Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":July 1, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
252151 7.5 危険 brian drawert - Brian Drawert yaplap の ldap.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-6575 2012-06-26 15:38 2006-12-15 Show GitHub Exploit DB Packet Storm
252152 6 警告 シトリックス・システムズ - Citrix Access Gateway Advanced Edition および Citrix Access Gateway Advanced Edition with AAC におけるデータへのアクセス権を取得される脆弱性 - CVE-2006-6573 2012-06-26 15:38 2006-11-4 Show GitHub Exploit DB Packet Storm
252153 6.5 警告 シトリックス・システムズ - Citrix AAC Option および Access Gateway with Advanced Access Control におけるアクセスポリシーを回避される脆弱性 - CVE-2006-6572 2012-06-26 15:38 2006-11-4 Show GitHub Exploit DB Packet Storm
252154 6.8 警告 genesistrader - GenesisTrader の form.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6571 2012-06-26 15:38 2006-12-15 Show GitHub Exploit DB Packet Storm
252155 7.5 危険 genesistrader - GenesisTrader の upload.php における任意のファイルをアップロードされる脆弱性 - CVE-2006-6570 2012-06-26 15:38 2006-12-15 Show GitHub Exploit DB Packet Storm
252156 7.8 危険 genesistrader - GenesisTrader の form.php における重要な情報を取得される脆弱性 - CVE-2006-6569 2012-06-26 15:38 2006-12-15 Show GitHub Exploit DB Packet Storm
252157 4 警告 FileZilla - FileZilla Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-DesignError
CVE-2006-6565 2012-06-26 15:38 2006-12-15 Show GitHub Exploit DB Packet Storm
252158 4 警告 FileZilla - FileZilla Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2006-6564 2012-06-26 15:38 2006-12-15 Show GitHub Exploit DB Packet Storm
252159 5 警告 crob - Crob FTP Server におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2006-6558 2012-06-26 15:38 2006-12-14 Show GitHub Exploit DB Packet Storm
252160 7.5 危険 eyeOS Project - EyeOS の apps/eyeHome.eyeapp/aplic.php の eyeHome 関数における任意のコードを実行される脆弱性 - CVE-2006-6556 2012-06-26 15:38 2006-12-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:July 1, 2026, 4:27 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
246441 5.3 MEDIUM
Network
stackstorm stackstorm Incorrect access control in StackStorm API (st2api) in StackStorm before 2.9.2 and 2.10.x before 2.10.1 allows an attacker (who has a StackStorm account and is authenticated against the StackStorm AP… NVD-CWE-noinfo
CVE-2018-20345 2024-11-21 13:01 2018-12-22 Show GitHub Exploit DB Packet Storm
246442 6.8 MEDIUM
Physics
floureon sp012 The Floureon IP Camera SP012 provides a root terminal on a UART serial interface without proper access control. This allows attackers with physical access to execute arbitrary commands with root priv… CWE-287
Improper Authentication
CVE-2018-20342 2024-11-21 13:01 2018-12-22 Show GitHub Exploit DB Packet Storm
246443 6.1 MEDIUM
Network
zohocorp manageengine_opmanager Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section. CWE-79
Cross-site Scripting
CVE-2018-20339 2024-11-21 13:01 2018-12-21 Show GitHub Exploit DB Packet Storm
246444 9.8 CRITICAL
Network
zohocorp manageengine_opmanager Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section. CWE-89
SQL Injection
CVE-2018-20338 2024-11-21 13:01 2018-12-21 Show GitHub Exploit DB Packet Storm
246445 8.8 HIGH
Network
libraw libraw There is a stack-based buffer overflow in the parse_makernote function of dcraw_common.cpp in LibRaw 0.19.1. Crafted input will lead to a denial of service or possibly unspecified other impact. CWE-787
 Out-of-bounds Write
CVE-2018-20337 2024-11-21 13:01 2018-12-21 Show GitHub Exploit DB Packet Storm
246446 7.5 HIGH
Network
openwebif_project openwebif An issue has been discovered in the OpenWebif plugin through 1.2.4 for Enigma2 based devices. Reading of arbitrary files is possible with /file?action=download&file= followed by a full pathname, and … CWE-22
Path Traversal
CVE-2018-20332 2024-11-21 13:01 2018-12-21 Show GitHub Exploit DB Packet Storm
246447 8.8 HIGH
Network
libjpeg-turbo libjpeg-turbo The tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflow with a resultant heap-based buffer overflow via a BMP image because multiplication of pitch and height is mishandled, as demons… CWE-787
CWE-190
 Out-of-bounds Write
 Integer Overflow or Wraparound
CVE-2018-20330 2024-11-21 13:01 2018-12-21 Show GitHub Exploit DB Packet Storm
246448 8.1 HIGH
Network
chamilo chamilo_lms Chamilo LMS version 1.11.8 contains a main/inc/lib/CoursesAndSessionsCatalog.class.php SQL injection, allowing users with access to the sessions catalogue (which may optionally be made public) to ext… CWE-89
SQL Injection
CVE-2018-20329 2024-11-21 13:01 2018-12-21 Show GitHub Exploit DB Packet Storm
246449 5.4 MEDIUM
Network
chamilo chamilo_lms Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool, allowing authenticated users to affect other users, under specific conditions of permissions granted b… CWE-79
Cross-site Scripting
CVE-2018-20328 2024-11-21 13:01 2018-12-21 Show GitHub Exploit DB Packet Storm
246450 5.4 MEDIUM
Network
chamilo chamilo_lms Chamilo LMS version 1.11.8 contains XSS in main/template/default/admin/gradebook_list.tpl in the gradebook dependencies tool, allowing authenticated users to affect other users, under specific condit… CWE-79
Cross-site Scripting
CVE-2018-20327 2024-11-21 13:01 2018-12-21 Show GitHub Exploit DB Packet Storm