Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 24, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
251271 7.5 危険 2X Software - 2X ThinClientServer Enterprise Edition における特権アカウントを生成される脆弱性 - CVE-2006-6221 2012-06-26 15:38 2006-12-9 Show GitHub Exploit DB Packet Storm
251272 6.8 警告 dev4u - dev4u CMS の index.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6219 2012-06-26 15:38 2006-11-30 Show GitHub Exploit DB Packet Storm
251273 7.5 危険 dev4u - dev4u CMS の index.php における SQL インジェクションの脆弱性 - CVE-2006-6218 2012-06-26 15:38 2006-11-30 Show GitHub Exploit DB Packet Storm
251274 6.8 警告 BirdBlog - BirdBlog におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6211 2012-06-26 15:38 2006-11-30 Show GitHub Exploit DB Packet Storm
251275 7.5 危険 enthrallweb - Enthrallweb eClassifieds における SQL インジェクションの脆弱性 - CVE-2006-6208 2012-06-26 15:38 2006-11-30 Show GitHub Exploit DB Packet Storm
251276 6.8 警告 enthrallweb - Enthrallweb eHomes の result.asp におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6205 2012-06-26 15:38 2006-11-30 Show GitHub Exploit DB Packet Storm
251277 7.5 危険 enthrallweb - Enthrallweb eHomes における SQL インジェクションの脆弱性 - CVE-2006-6204 2012-06-26 15:38 2006-11-30 Show GitHub Exploit DB Packet Storm
251278 7.5 危険 Borland Software Corporation
revilloc
- RevilloC MailServer などの製品で使用される Borland idsql32.dll におけるヒープベースのバッファオーバーフローの脆弱性 - CVE-2006-6201 2012-06-26 15:38 2006-11-30 Show GitHub Exploit DB Packet Storm
251279 7.5 危険 francisco burzi - Francisco Burzi PHP-Nuke の News モジュールにおける SQL インジェクションの脆弱性 - CVE-2006-6200 2012-06-26 15:38 2006-11-30 Show GitHub Exploit DB Packet Storm
251280 7.5 危険 blazevideo - BlazeVideo BlazeDVD Standard および Professional におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2006-6199 2012-06-26 15:38 2006-11-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 24, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
247011 5.4 MEDIUM
Network
feindura feindura feindura 2.0.7 allows XSS via the tags field of a new page created at index.php?category=0&page=new. CWE-79
Cross-site Scripting
CVE-2018-16728 2024-11-21 12:53 2018-09-13 Show GitHub Exploit DB Packet Storm
247012 5.4 MEDIUM
Network
razorcms razorcms razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component. CWE-79
Cross-site Scripting
CVE-2018-16727 2024-11-21 12:53 2018-09-13 Show GitHub Exploit DB Packet Storm
247013 5.4 MEDIUM
Network
razorcms razorcms razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component. CWE-79
Cross-site Scripting
CVE-2018-16726 2024-11-21 12:53 2018-09-13 Show GitHub Exploit DB Packet Storm
247014 5.4 MEDIUM
Network
dlink dir-600m_firmware D-Link DIR-600M devices allow XSS via the Hostname and Username fields in the Dynamic DNS Configuration page. CWE-79
Cross-site Scripting
CVE-2018-16605 2024-11-21 12:53 2018-09-13 Show GitHub Exploit DB Packet Storm
247015 6.5 MEDIUM
Adjacent
inteno dg400_firmware Inteno DG400 WU7U_ELION3.11.6-170614_1328 devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets with random MAC addresses, as demonstrated by macof. NVD-CWE-noinfo
CVE-2018-16950 2024-11-21 12:53 2018-09-12 Show GitHub Exploit DB Packet Storm
247016 8.0 HIGH
Network
xunfeng_project xunfeng xunfeng 0.2.0 allows command execution via CSRF because masscan.py mishandles backquote characters, a related issue to CVE-2018-16832. CWE-352
 Origin Validation Error
CVE-2018-16951 2024-11-21 12:53 2018-09-12 Show GitHub Exploit DB Packet Storm
247017 7.5 HIGH
Network
openafs
debian
openafs
debian_linux
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several data types used as RPC input variables were implemented as unbounded array types, limited only by the inherent 32-bit … CWE-400
 Uncontrolled Resource Consumption
CVE-2018-16949 2024-11-21 12:53 2018-09-12 Show GitHub Exploit DB Packet Storm
247018 7.5 HIGH
Network
openafs
debian
openafs
debian_linux
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several RPC server routines did not fully initialize their output variables before returning, leaking memory contents from bot… CWE-200
Information Exposure
CVE-2018-16948 2024-11-21 12:53 2018-09-12 Show GitHub Exploit DB Packet Storm
247019 9.8 CRITICAL
Network
openafs
debian
openafs
debian_linux
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accepts incoming RPCs but does not require (or allow for) authentication of those RP… CWE-287
Improper Authentication
CVE-2018-16947 2024-11-21 12:53 2018-09-12 Show GitHub Exploit DB Packet Storm
247020 7.5 HIGH
Network
lg lnb5110_firmware
lnb5320_firmware
lnb5320r_firmware
lnb7210_firmware
lnd3230r_firmware
lnd5110_firmware
lnd5110r_firmware
lnd5220r_firmware
lnd7210_firmware
lnd7210r_firmwa…
LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log & Report) files and download backup files (via down… CWE-552
 Files or Directories Accessible to External Parties
CVE-2018-16946 2024-11-21 12:53 2018-09-12 Show GitHub Exploit DB Packet Storm