018-06-1 Show GitHub Exploit DB Packet Storm
253298 6.1 MEDIUM
Network
quest kace_system_management_appliance The 'fmt' parameter of the '/common/run_cross_report.php' script in the the Quest KACE System Management Appliance 8.0.318 is vulnerable to cross-site scripting. CWE-79
Cross-site Scripting
CVE-2018-11133 2024-11-21 12:42 2018-06-1 Show GitHub Exploit DB Packet Storm
253299 8.8 HIGH
Network
quest kace_system_management_appliance In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue that runs daemonized with root privileges and only allows a se… CWE-78
OS Command 
CVE-2018-11132 2024-11-21 12:42 2018-06-1 Show GitHub Exploit DB Packet Storm
253300 8.8 HIGH
Network
bitmain antminer_d3_firmware
antminer_l3\+_firmware
antminer_s9_firmware
Bitmain Antminer D3, L3+, and S9 devices allow Remote Command Execution via the system restore function. NVD-CWE-noinfo
CVE-2018-11220 2024-11-21 12:42 2018-06-1 Show GitHub Exploit DB Packet Storm