Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
195511 9.8 緊急
Network
Zammad - Zammad における有効なセッション Cookie を持つユーザの REST API に対してクロスドメイン要求を直接送信される脆弱性 CWE-284
不適切なアクセス制御
CVE-2017-6080 2017-04-3 17:27 2017-02-14 Show GitHub Exploit DB Packet Storm
195512 6.1 警告
Network
Zammad - Zammad におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-5621 2017-04-3 17:27 2017-02-14 Show GitHub Exploit DB Packet Storm
195513 6.1 警告
Network
Zammad - Zammad におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-5620 2017-04-3 17:27 2017-02-14 Show GitHub Exploit DB Packet Storm
195514 9.8 緊急
Network
Zammad - Zammad におけるハッシュ化されたパスワード自体でログインされる脆弱性 CWE-255
証明書・パスワード管理
CVE-2017-5619 2017-04-3 17:27 2017-02-14 Show GitHub Exploit DB Packet Storm
195515 6.1 警告
Network
UNINETT - mod_auth_mellon におけるクロスサイトセッション転送攻撃 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-6807 2017-04-3 17:13 2017-03-13 Show GitHub Exploit DB Packet Storm
195516 9.8 緊急
Network
OnePlus - OnePlus 3 および 3T 上で稼動する OxygenOS における任意のコードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2017-5626 2017-04-3 17:08 2017-02-8 Show GitHub Exploit DB Packet Storm
195517 9.8 緊急
Network
OnePlus - OnePlus 3 および 3T 用 OxygenOS における任意のコードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2017-5624 2017-04-3 17:08 2017-02-8 Show GitHub Exploit DB Packet Storm
195518 8.8 重要
Network
Keekoonvision Technology Co., Ltd - Keekoon KK002 デバイス HD におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2017-6180 2017-04-3 17:06 2017-02-21 Show GitHub Exploit DB Packet Storm
195519 7.5 重要
Network
MikroTik - MikroTik Router hAP Lite におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2017-6444 2017-04-3 16:56 2017-03-2 Show GitHub Exploit DB Packet Storm
195520 6.8 警告
Adjacent
エマソン - Emerson DeltaV Easy Security Management における権限を昇格される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-9345 2017-04-3 16:52 2016-11-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
347171 - squid-cache squid Per: http://cwe.mitre.org/data/definitions/476.html 'NULL Pointer Dereference' NVD-CWE-Other
CVE-2010-0639 2010-08-2 13:00 2010-02-16 Show GitHub Exploit DB Packet Storm
347172 - mediawiki mediawiki Cross-site scripting (XSS) vulnerability in MediaWiki 1.15 before 1.15.4 and 1.16 before 1.16 beta 3 allows remote attackers to inject arbitrary web script or HTML via crafted Cascading Style Sheets … CWE-79
Cross-site Scripting
CVE-2010-1647 2010-07-30 14:48 2010-06-8 Show GitHub Exploit DB Packet Storm
347173 - mediawiki mediawiki Cross-site request forgery (CSRF) vulnerability in the login interface in MediaWiki 1.15 before 1.15.4 and 1.16 before 1.16 beta 3 allows remote attackers to hijack the authentication of users for re… CWE-352
 Origin Validation Error
CVE-2010-1648 2010-07-30 14:48 2010-06-8 Show GitHub Exploit DB Packet Storm
347174 - openx openx Unspecified vulnerability in OpenX 2.8.1 and 2.8.2 allows remote attackers to bypass authentication and obtain access to an Administrator account via unknown vectors, possibly related to www/admin/in… NVD-CWE-noinfo
CWE-287
Improper Authentication
CVE-2009-4830 2010-07-30 13:00 2010-04-28 Show GitHub Exploit DB Packet Storm
347175 - cisco ios Unspecified vulnerability in Cisco IOS 12.4, when NAT SCCP fragmentation support is enabled, allows remote attackers to cause a denial of service (device reload) via crafted Skinny Client Control Pro… NVD-CWE-noinfo
CVE-2010-0584 2010-07-13 14:50 2010-03-26 Show GitHub Exploit DB Packet Storm
347176 - frank-karau phpfk_php_forum Cross-site scripting (XSS) vulnerability in search.php in phpFK PHP Forum ohne 7.0.4 allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: the provenance of … CWE-79
Cross-site Scripting
CVE-2009-4677 2010-07-13 14:48 2010-03-9 Show GitHub Exploit DB Packet Storm
347177 - gnome screensaver gnome-screensaver 2.28.0 does not resume adherence to its activation settings after an inhibiting application becomes unavailable on the session bus, which allows physically proximate attackers to ac… NVD-CWE-Other
CVE-2009-4641 2010-07-7 13:00 2010-02-12 Show GitHub Exploit DB Packet Storm
347178 - tim_lochmueller mydashboard Cross-site scripting (XSS) vulnerability in the myDashboard (mydashboard) extension 0.1.13 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2010-1011 2010-06-25 13:00 2010-03-20 Show GitHub Exploit DB Packet Storm
347179 - fr.simon_rundell pd_diocesedatabase SQL injection vulnerability in the Diocese of Portsmouth Database (pd_diocesedatabase) extension before 0.7.13 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vect… CWE-89
SQL Injection
CVE-2010-1013 2010-06-25 13:00 2010-03-20 Show GitHub Exploit DB Packet Storm
347180 - laurent_foulloy sav_filter_abc SQL injection vulnerability in the SAV Filter Alphabetic (sav_filter_abc) extension before 1.0.9 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. CWE-89
SQL Injection
CVE-2010-1015 2010-06-24 13:00 2010-03-20 Show GitHub Exploit DB Packet Storm