Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
203811 7.8 重要
Local
The Go Project - Windows 上で稼動する Go における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-3958 2016-05-27 15:54 2016-04-2 Show GitHub Exploit DB Packet Storm
203812 7.4 重要
Network
トレンドマイクロ - Apple iOS 用 Trend Micro Mobile Security におけるモバイルアプリケーションのログインサーバになりすまされる脆弱性 CWE-200
情報漏えい
CVE-2016-3664 2016-05-27 15:03 2016-04-22 Show GitHub Exploit DB Packet Storm
203813 6.3 警告
Network
エヌ・ティ・ティ・ブロードバンドプラットフォーム株式会社 - Japan Connected-free Wi-Fi におけるアクセス制限不備の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-5629 2016-05-27 12:12 2015-09-11 Show GitHub Exploit DB Packet Storm
203814 7.5 重要
Adjacent
Huawei - 複数の Huawei デバイス製品のソフトウェアの Smart DNS 機能におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-4577 2016-05-27 11:23 2016-05-11 Show GitHub Exploit DB Packet Storm
203815 9.8 緊急
Network
Huawei - 複数の Huawei デバイス製品のソフトウェアの Application Specific Packet Filtering 機能におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-4576 2016-05-27 11:23 2016-05-11 Show GitHub Exploit DB Packet Storm
203816 8.1 重要
Network
Huawei - Huawei S12700 および S5700 スイッチのソフトウェアにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2016-4087 2016-05-27 11:23 2016-04-27 Show GitHub Exploit DB Packet Storm
203817 7.8 重要
Local
Huawei - Huawei Mobile Broadband HL Service における SYSTEM 権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-2855 2016-05-27 11:23 2016-05-12 Show GitHub Exploit DB Packet Storm
203818 4.4 警告
Local
Fabrice Bellard
Fedora Project
- QEMU の hw/usb/hcd-ehci.c の ehci_advance_state 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2016-4037 2016-05-27 10:08 2016-04-19 Show GitHub Exploit DB Packet Storm
203819 6.5 警告
Local
Fabrice Bellard - QEMU の hw/i386/kvmvapic.c の patch_instruction 関数におけるホストスタックメモリから重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-4020 2016-05-27 10:08 2016-05-23 Show GitHub Exploit DB Packet Storm
203820 5.9 警告
Network
Fabrice Bellard
Fedora Project
- QEMU の hw/net/stellaris_enet.c の stellaris_enet_receive 関数におけるバッファオーバーフローの脆弱性 CWE-20
不適切な入力確認
CVE-2016-4001 2016-05-27 10:08 2016-04-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 20, 2026, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
349331 - efrontlearning efront SQL injection vulnerability in ask_chat.php in eFront 3.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the chatrooms_ID parameter. CWE-89
SQL Injection
CVE-2010-1918 2010-05-13 04:36 2010-05-12 Show GitHub Exploit DB Packet Storm
349332 - gnustep gnustep_base Tools/gdomap.c in gdomap in GNUstep Base before 1.20.0 allows local users to read arbitrary files via a (1) -c or (2) -a option, which prints file contents in an error message. CWE-200
Information Exposure
CVE-2010-1457 2010-05-12 20:46 2010-05-12 Show GitHub Exploit DB Packet Storm
349333 - tufat flashcard Cross-site scripting (XSS) vulnerability in cPlayer.php in FlashCard 2.6.5 and 3.0.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: some of these details … CWE-79
Cross-site Scripting
CVE-2010-1872 2010-05-12 20:46 2010-05-12 Show GitHub Exploit DB Packet Storm
349334 - abcbackup
internet-soft
abc_backup
urgent_backup
Stack-based buffer overflow in (1) Urgent Backup 3.20, and (2) ABC Backup Pro 5.20 and ABC Backup 5.50, allows user-assisted remote attackers to execute arbitrary code via a crafted ZIP archive. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-1686 2010-05-12 09:41 2010-05-5 Show GitHub Exploit DB Packet Storm
349335 - turnkeyforms yahoo-answers-clone Cross-site scripting (XSS) vulnerability in questiondetail.php in Yahoo Answers Clone allows remote attackers to inject arbitrary web script or HTML via the questionid parameter. CWE-79
Cross-site Scripting
CVE-2009-4858 2010-05-11 21:02 2010-05-11 Show GitHub Exploit DB Packet Storm
349336 - onlinetechtools.com owos_lite Multiple cross-site scripting (XSS) vulnerabilities in Online Work Order Suite (OWOS) Lite Edition 3.10 allow remote attackers to inject arbitrary web script or HTML via the show parameter to (1) def… CWE-79
Cross-site Scripting
CVE-2009-4859 2010-05-11 21:02 2010-05-11 Show GitHub Exploit DB Packet Storm
349337 - supportpro supportdesk Cross-site scripting (XSS) vulnerability in shownews.php in SupportPRO SupportDesk 3.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. CWE-79
Cross-site Scripting
CVE-2009-4861 2010-05-11 21:02 2010-05-11 Show GitHub Exploit DB Packet Storm
349338 - hitronsoft answer_me Cross-site scripting (XSS) vulnerability in Hitron Soft Answer Me 1.0 allows remote attackers to inject arbitrary web script or HTML via the q_id parameter to the answers script (aka answers.php). N… CWE-79
Cross-site Scripting
CVE-2009-4868 2010-05-11 21:02 2010-05-11 Show GitHub Exploit DB Packet Storm
349339 - hitronsoft nasim_guest_book Cross-site scripting (XSS) vulnerability in index.php in Nasim Guest Book 1.2 allows remote attackers to inject arbitrary web script or HTML via the page parameter. CWE-79
Cross-site Scripting
CVE-2009-4869 2010-05-11 21:02 2010-05-11 Show GitHub Exploit DB Packet Storm
349340 - openttd openttd OpenTTD before 1.0.1 accepts a company password for authentication in response to a request for the server password, which allows remote authenticated users to bypass intended access restrictions or … CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-0401 2010-05-11 13:00 2010-05-5 Show GitHub Exploit DB Packet Storm