Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":July 1, 2026, 4:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
251181 4.3 警告 digiappz - Digirez におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-2880 2012-06-26 15:46 2007-05-29 Show GitHub Exploit DB Packet Storm
251182 4.3 警告 gnuturk - GTP GNUTurk Portal System の mods.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-2879 2012-06-26 15:46 2007-05-29 Show GitHub Exploit DB Packet Storm
251183 7.5 危険 devellion - CubeCart における SQL インジェクションの脆弱性 - CVE-2007-2862 2012-06-26 15:46 2007-05-24 Show GitHub Exploit DB Packet Storm
251184 6.5 警告 boastmachine - BoastMachine の user.php における権限を取得される脆弱性 - CVE-2007-2860 2012-06-26 15:46 2007-05-24 Show GitHub Exploit DB Packet Storm
251185 6.8 警告 Dart Communications - DartZip.dll の Dart Communications PowerTCP ZIP Compression ActiveX コントロールにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-2856 2012-06-26 15:46 2007-05-24 Show GitHub Exploit DB Packet Storm
251186 6.8 警告 Dart Communications - ActiveX 用の Dart ZipLite Compression の特定の ActiveX コントロールにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-2855 2012-06-26 15:46 2007-05-24 Show GitHub Exploit DB Packet Storm
251187 7.5 危険 bti-tracker - BtiTracker の account_change.php における SQL インジェクションの脆弱性 - CVE-2007-2854 2012-06-26 15:46 2007-05-24 Show GitHub Exploit DB Packet Storm
251188 9.3 危険 ESET - ESET NOD32 Antivirus におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-2852 2012-06-26 15:46 2007-05-24 Show GitHub Exploit DB Packet Storm
251189 10 危険 シトリックス・システムズ - Citrix MetaFrame Presentation Server などの製品で使用される XTE におけるネットワークセキュリティポリシーを回避される脆弱性 - CVE-2007-2850 2012-06-26 15:46 2007-05-23 Show GitHub Exploit DB Packet Storm
251190 9.3 危険 AVAST Software s.r.o. - avast! Anti-Virus Managed Client の SIS アンパッカーにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-2846 2012-06-26 15:46 2007-05-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:July 1, 2026, 4:27 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
247211 6.1 MEDIUM
Network
ibm websphere_portal IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality poten… CWE-79
Cross-site Scripting
CVE-2018-1483 2024-11-21 12:59 2018-04-12 Show GitHub Exploit DB Packet Storm
247212 9.8 CRITICAL
Network
vmware
oracle
spring_framework
primavera_gateway
application_testing_suite
retail_open_commerce_platform
communications_diameter_signaling_router
communications_performance_intelligence_center
in…
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STO… - CVE-2018-1275 2024-11-21 12:59 2018-04-11 Show GitHub Exploit DB Packet Storm
247213 9.8 CRITICAL
Network
pivotal_software
apache
oracle
spring_data_commons
spring_data_rest
ignite
financial_services_crime_and_compliance_management_studio
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An… CWE-74
Injection
CVE-2018-1273 2024-11-21 12:59 2018-04-11 Show GitHub Exploit DB Packet Storm
247214 9.8 CRITICAL
Network
dell emc_integrated_data_protection_appliance
emc_avamar
Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affected by a missing access control check vulnerabili… NVD-CWE-noinfo
CWE-862
 Missing Authorization
CVE-2018-1217 2024-11-21 12:59 2018-04-10 Show GitHub Exploit DB Packet Storm
247215 7.5 HIGH
Network
apache
debian
solr
debian_linux
This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be u… CWE-611
XXE
CVE-2018-1308 2024-11-21 12:59 2018-04-9 Show GitHub Exploit DB Packet Storm
247216 7.5 HIGH
Network
vmware
oracle
spring_framework
enterprise_manager_ops_center
primavera_gateway
application_testing_suite
retail_back_office
retail_open_commerce_platform
communications_diameter_signaling_router<…
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux se… NVD-CWE-noinfo
CVE-2018-1272 2024-11-21 12:59 2018-04-6 Show GitHub Exploit DB Packet Storm
247217 5.9 MEDIUM
Network
vmware
oracle
spring_framework
retail_xstore_point_of_service
enterprise_manager_ops_center
primavera_gateway
application_testing_suite
retail_back_office
retail_open_commerce_platform
communi…
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, imag… - CVE-2018-1271 2024-11-21 12:59 2018-04-6 Show GitHub Exploit DB Packet Storm
247218 9.8 CRITICAL
Network
vmware
oracle
redhat
debian
spring_framework
retail_xstore_point_of_service
enterprise_manager_ops_center
primavera_gateway
application_testing_suite
retail_back_office
retail_open_commerce_platform
communi…
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STO… - CVE-2018-1270 2024-11-21 12:59 2018-04-6 Show GitHub Exploit DB Packet Storm
247219 6.5 MEDIUM
Network
theforeman
redhat
foreman
satellite
An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an SQL injection attack on the back end database. CWE-89
SQL Injection
CVE-2018-1096 2024-11-21 12:59 2018-04-6 Show GitHub Exploit DB Packet Storm
247220 3.7 LOW
Network
apache hive In Apache Hive 2.1.0 to 2.3.2, when 'COPY FROM FTP' statement is run using HPL/SQL extension to Hive, a compromised/malicious FTP server can cause the file to be written to an arbitrary location on t… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2018-1315 2024-11-21 12:59 2018-04-5 Show GitHub Exploit DB Packet Storm