Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 13, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
196441 6.1 警告
Network
IBM - IBM iNotes におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-5883 2017-03-13 16:01 2016-06-29 Show GitHub Exploit DB Packet Storm
196442 7.5 重要
Network
Linux - Linux Kernel の net/ipv4/tcp.c の tcp_splice_read 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2017-6214 2017-03-13 15:53 2017-02-18 Show GitHub Exploit DB Packet Storm
196443 7.8 重要
Local
Linux - Linux Kernel の ipc/shm.c の do_shmat 関数におけるゼロページをマップされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2017-5669 2017-03-13 15:53 2017-02-8 Show GitHub Exploit DB Packet Storm
196444 8.8 重要
Local
シスコシステムズ - Cisco UCS Director の Web ベースの GUI における権限を昇格される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2017-3801 2017-03-13 15:49 2017-02-15 Show GitHub Exploit DB Packet Storm
196445 8.8 重要
Network
Smartlink Network Systems Ltd. - DIGISOL DG-HR1400 Wireless Router のファームウェアのアクセスポータルにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2017-6127 2017-03-13 15:49 2017-02-23 Show GitHub Exploit DB Packet Storm
196446 6.7 警告
Local
VCE Company, LLC. - VCE Vision Intelligent Operations の System Library における認証情報を取得される脆弱性 CWE-310
暗号の問題
CVE-2015-4056 2017-03-13 15:48 2015-06-17 Show GitHub Exploit DB Packet Storm
196447 5.4 警告
Network
トレンドマイクロ - Trend Micro InterScan Web Security Virtual Appliance における格納型クロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-9316 2017-03-13 15:38 2016-11-14 Show GitHub Exploit DB Packet Storm
196448 7.8 重要
Local
トレンドマイクロ - Trend Micro InterScan Web Security Virtual Appliance における重要な情報を公開される脆弱性 CWE-200
情報漏えい
CVE-2016-9314 2017-03-13 15:38 2016-11-14 Show GitHub Exploit DB Packet Storm
196449 9.9 緊急
Network
トレンドマイクロ - Trend Micro Interscan Web Security Virtual Appliance におけるリモートでコマンドを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-9269 2017-03-13 15:38 2016-11-10 Show GitHub Exploit DB Packet Storm
196450 9.8 緊急
Network
デル - Dell SonicWALL Secure Remote Access サーバの Web 管理インターフェースにおけるリモートコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2016-9684 2017-03-13 15:37 2016-11-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
347861 - info-zip unzip Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via filenames in the archive that begin with the '/' (slash) character. NVD-CWE-Other
CVE-2001-1269 2010-05-25 13:10 2001-07-12 Show GitHub Exploit DB Packet Storm
347862 - xfree86_project xfree86_x_server dexconf in XFree86 Xserver 4.1.0-2 creates the /dev/dri directory with insecure permissions (666), which allows local users to replace or create files in the root file system. NVD-CWE-Other
CVE-2001-1409 2010-05-25 13:10 2003-07-24 Show GitHub Exploit DB Packet Storm
347863 - sebrac.webcindario migascms SQL injection vulnerability in function.php in MigasCMS 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the categorie parameter in a catalogo act… CWE-89
SQL Injection
CVE-2010-2012 2010-05-25 02:30 2010-05-25 Show GitHub Exploit DB Packet Storm
347864 - createch-group lisk_cms Cross-site scripting (XSS) vulnerability in cp/list_content.php in LiSK CMS 4.4 allows remote attackers to inject arbitrary web script or HTML via the cl or possibly id parameter. CWE-79
Cross-site Scripting
CVE-2010-2014 2010-05-25 02:30 2010-05-25 Show GitHub Exploit DB Packet Storm
347865 - createch-group lisk_cms Multiple SQL injection vulnerabilities in LiSK CMS 4.4 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in a view_inbox action to cp/cp_messages.php or (2) the id par… CWE-89
SQL Injection
CVE-2010-2015 2010-05-25 02:30 2010-05-25 Show GitHub Exploit DB Packet Storm
347866 - bukulokomedia lokomedia_cms Cross-site scripting (XSS) vulnerability in hasil-pencarian.html in Lokomedia CMS 1.4.1 and 2.0 allows remote attackers to inject arbitrary web script or HTML via the kata parameter. NOTE: some of t… CWE-79
Cross-site Scripting
CVE-2010-2017 2010-05-25 02:30 2010-05-25 Show GitHub Exploit DB Packet Storm
347867 - bukulokomedia lokomedia_cms SQL injection vulnerability in downlot.php in Lokomedia CMS 1.4.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the file parameter. NOTE: the prov… CWE-89
SQL Injection
CVE-2010-2019 2010-05-25 02:30 2010-05-25 Show GitHub Exploit DB Packet Storm
347868 - apple java Apple Java for Mac OS X 10.5 before Update 7 and Java for Mac OS X 10.6 before Update 2 do not properly handle mediaLibImage objects, which allows remote attackers to execute arbitrary code or cause … CWE-399
 Resource Management Errors
CVE-2010-0538 2010-05-24 13:00 2010-05-22 Show GitHub Exploit DB Packet Storm
347869 - apple java_1.5
java_1.6
Integer signedness error in the window drawing implementation in Apple Java for Mac OS X 10.5 before Update 7 and Java for Mac OS X 10.6 before Update 2 allows remote attackers to execute arbitrary c… CWE-189
Numeric Errors
CVE-2010-0539 2010-05-24 13:00 2010-05-22 Show GitHub Exploit DB Packet Storm
347870 - peter_hocherl com_tweetla Directory traversal vulnerability in the TweetLA (com_tweetla) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. CWE-22
Path Traversal
CVE-2010-1533 2010-05-24 13:00 2010-04-27 Show GitHub Exploit DB Packet Storm