Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 21, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
250551 4.9 警告 FreeBSD - FreeBSD の ffs_rdextattr 関数における整数オーバーフローの脆弱性 - CVE-2006-5824 2012-06-26 15:37 2006-11-9 Show GitHub Exploit DB Packet Storm
250552 7.5 危険 シトリックス・システムズ - ImaSystem.dll for Citrix MetaFrame XP および Presentation Server におけるヒープベースのバッファオーバーフローの脆弱性 - CVE-2006-5821 2012-06-26 15:37 2006-11-8 Show GitHub Exploit DB Packet Storm
250553 9.3 危険 AOL - America Online Security Edition の Sb.SuperBuddy.1 の LinkSBIcons メソッドにおける任意のコードを実行される脆弱性 - CVE-2006-5820 2012-06-26 15:37 2007-04-2 Show GitHub Exploit DB Packet Storm
250554 7.5 危険 dmitry sheiko - BCWB における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5816 2012-06-26 15:37 2006-11-8 Show GitHub Exploit DB Packet Storm
250555 4.6 警告 シスコシステムズ - CSD のインストールにおける権限を取得される脆弱性 - CVE-2006-5808 2012-06-26 15:37 2006-11-8 Show GitHub Exploit DB Packet Storm
250556 4.6 警告 シスコシステムズ - CSD における安全なデスクトップ環境から逃避される脆弱性 - CVE-2006-5807 2012-06-26 15:37 2006-11-8 Show GitHub Exploit DB Packet Storm
250557 2.1 注意 シスコシステムズ - Cisco Secure Desktop の SSL VPN Client における暗号化されていないデータを読まれる脆弱性 - CVE-2006-5806 2012-06-26 15:37 2006-11-8 Show GitHub Exploit DB Packet Storm
250558 7.5 危険 advanced guestbook - Advanced Guestbook の admin.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5804 2012-06-26 15:37 2006-11-8 Show GitHub Exploit DB Packet Storm
250559 7.5 危険 e107.org - e107 の class2.php におけるディレクトリトラバーサルの脆弱性 - CVE-2006-5786 2012-06-26 15:37 2006-11-7 Show GitHub Exploit DB Packet Storm
250560 7.5 危険 creasito - Creasito E-Commerce Content Manager における認証を回避される脆弱性 - CVE-2006-5777 2012-06-26 15:37 2006-11-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 21, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
247281 5.9 MEDIUM
Network
axtls_project axtls In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification does not reject excess data after the hash value. Consequently, a remote attacker can forge signatu… CWE-347
 Improper Verification of Cryptographic Signature
CVE-2018-16150 2024-11-21 12:52 2018-11-8 Show GitHub Exploit DB Packet Storm
247282 5.9 MEDIUM
Network
axtls_project axtls In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification blindly trusts the declared lengths in the ASN.1 structure. Consequently, when small public exponen… CWE-347
 Improper Verification of Cryptographic Signature
CVE-2018-16149 2024-11-21 12:52 2018-11-8 Show GitHub Exploit DB Packet Storm
247283 7.5 HIGH
Network
knight_project knight A Path Traversal in Knightjs versions <= 0.0.1 allows an attacker to read content of arbitrary files on a remote server. CWE-22
Path Traversal
CVE-2018-16475 2024-11-21 12:52 2018-11-7 Show GitHub Exploit DB Packet Storm
247284 6.1 MEDIUM
Network
tianma-static_project tianma-static A stored xss in tianma-static module versions <=1.0.4 allows an attacker to execute arbitrary javascript. CWE-79
Cross-site Scripting
CVE-2018-16474 2024-11-21 12:52 2018-11-7 Show GitHub Exploit DB Packet Storm
247285 5.3 MEDIUM
Network
takeapeek_project takeapeek A path traversal in takeapeek module versions <=0.2.2 allows an attacker to list directory and files. CWE-22
Path Traversal
CVE-2018-16473 2024-11-21 12:52 2018-11-7 Show GitHub Exploit DB Packet Storm
247286 7.5 HIGH
Network
cached-path-relative_project
debian
cached-path-relative
debian_linux
A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype … CWE-20
 Improper Input Validation 
CVE-2018-16472 2024-11-21 12:52 2018-11-7 Show GitHub Exploit DB Packet Storm
247287 7.5 HIGH
Network
merge_project merge The merge.recursive function in the merge package <1.2.1 can be tricked into adding or modifying properties of the Object prototype. These properties will be present on all objects allowing for a den… CWE-20
 Improper Input Validation 
CVE-2018-16469 2024-11-21 12:52 2018-10-31 Show GitHub Exploit DB Packet Storm
247288 5.4 MEDIUM
Network
loofah_project
debian
loofah
debian_linux
In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. CWE-79
Cross-site Scripting
CVE-2018-16468 2024-11-21 12:52 2018-10-31 Show GitHub Exploit DB Packet Storm
247289 5.3 MEDIUM
Network
nextcloud nextcloud_server A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file password protected shares. CWE-287
Improper Authentication
CVE-2018-16467 2024-11-21 12:52 2018-10-31 Show GitHub Exploit DB Packet Storm
247290 8.1 HIGH
Network
nextcloud nextcloud_server Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess tokens. CWE-273
 Improper Check for Dropped Privileges
CVE-2018-16466 2024-11-21 12:52 2018-10-31 Show GitHub Exploit DB Packet Storm