Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 15, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227391 4.3 警告 ravenphpscripts - RavenNuke の Your Account モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-0679 2012-12-20 19:10 2009-02-18 Show GitHub Exploit DB Packet Storm
227392 5 警告 ravenphpscripts - RavenNuke の images/captcha.php における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2009-0678 2012-12-20 19:10 2009-02-18 Show GitHub Exploit DB Packet Storm
227393 6.5 警告 ravenphpscripts - Raven Web Services RavenNuke の Your Account モジュールにおける任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2009-0677 2012-12-20 19:10 2009-02-18 Show GitHub Exploit DB Packet Storm
227394 6 警告 ravenphpscripts - Raven Web Services RavenNuke の images/captcha.php におけるローカルファイルの存在を特定される脆弱性 CWE-94
コード・インジェクション
CVE-2009-0674 2012-12-20 19:10 2009-02-18 Show GitHub Exploit DB Packet Storm
227395 6.5 警告 ravenphpscripts - Raven Web Services RavenNuke の Your Account モジュールにおける任意の PHP コードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2009-0673 2012-12-20 19:10 2009-02-18 Show GitHub Exploit DB Packet Storm
227396 6.5 警告 ravenphpscripts - Raven Web Services RavenNuke の Resend_Email モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0672 2012-12-20 19:10 2009-02-18 Show GitHub Exploit DB Packet Storm
227397 6 警告 Plone Foundation - Plone 用の PlonePAS 製品における任意のユーザの ID を取得される脆弱性 CWE-287
不適切な認証
CVE-2009-0662 2012-12-20 19:10 2009-04-21 Show GitHub Exploit DB Packet Storm
227398 5 警告 tptest - TPTEST の GetStatsFromLine 関数におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-0659 2012-12-20 19:10 2009-02-20 Show GitHub Exploit DB Packet Storm
227399 5.1 警告 The Tor Project - Tor における送信元および送信先間の通信を特定される脆弱性 CWE-Other
その他
CVE-2009-0654 2012-12-20 19:10 2009-02-20 Show GitHub Exploit DB Packet Storm
227400 10 危険 tptest - TPTEST の GetStatsFromLine 関数におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-0650 2012-12-20 19:10 2009-02-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 15, 2026, 4:28 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
275061 - sap netweaver_enterprise_portal XML external entity (XXE) vulnerability in ReportXmlViewer in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Not… NVD-CWE-Other
CVE-2015-2811 2024-11-21 11:28 2015-04-1 Show GitHub Exploit DB Packet Storm
275062 - debian
xen
fedoraproject
canonical
debian_linux
xen
fedora
ubuntu_linux
QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and … CWE-264
Permissions, Privileges, and Access Controls
CVE-2015-2756 2024-11-21 11:28 2015-04-1 Show GitHub Exploit DB Packet Storm
275063 - ab_google_map_travel_project ab_google_map_travel Multiple cross-site request forgery (CSRF) vulnerabilities in the AB Google Map Travel (AB-MAP) plugin before 4.0 for WordPress allow remote attackers to hijack the authentication of administrators f… CWE-352
 Origin Validation Error
CVE-2015-2755 2024-11-21 11:28 2015-04-1 Show GitHub Exploit DB Packet Storm
275064 - synology diskstation_manager The Multicast DNS (mDNS) responder in Synology DiskStation Manager (DSM) before 3.1 inadvertently responds to unicast queries with source addresses that are not link-local, which allows remote attack… CWE-200
Information Exposure
CVE-2015-2809 2024-11-21 11:28 2015-04-1 Show GitHub Exploit DB Packet Storm
275065 - oracle
debian
redhat
suse
opensuse
canonical
fujitsu
huawei
ibm
http_server
integrated_lights_out_manager_firmware
communications_application_session_controller
communications_policy_management
debian_linux
enterprise_linux_desktop
enterprise_li…
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to cond… CWE-327
 Use of a Broken or Risky Cryptographic Algorithm
CVE-2015-2808 2024-11-21 11:28 2015-04-1 Show GitHub Exploit DB Packet Storm
275066 - debian
gaia-gis
debian_linux
freexl
The parse_SST function in FreeXL before 1.0.0i allows remote attackers to cause a denial of service (memory consumption) via a crafted shared strings table in a workbook. CWE-20
 Improper Input Validation 
CVE-2015-2776 2024-11-21 11:28 2015-03-31 Show GitHub Exploit DB Packet Storm
275067 - wpml wpml The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass nonce checks and perform arbitrary actions via a request con… CWE-284
Improper Access Control
CVE-2015-2792 2024-11-21 11:28 2015-03-30 Show GitHub Exploit DB Packet Storm
275068 - wpml wpml The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a crafted request to sitepress-multilingual-cms/menu/men… CWE-264
Permissions, Privileges, and Access Controls
CVE-2015-2791 2024-11-21 11:28 2015-03-30 Show GitHub Exploit DB Packet Storm
275069 - foxitsoftware enterprise_reader
foxit_reader
phantompdf
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted (1) Ubyte Size in a DataSubBlock structure o… CWE-20
 Improper Input Validation 
CVE-2015-2790 2024-11-21 11:28 2015-03-30 Show GitHub Exploit DB Packet Storm
275070 - foxitsoftware foxit_reader Unquoted Windows search path vulnerability in the Foxit Cloud Safe Update Service in the Cloud plugin in Foxit Reader 6.1 through 7.0.6.1126 allows local users to gain privileges via a Trojan horse p… NVD-CWE-Other
CVE-2015-2789 2024-11-21 11:28 2015-03-30 Show GitHub Exploit DB Packet Storm